Privacy Policy
Table of Contents
Introduction and Overview
Scope of Application
Legal Basis
Contact Details of the Controller
Contact Details of the Data Protection Officer
Storage Period
Rights under the General Data Protection Regulation (GDPR)
Security of Data Processing
Communication
Cookies
Web Hosting Introduction
Cookie Consent Management Platform Introduction
Web Design Introduction
Online Map Services Introduction
Explanation of Terms Used
Conclusion
Introduction and Overview
We have prepared this privacy policy (version 08.03.2026-113193445) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (hereinafter referred to as "data") we, as the controller – and the processors we have engaged (e.g., providers) – process, will process in the future, and what legal options you have. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, aims to describe the most important aspects as simply and transparently as possible. Where it promotes transparency, technical terms are explained in a reader-friendly way, links to further information are provided, and graphics are used. We inform you in clear and simple language that we only process personal data in the course of our business activities if there is a corresponding legal basis. This is certainly not possible if one provides the briefest, unclear, and overly technical legal explanations that are often standard practice on the internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps you will discover some information that was new to you.
If you still have questions, please contact the responsible party listed below or in the legal notice, follow the provided links, and consult further information on third-party websites. Our contact details can, of course, also be found in the legal notice.
Scope of Application
This privacy policy applies to all personal data processed by us within our company and to all personal data processed by companies commissioned by us (data processors). Personal data refers to information as defined in Article 4 No. 1 GDPR, such as a person's name, email address, and postal address. The processing of personal data enables us to offer and bill for our services and products, whether online or offline. The scope of this privacy policy includes:
all online presences (websites, online shops) that we operate
social media presence and email communication
mobile apps for smartphones and other devices
In short: This privacy policy applies to all areas in which personal data is processed in a structured manner within our company via the aforementioned channels. Should we enter into legal relationships with you outside of these channels, we will inform you separately, if necessary.
Legal Basis
In the following privacy policy, we provide you with transparent information on the legal principles and regulations, i.e., the legal bases of the General Data Protection Regulation (GDPR), that allow us to process personal data. Regarding EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU General Data Protection Regulation online at EUR-Lex, the access point to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
Consent (Article 6 paragraph 1 lit. a GDPR): You have given us your consent to process data for a specific purpose. An example would be storing the data you enter in a contact form.
Contract (Article 6 paragraph 1 lit. b GDPR): We process your data to fulfill a contract or pre-contractual obligations with you. For example, if we conclude a purchase agreement with you, we need personal information beforehand.
Legal obligation (Article 6 paragraph 1 lit. c GDPR): We process your data when we are subject to a legal obligation. For example, we are legally required to retain invoices for accounting purposes. These typically contain personal data.
Legitimate interests (Article 6 paragraph 1 lit. f GDPR): In the case of legitimate interests that do not infringe your fundamental rights, we reserve the right to process personal data.
For example, we need to process certain data to operate our website securely and efficiently. This processing is therefore a legitimate interest.
Other conditions, such as the recording of images in the public interest, the exercise of official authority, or the protection of vital interests, do not generally apply to us. If such a legal basis should apply, it will be indicated accordingly.
In addition to the EU Regulation, national laws also apply:
In Austria, this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), abbreviated DSG.
In Germany, the Federal Data Protection Act, abbreviated BDSG, applies.
If other regional or national laws apply, we will inform you about them in the following sections.
Contact details of the data controller
Should you have any questions regarding data protection or the processing of personal data, you will find the contact details of the data controller below, in accordance with Article 4(7) of the EU General Data Protection Regulation (GDPR):
Anesa Jahić, MSc
Ziegelstraße 22, 8045 Graz, Austria
Email: shamsbyanesa@gmail.com
Phone: +43 676 91 06 886
Legal notice: https://www.shamsbyanesa.com/impressum
Contact details of the data protection officer
The contact details of the data protection officer are below:
Anesa Jahić, MSc
Ziegelstraße 22, 8045 Graz, Austria
Email: shamsbyanesa@gmail.com
Phone: +43 676 91 06 886
Data retention period
We only store personal data for as long as is absolutely necessary for the provision of our services and products. This is a general criterion for us. This means that we delete personal data as soon as the reason for processing it no longer exists. In some cases, we are legally obligated to store certain data even after the original purpose has ceased to exist, for example, for accounting purposes.
If you wish to have your data deleted or revoke your consent to data processing, the data will be deleted as quickly as possible, provided there is no legal obligation to retain it.
We will inform you about the specific duration of the respective data processing below, if we have further information.
Rights under the General Data Protection Regulation (GDPR)
In accordance with Articles 13 and 14 of the GDPR, we inform you about the following rights you have to ensure fair and transparent data processing:
According to Article 15 of the GDPR, you have the right to access your personal data. If this is the case, you have the right to receive a copy of the data and the following information:
the purpose for which we process the data;
the categories, i.e., the types of data, that are processed;
Who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
how long the data is stored;
the existence of the right to rectification, erasure, or restriction of processing and the right to object to processing;
that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
the origin of the data if we did not collect it from you;
whether profiling is carried out, i.e., whether data is automatically analyzed to create a personal profile of you.
According to Article 16 GDPR, you have the right to rectification of your data, which means that we must correct data if you find errors.
According to Article 17 GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you can request the deletion of your data.
According to Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it further.
According to Article 20 of the GDPR, you have the right to data portability, which means that we will provide you with your data in a commonly used format upon request.
According to Article 21 of the GDPR, you have the right to object, which, if exercised, will result in a change to the processing of your data.
If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then review your objection as quickly as possible to determine whether we can legally comply with it.
If data is used for direct marketing purposes, you can object to this type of data processing at any time. We will then no longer be permitted to use your data for direct marketing.
If data is used for profiling, you can object to this type of data processing at any time. We will then no longer be permitted to use your data for profiling.
Use.
According to Article 22 of the GDPR, you may have the right not to be subject to a decision based solely on automated processing (e.g., profiling).
According to Article 77 of the GDPR, you have the right to lodge a complaint. This means you can lodge a complaint with the data protection authority at any time if you believe that the processing of your personal data violates the GDPR.
In short: You have rights – don't hesitate to contact the data controller listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you can lodge a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/. In Germany, there is a data protection commissioner for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
Austrian Data Protection Authority
Head: Dr. Matthias Schmidl
Address: Barichgasse 40-42, 1030 Vienna
Telephone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at/
Data Processing Security
To protect personal data, we have implemented both technical and organizational measures. Where possible, we encrypt or pseudonymize personal data. This makes it as difficult as possible, within our means, for third parties to infer personal information from our data.
Article 25 of the GDPR refers to "data protection by design and by default," meaning that security must always be considered and appropriate measures implemented for both software (e.g., forms) and hardware (e.g., access to the server room). Below, we will discuss specific measures as needed.
TLS encryption with HTTPS
TLS, encryption, and HTTPS sound very technical, and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data securely over the internet.
This means that the entire transmission of all data from your browser to our web server is secure – no one can eavesdrop.
With this, we have introduced an additional layer of security and comply with data protection by design (Article 25 Paragraph 1 GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the internet, we can ensure the protection of confidential data.
You can recognize this secure data transmission by the small padlock icon in the top left corner of your browser, to the left of the web address (e.g., examplepage.com), and the use of the https scheme (instead of http) as part of our web address.
If you would like to learn more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find helpful links to further information.
Communication
Communication Summary
👥 Data Subjects: Everyone who communicates with us by phone, email, or online form
📓 Data Processed: e.g., phone number, name, email address, form data entered. More details can be found with the respective contact method.
🤝 Purpose: Handling communication with customers, business partners, etc.
📅 Storage Period: Duration of the business transaction and legal requirements
⚖️ Legal Basis: Art. 6 para. 1 lit. a GDPR (Consent), Art. 6 para. 1 lit. b GDPR (Contract), Art. 6 para. 1 lit. f GDPR (Legitimate Interests)
When you contact us and communicate with us by phone, email, or online form, personal data may be processed.
The data is processed for handling and processing your inquiry and the associated business transaction. The data is stored for as long as required by law.
Data Subjects
The aforementioned processes affect all those who contact us via the communication channels we provide.
Telephone
When you call us, the call data is stored pseudonymously on the respective device and with the telecommunications provider. Furthermore, data such as your name and telephone number may subsequently be sent by email and stored for the purpose of responding to your inquiry. The data is deleted as soon as the business transaction has been completed and legal requirements permit.
Email
When you communicate with us by email, data may be stored on the respective device (computer, laptop, smartphone, etc.), and the following may be stored:
Data is stored on the email server. The data is deleted as soon as the business transaction has been completed and legal requirements permit.
Online Forms
When you communicate with us via an online form, data is stored on our web server and may be forwarded to an email address provided by us. The data is deleted as soon as the business transaction has been completed and legal requirements permit.
Legal Basis
The processing of data is based on the following legal grounds:
Art. 6 para. 1 lit. a GDPR (Consent): You give us your consent to store your data and use it for purposes related to the business transaction;
Art. 6 para. 1 lit. b GDPR (Contract): Processing is necessary for the performance of a contract with you or a data processor, such as a telephone provider, or for pre-contractual activities, such as preparing a quotation;
Art. 6 para. 1 lit. f GDPR (Legitimate Interests): We want to handle customer inquiries and business communication in a professional manner. Certain technical infrastructure, such as email programs, Exchange servers, and mobile network operators, is necessary for efficient communication.
Cookies
Cookies Summary
👥 Affected parties: Website visitors
🤝 Purpose: Depends on the specific cookie. More details can be found below or on the website of the software provider that sets the cookie.
📓 Data processed: Depends on the specific cookie used. More details can be found below or on the website of the software provider that sets the cookie.
📅 Storage duration: Depends on the specific cookie; can vary from hours to years.
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)
What are cookies?
Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used to help you better understand the following privacy policy.
``` Whenever you browse the internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
There's no denying it: cookies are really useful tools. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are other types of cookies for different applications. HTTP cookies are small files that our website stores on your computer. These cookie files are automatically placed in the cookie folder, essentially the "brain" of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data, such as your language or personal website settings. When you revisit our site, your browser sends this user-related information back to us. Thanks to cookies, our website knows who you are and offers you the settings you're used to. In some browsers, each cookie has its own file, while in others, such as Firefox, all cookies are stored in a single file.
The following graphic illustrates a possible interaction between a web browser, such as Chrome, and a web server. The web browser requests a website and receives a cookie from the server, which the browser then reuses whenever another page is requested.
There are first-party cookies and third-party cookies. First-party cookies are created directly by our website, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to several years. Cookies are not software programs and do not contain viruses, Trojans, or other malware. Cookies cannot access information on your computer.
This is what cookie data might look like, for example:
Name: _ga
Value: GA1.2.1326744211.152113193445-9
Purpose: Differentiating website visitors
Expiration date: after 2 years
These are the minimum sizes a browser should be able to support:
At least 4096 bytes per cookie
At least 50 cookies per domain
At least 3000 cookies in total
What types of cookies are there?
The specific cookies we use depend on the services used and are explained in the following sections of the privacy policy. Here, we would like to briefly discuss the different types of HTTP cookies.
There are four types of cookies:
Essential cookies
These cookies are necessary to
These cookies ensure the basic functionality of the website. For example, they are needed when a user adds a product to their shopping cart, then continues browsing other pages, and only later proceeds to checkout. These cookies prevent the shopping cart from being emptied, even if the user closes their browser window.
Functional Cookies
These cookies collect information about user behavior and whether the user receives any error messages. They also measure loading times and the website's performance across different browsers.
Performance Cookies
These cookies improve user experience. For example, they save entered locations, font sizes, or form data.
Advertising Cookies
These cookies are also called targeting cookies. They are used to deliver personalized advertising to the user. This can be very convenient, but also very annoying.
Typically, you will be asked which of these cookie types you wish to allow when you first visit a website. This decision is, of course, also stored in a cookie.
If you would like to learn more about cookies and are comfortable with technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments entitled “HTTP State Management Mechanism”.
Purpose of Processing via Cookies
The purpose ultimately depends on the specific cookie. More details can be found below or on the website of the software provider that sets the cookie.
What Data is Processed?
Cookies are small helpers for many different tasks. Unfortunately, it is not possible to generalize about which data is stored in cookies, but we will inform you about the processed and stored data in the following privacy policy.
Storage Period of Cookies
The storage period depends on the specific cookie and is specified further below. Some cookies are deleted after less than an hour, while others can remain stored on a computer for several years.
You also have control over the storage period. You can manually delete all cookies at any time via your browser (see also “Right to Object” below). Furthermore, cookies based on consent will be deleted at the latest after you withdraw your consent, although the lawfulness of the storage remains unaffected until then.
Right to object – how can I delete cookies?
You decide how and whether you want to use cookies. Regardless of the service or website the cookies originate from, you always have the option to delete, disable, or partially allow cookies. For example, you can block third-party cookies but allow all other cookies.
If you want to see which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find this information in your browser settings:
Chrome: Delete, enable, and manage cookies in Chrome
Safari: Manage cookies and website data with Safari
Firefox: Clear cookies to remove data that websites have stored on your computer
Internet Explorer: Delete and manage cookies
Microsoft Edge: Delete and manage cookies
If you generally do not want any cookies, you can configure your browser to always notify you when a cookie is about to be set. This allows you to decide whether to allow or block each individual cookie. The procedure varies depending on the browser. The best way to find instructions is to search on Google using the keywords "delete cookies Chrome" or "disable cookies Chrome" if you are using the Chrome browser.
Legal Basis
Since 2009, the so-called "Cookie Directive" has been in effect. It stipulates that storing cookies requires your consent (Article 6(1)(a) GDPR). However, reactions to this directive vary considerably within the EU. In Austria, this directive was implemented in Section 165(3) of the Telecommunications Act (2021). In Germany, the Cookie Directive was not implemented as national law. Instead, it was largely implemented in Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.
For strictly necessary cookies, even where no consent has been given, there are legitimate interests (Article 6(1)(f) GDPR) which are in most cases of an economic nature. We want to provide visitors to the website with a pleasant user experience, and certain cookies are often essential for this.
If non-essential cookies are used, this only happens with your consent. The legal basis for this is Article 6(1)(a) GDPR.
a GDPR.
In the following sections, you will find more detailed information about the use of cookies, provided that the software used employs cookies.
Web Hosting Introduction
Web Hosting Summary
👥 Data Subjects: Website Visitors
🤝 Purpose: Professional hosting of the website and ensuring its operation
📓 Data Processed: IP address, time of website visit, browser used, and other data. More details can be found below or with the respective web hosting provider.
📅 Storage Period: Depends on the respective provider, but generally 2 weeks
⚖️ Legal Basis: Art. 6 para. 1 lit. f GDPR (Legitimate Interests)
What is Web Hosting?
When you visit websites today, certain information – including personal data – is automatically generated and stored, as is the case on this website. This data should be processed as sparingly as possible and only with justification. By "website," we mean the entirety of all web pages on a domain, i.e., everything from the homepage to the very last subpage (like this one). By "domain," we mean, for example, example.de or sample.com.
If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser. You're probably familiar with some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We simply call them browsers or web browsers.
To display the website, the browser needs to connect to another computer where the website's code is stored: the web server. Operating a web server is a complex and resource-intensive task, which is why it's usually handled by professional providers, or ISPs. These providers offer web hosting and ensure the reliable and error-free storage of website data. A lot of technical terms, but please stick around, it gets better!
When your browser connects to our website (desktop, laptop, tablet, or smartphone) and during data transfer to and from our web server, personal data may be processed. Your computer stores data, and the web server also needs to store data for a period of time to ensure proper operation.
A picture is worth a thousand words, so the following graphic illustrates the interaction between your browser, the internet, and your hosting provider.
Why do we process personal data?
The purposes of data processing are:
Professional hosting of the website and ensuring its operation
Maintaining operational and IT security
Anonymous analysis of access behavior to improve our services and, if necessary, for law enforcement or pursuing legal claims
What data is processed?
Even while you are currently visiting our website, our web server—the computer on which this website is stored—generally saves data automatically, such as:
the complete internet address (URL) of the accessed website
browser and browser version (e.g., Chrome 87)
the operating system used (e.g., Windows 10)
the address (URL) of the previously visited page (referrer URL) (e.g., https://www.examplesourcesite.de/fromwhereIcame/)
the hostname and IP address of the device accessing the site (e.g., COMPUTERNAME and 194.23.43.121)
date and time
in files called web server log files.
How long is data stored?
The data mentioned above is generally stored for two weeks and then automatically deleted. We do not share this data, but we cannot rule out the possibility that authorities may access it in the event of unlawful activity.
``` In short: Your visit is logged by our provider (the company that runs our website on dedicated computers (servers)), but we will not share your data without your consent!
Legal basis
The lawfulness of processing personal data in the context of web hosting is based on Article 6(1)(f) GDPR (legitimate interests), as using professional hosting from a provider is necessary to present the company securely and user-friendly online and to be able to pursue any attacks and claims arising therefrom.
We typically have a data processing agreement with the hosting provider in accordance with Articles 28 et seq. GDPR, which ensures compliance with data protection regulations and guarantees data security.
External Web Hosting Provider Privacy Policy
Below you will find the contact details of our external hosting provider, where you can learn more about data processing in addition to the information above:
Lior Saar
Deputy General Counsel & DPO
Wix.com Inc.
100 Gansevoort Street
New York, NY 10014
Email: dpo@wix.com
Phone: +972 03 545 4900
Learn more
You can find information about data processing by this provider in their privacy policy.
Cookie Consent Management Platform Introduction
Cookie Consent Management Platform Summary
👥 Affected parties: Website visitors
🤝 Purpose: Obtaining and managing consent for specific cookies and thus the use of certain tools
📓 Data processed: Data for managing the configured cookie settings, such as IP address, time of consent, type of consent, and individual consents. More details can be found with the respective tool used.
📅 Storage period: Depends on the tool used; expect storage periods of several years.
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)
What is a Cookie Consent Management Platform?
We use Consent Management Platform (CMP) software on our website, which facilitates the correct and secure handling of scripts and cookies for both us and you. The software automatically creates a cookie popup, scans and checks all scripts and cookies, provides you with the legally required cookie consent, and helps us and you keep track of all cookies. Most cookie consent management tools identify and categorize all existing cookies. As a website visitor, you then decide which scripts and cookies you allow or block. The following graphic illustrates the relationship between browser, web server, and CMP.
Why do we use a cookie management tool?
Our goal is to offer you the best possible transparency regarding data protection. We are also legally obligated to do so. We want to inform you as thoroughly as possible about all tools and all cookies that can store and process your data. It is also your right to decide which cookies you accept and which you do not. To grant you this right, we first need to know exactly which cookies have landed on our website. Thanks to a cookie management tool that regularly scans the website for all existing cookies, we are aware of all cookies and can provide you with GDPR-compliant information about them. You can then accept or reject cookies via the consent system.
What data is processed?
With our cookie management tool, you can manage each individual cookie yourself and have complete control over the storage and processing of your data. Your declaration of consent is stored so that we don't have to ask you every time you visit our website and so that we can also prove your consent if legally required. This is stored either in an opt-in cookie or on a server. The storage period for your cookie consent varies depending on the provider of the cookie management tool. This data (such as pseudonymous user ID, time of consent, details about the cookie categories or tools, browser, device information) is usually stored for up to two years.
Duration of data processing
We will inform you about the duration of data processing below, provided we have further information on this. Generally, we process personal data only for as long as is absolutely necessary for providing our services and products. Data stored in cookies is stored for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others can remain stored in your browser for several years. The exact duration of data processing depends on the tool used; you should generally expect a storage period of several years. You can usually find detailed information about the duration of data processing in the respective privacy policies of the individual providers.
Right to object
You also have the right and the option to withdraw your consent to the use of cookies at any time. This can be done either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, disabling, or deleting cookies in your browser.
Information on specific cookie management tools can be found – if available – in the following sections.
Legal basis
If you consent to cookies, your personal data will be processed and stored via these cookies. If we are permitted to use cookies based on your consent (Article 6(1)(a) GDPR), this consent also serves as the legal basis for the use of cookies and the processing of your data. To manage cookie consent and enable you to grant it, we use cookie consent management platform software.
for use. The use of this software enables us to operate the website efficiently and in compliance with the law, which constitutes a legitimate interest (Article 6(1)(f) GDPR).
AdSimple Consent Manager Privacy Policy
AdSimple Consent Manager Privacy Policy Summary
👥 Data Subjects: Website Visitors
🤝 Purpose: Obtaining consent for certain cookies and thus the use of certain tools
📓 Data Processed: Data for managing the configured cookie settings, such as IP address, time of consent, type of consent, and individual consents. More details can be found further down in this privacy policy.
📅 Storage Period: The cookie used expires after one year.
⚖️ Legal Basis: Article 6(1)(a) GDPR (consent), Article 6(1)(f) GDPR (legitimate interests)
What is the AdSimple Consent Manager?
We use the AdSimple Consent Manager from the software development and online marketing company AdSimple GmbH, Fabriksgasse 20, 2230 Gänserndorf, on our website. The AdSimple Consent Manager allows us, among other things, to provide you with a comprehensive and GDPR-compliant cookie notice, so you can decide which cookies you allow and which you do not. By using this software, your data is sent to and stored by AdSimple. In this privacy policy, we inform you why we use the AdSimple Consent Manager, what data is transferred and stored, and how you can prevent this data transfer.
The AdSimple Consent Manager is software that scans our website and identifies and categorizes all existing cookies. Furthermore, as a website visitor, you are informed about the use of cookies via a cookie notice script and can decide for yourself which cookies you allow and which you do not.
Why do we use the AdSimple Consent Manager on our website?
We want to offer you maximum transparency regarding data protection. To ensure this, we first need to know exactly which cookies have landed on our website over time. Because the AdSimple Consent Manager regularly scans our website and identifies all cookies, we have full control over these cookies and can therefore act in compliance with the GDPR. This allows us to inform you precisely about the use of cookies on our website. Furthermore, you will always receive an up-to-date and GDPR-compliant cookie notice and can decide for yourself, via a checkbox system, which cookies you accept or block.
What data is stored by the AdSimple Consent Manager?
If you consent to cookies on our website, the following cookie will be set by the AdSimple Consent Manager:
Name: acm_status
Value: “:true,”statistics”:true,”marketing”:true,”socialmedia”:true,”settings”:true}
Purpose: This cookie stores your consent status. This allows our website to read and follow the current status on future visits.
Expiration date: after one year
How long and where is the data stored?
All data collected by the AdSimple Consent Manager is transferred and stored exclusively within the European Union. The collected data is stored on AdSimple's servers at Hetzner GmbH in Germany. Only AdSimple GmbH and Hetzner GmbH have access to this data.
How can I delete my data or prevent data storage?
You have the right to access and delete your personal data at any time. You can prevent data collection and storage, for example, by rejecting the use of cookies via the cookie notice script. Another option is to Your browser offers options to prevent data processing or manage it according to your preferences. Cookie management works slightly differently depending on the browser. Under the "Cookies" section, you will find links to the instructions for the most common browsers.
Legal Basis
If you consent to cookies, your personal data will be processed and stored via these cookies. If we are permitted to use cookies based on your consent (Article 6 Paragraph 1 Letter a GDPR), this consent also serves as the legal basis for the use of cookies and the processing of your data. The AdSimple Consent Manager is used to manage cookie consent and enable you to grant it. Using this software allows us to operate the website efficiently and in compliance with the law, which constitutes a legitimate interest (Article 6 Paragraph 1 Letter f GDPR).
We hope we have provided you with a good overview of the data traffic and data processing by the AdSimple Consent Manager. If you would like to learn more about this tool...
If you would like to learn more, we recommend the description page at https://www.adsimple.at/consent-manager/.
Web Design Introduction
Web Design Privacy Policy Summary
👥 Data Subjects: Website Visitors
🤝 Purpose: Improving the User Experience
📓 Data Processed: The data processed depends heavily on the services used. It typically includes IP address, technical data, language settings, browser version, screen resolution, and browser name. More details can be found with the respective web design tools used.
📅 Storage Period: Depends on the tools used
⚖️ Legal Basis: Art. 6 para. 1 lit. a GDPR (Consent), Art. 6 para. 1 lit. f GDPR (Legitimate Interests)
What is Web Design?
We use various tools on our website to enhance our web design. Contrary to popular belief, web design is not just about making our website look good, but also about functionality and performance. But of course, the right look for a website is also one of the major goals of professional web design. Web design is a subfield of media design and deals with the visual, structural, and functional design of a website. The goal is to improve your experience on our website through web design. In web design jargon, this is referred to as user experience (UX) and usability. User experience encompasses all the impressions and experiences that a website visitor has on a website. A sub-concept of user experience is usability, which refers to the user-friendliness of a website. The emphasis here is on ensuring that content, subpages, or products are clearly structured and that you can easily and quickly find what you are looking for. To offer you the best possible experience on our website, we also use so-called third-party web design tools. In this privacy policy, the category "web design" therefore includes all services that improve the design of our website. These can include, for example, fonts, various plugins, or other integrated web design functions.
Why do we use web design tools?
How you absorb information from a website depends heavily on its structure, functionality, and visual appeal. Therefore, good and professional web design has become increasingly important to us. We are constantly working to improve our website and see this as an enhanced service for you as a website visitor. Furthermore, a beautiful and functional website also offers us economic advantages. Ultimately, you will only visit us and take advantage of our services if you feel completely comfortable.
What data is stored by web design tools?
When you visit our website, web design elements may be integrated into our pages that can also process data. The exact data involved depends, of course, on the tools used. Below you will find a detailed list of the tools we use for our website. For more information about data processing, we recommend that you also read the respective privacy policies of the tools used. These policies usually explain what data is processed, whether cookies are used, and how long the data is stored. Fonts such as Google Fonts automatically transmit information like language settings, IP address, browser version, screen resolution, and browser name to Google servers.
Duration of Data Processing
The length of time data is processed varies greatly and depends on the web design elements used. For example, if cookies are used, the storage period can range from just a minute to several years. Please familiarize yourself with this information. We recommend reading our general section on cookies and reviewing the privacy policies of the tools used. These policies typically explain which cookies are used and what information they store. Google Font files, for instance, are stored for one year to improve website loading times. Generally, data is only stored for as long as necessary to provide the service. Data may be stored for longer periods if required by law.
Right to Object
You have the right to withdraw your consent to the use of cookies or third-party providers at any time. This works either via our cookie management tool or via other opt-out functions. You can also prevent data collection by cookies by managing, disabling, or deleting cookies in your browser. This is often found under web design elements (mostly fonts).
However, there is also data that cannot be deleted quite so easily. This is the case when data is automatically collected directly upon a page request and transmitted to a third-party provider (such as Google). In this case, please contact the support of the respective provider. For Google, you can reach their support at https://support.google.com/?hl=de.
Legal Basis
If you have consented to the use of web design tools, the legal basis for the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur when collected by web design tools. We also have a legitimate interest in improving the web design on our website. After all, this is the only way we can provide you with an attractive and professional website. The corresponding legal basis for this is Art. 6 para. 1 lit. f GDPR (Legitimate Interests). Nevertheless, we only use web design tools if you have given your consent. We definitely want to emphasize this again here.
Information on specific web design tools can be found – if available – in the following sections.
Google Fonts Local Privacy Policy
On our website, we use Google Fonts from Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible. We have integrated the Google fonts locally, i.e., on our web server – not on Google's servers. Therefore, there is no connection to Google servers and consequently no data transfer or storage.
What are Google Fonts?
Google Fonts were formerly known as Google Web Fonts. It is an interactive directory with over 800 fonts that Google provides free of charge. With Google Fonts, you could use fonts without uploading them to your own server. However, to prevent any data transfer to Google servers, we have downloaded the fonts to our server. In this way, we comply with data protection regulations and do not send any data to Google Fonts.
Online Map Services Introduction
Online Map Services Privacy Policy Summary
👥 Data Subjects: Website Visitors
🤝 Purpose: Improving User Experience
📓 Data Processed: The data processed depends heavily on the services used. It usually includes IP address, location data, search terms, and/or technical data. More details can be found with the respective tools used.
📅 Storage Period: Depends on the tools used
⚖️ Legal Basis: Art. 6 para. 1 lit. a GDPR (Consent), Art. 6 para. 1 lit. f GDPR (Legitimate Interests)
What are Online Map Services?
We also use online map services as an enhanced service on our website. Google Maps is probably the service you are most familiar with, but there are other providers that specialize in creating digital maps. These services allow locations, route plans, or other geographical information to be displayed directly on our website. Thanks to an integrated map service, you no longer need to leave our website to, for example, view directions to a location. Map sections are embedded using HTML code to ensure the online map functions correctly. These services can then display road maps, the Earth's surface, or aerial and satellite images. When you use the integrated map service, data is also transferred to and stored by the tool. This data may include personal information.
Why do we use online map services on our website?
Generally speaking, our goal is to provide you with a pleasant experience on our website. And your experience is only truly enjoyable if you can easily navigate our website and find all the information you need quickly and easily. Therefore, we thought an online map system could significantly improve our website service. Without leaving our website, you can easily view route descriptions, locations, or points of interest using the map system. It's also incredibly convenient that you can see at a glance where our company headquarters are located, ensuring you can find us quickly and easily. As you can see, there are many advantages, and we clearly consider online map services on our website to be part of our customer service.
What data is stored by online map services?
When you open a page on our website that has an integrated online map function, personal data may be transmitted to the respective provider.
Your data is transmitted to and stored by the service. This usually includes your IP address, which can also be used to determine your approximate location. In addition to the IP address, data such as entered search terms and latitude and longitude coordinates are also stored. If you enter an address for route planning, this data is also saved. The data is not stored on our servers, but on the servers of the integrated tools. You can think of it like this: You are on our website, but when you interact with a map service, this interaction actually takes place on their website. For the service to function correctly, at least one cookie is usually placed in your browser. Google Maps, for example, also uses cookies to record user behavior and thus optimize its own service and display personalized advertising. You can learn more about cookies in our "Cookies" section.
How long and where is the data stored?
Each online map service processes different user data. If we have further information, we will inform you about the duration of data processing below in the corresponding sections for the individual tools. In principle, personal data is only stored for as long as necessary to provide the service. Google Maps, for example, stores certain data for a specific period, while you must delete other data yourself. Mapbox, for instance, stores IP addresses for 30 days and then deletes them. As you can see, each tool stores data for a different length of time. Therefore, we recommend that you carefully review the privacy policies of the tools used.
The providers also use cookies to store data about your user behavior with the map service. You can find more general information about cookies in our "Cookies" section, and you can also find out which cookies may be used in the privacy policies of the individual providers. However, these are usually only exemplary lists and are not exhaustive.
Right to object
You always have the option and the right to access your personal data and to object to its use and processing. You can also revoke your consent at any time. This is usually easiest via the cookie consent tool. However, there are also other opt-out tools that you can use. You can manage, delete, or disable any cookies set by the providers you use with just a few clicks. However, this may result in some service functions no longer working as expected. How you manage cookies in your browser depends on the browser you are using. In the "Cookies" section, you will also find links to instructions for the most common browsers.
Legal Basis
If you have consented to the use of an online map service, the legal basis for the corresponding data processing is this consent. According to Article 6 Paragraph 1 Letter a GDPR (Consent), this consent constitutes the legal basis for processing personal data, such as that collected by an online map service.
We also have a legitimate interest in using an online map service to optimize our service on our website. The corresponding legal basis for this is Article 6 Paragraph 1 Letter f GDPR (Legitimate Interests). However, we only use an online map service if you have given your consent. We want to emphasize this point again here.
Information on specific online map services can be found – if available – in the following sections.
Google Maps Privacy Policy
Google Maps Privacy Policy Summary
👥 Data subjects: Website visitors
🤝 Purpose: Optimizing our service
📓 Data processed: Data such as entered search terms, your IP address, and latitude and longitude coordinates.
More details can be found further down in this privacy policy.
📅 Storage period: Depends on the stored data
⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests)
What is Google Maps?
We use Google Maps from Google Inc. on our website. For the European Economic Area, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services. Google Maps allows us to show you locations more effectively and thus tailor our service to your needs. By using Google Maps, data is transferred to Google and stored on Google's servers. Here we want to
Now let's take a closer look at what Google Maps is, why we use this Google service, what data is stored, and how you can prevent this.
Google Maps is an online mapping service provided by Google. With Google Maps, you can search for the exact locations of cities, landmarks, accommodations, or businesses online using a PC, tablet, or app. If businesses are listed on Google My Business, additional information about the company is displayed alongside the location. To show directions, map snippets of a location can be embedded into a website using HTML code. Google Maps displays the Earth's surface as a road map or as an aerial or satellite image. Thanks to Street View images and high-quality satellite imagery, very precise representations are possible.
Why do we use Google Maps on our website?
All our efforts on this page aim to provide you with a useful and meaningful experience on our website. By integrating Google Maps, we can provide you with essential information about various locations. You can see at a glance where our company headquarters are located. The directions will always show you the best and fastest way to reach us. You can get directions for routes by car, public transport, on foot, or by bicycle. For us, providing Google Maps is part of our customer service.
What data does Google Maps store?
In order for Google Maps to fully offer its service, the company needs to collect and store data from you. This includes, among other things, the search terms you enter, your IP address, and your latitude and longitude coordinates. If you use the route planner function, the starting address you enter will also be saved. However, this data storage takes place on Google Maps' websites. We can only inform you about this, but we have no control over it. Because we have integrated Google Maps into our website, Google places at least one cookie (name: NID) in your browser. This cookie stores data about your user behavior. Google primarily uses this data to optimize its own services and to provide you with personalized advertising.
The following cookie is set in your browser due to the integration of Google Maps:
Name: NID
Value: 188=h26c1Ktha7fCQTx8rXgLyATyITJ113193445-5
Purpose: NID is used by Google to personalize ads based on your Google searches. With the help of this cookie, Google "remembers" your most frequently entered search queries or your previous interactions with ads. This ensures you always receive tailored advertisements. The cookie contains a unique ID that Google uses to collect your personal preferences for advertising purposes.
Expiration date: after 6 months
Note: We cannot guarantee the completeness of the information regarding the stored data. Changes are always possible, especially when using cookies. To identify the NID cookie, a separate test page was created that only included Google Maps.
How long and where is the data stored?
Google's servers are located in data centers around the world. However, most servers are located in the United States. For this reason, your data is increasingly stored in the USA. You can find out exactly where Google's data centers are located here: https://datacenters.google/ Google distributes the data across various storage devices. This makes the data faster to access and better protected against potential manipulation attempts. Each data center also has specific emergency protocols. For example, if there are problems with Google hardware or a natural disaster disables the servers, the data remains quite secure.
Google stores some data for a fixed period. For other data, Google only offers the option to delete it manually. Furthermore, the company also anonymizes information (such as advertising data) in server logs by deleting part of the IP address and cookie information after 9 or 18 months.
How can I delete my data or prevent data storage?
With the automatic deletion feature for location and activity data introduced in 2019, information about your location and web/app activity is stored for either 3 or 18 months, depending on your choice, and then deleted. You can also manually delete this data from your history at any time via your Google account. If you want to completely prevent location tracking, you need to pause the "Web & App Activity" section in your Google account. Click "Data & Personalization" and then the "Activity controls" option. Here you can turn activity tracking on or off.
In your
In your browser, you can also deactivate, delete, or manage individual cookies. Depending on which browser you use, this process varies slightly. Under the "Cookies" section, you will find links to the instructions for the most common browsers.
If you generally do not want to allow cookies, you can configure your browser to always notify you when a cookie is about to be set. This allows you to decide whether to allow each individual cookie.
Legal Basis
If you have consented to the use of Google Maps, the legal basis for the corresponding data processing is this consent. According to Article 6 Paragraph 1 Letter a GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur during collection by Google Maps.
We also have a legitimate interest in using Google Maps to optimize our online service. The corresponding legal basis for this is Article 6 Paragraph 1 Letter f GDPR (Legitimate Interests). However, we only use Google Maps if you have given your consent.
Google processes your data in the USA, among other locations. Google is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. More information can be found at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Google uses so-called Standard Contractual Clauses (Article 46, paragraphs 2 and 3 of the GDPR). Standard Contractual Clauses (SCCs) are template agreements provided by the European Commission and are designed to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the USA). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google commits to maintaining European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the USA. These clauses are based on an implementing decision of the European Commission. You can find the decision and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which refer to the standard contractual clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
If you would like to learn more about Google's data processing, we recommend that you consult the company's privacy policy at https://policies.google.com/privacy?hl=de.
Explanation of Terms Used
We always strive to make our privacy policy as clear and understandable as possible. However, this is not always easy, especially when dealing with technical and legal topics. It often makes sense to use legal terms (such as personal data) or certain technical terms (such as cookies, IP address). However, we do not want to use these terms without explanation. Below you will find an alphabetical list of important terms used that we may not have adequately addressed in the previous privacy policy. If these terms are taken from the GDPR and are definitions, we will also cite the GDPR texts here and, where necessary, add our own explanations.
Supervisory Authority
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Supervisory authority” means an independent public authority established by a Member State pursuant to Article 51;
Explanation: “Supervisory authorities” are always independent public bodies that also have the power to issue directives in certain cases. They serve to carry out so-called state supervision and are located in ministries, special departments, or other authorities. In Austria, there is an Austrian Data Protection Authority, while in Germany, each federal state has its own data protection authority.
Data Processor
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Data processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data we process from you. In addition to controllers, there may also be so-called data processors. This includes any company or person who processes personal data on our behalf. Data processors can therefore.
This could include service providers such as tax advisors, hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
Supervisory Authority Affected
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Supervisory Authority concerned” means a supervisory authority which is affected by the processing of personal data because:
a) the controller or processor is established in the territory of the Member State of that supervisory authority,
b) the processing is likely to have a significant impact on data subjects residing in the Member State of that supervisory authority, or
c) a complaint has been lodged with that supervisory authority;
Explanation: In Germany, each federal state has its own data protection supervisory authority. Therefore, if your company headquarters (main establishment) is in Germany, the respective supervisory authority of that federal state is generally your point of contact. In Austria, there is only one data protection supervisory authority for the entire country.
``` Biometric Data
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Biometric data” means personal data obtained by specific technical means relating to the physical, physiological, or behavioural characteristics of a natural person which enable or confirm the unique identification of that natural person, such as facial images or fingerprint data;
Explanation: These are biological characteristics that are described by biometric data and from which personal data can be obtained using technical means. Examples include DNA, fingerprints, the geometry of various body parts, height, but also handwriting or the sound of a voice.
Filing System
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Filing system” means any structured set of personal data which is accessible according to specific criteria, whether that set is centralised, decentralised, or organized according to functional or geographical considerations;
Explanation: Any organized storage of data on a computer's storage medium is referred to as a “filing system”. For example, if we store your name and email address on a server for our newsletter, this data is located in a so-called "file system." The most important tasks of a "file system" include quickly searching for and finding specific data and, of course, securely storing the data.
Information Society Service
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
"Information society service" means a service as defined in Article 1(1)(b) of Directive (EU) 2015/1535 of the European Parliament and of the Council (19);
Explanation: In general, the term "information society" refers to a society that relies on information and communication technologies. As a website visitor, you are familiar with various types of online services, and most online services fall under the category of "information society services." A classic example is online transactions, such as purchasing goods via the internet.
Third Party
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Third party” means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data;
Explanation: The GDPR essentially only clarifies what a “third party” is not. In practice, any entity that has an interest in the personal data but is not one of the aforementioned persons, public authorities or agencies is considered a “third party.” For example, a parent company can act as a “third party.” In this case, the subsidiary is the controller and the parent company is the “third party.” However, this does not mean that the parent company is automatically entitled to access, collect, or store the personal data of its subsidiary.
Restriction of Processing
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Restriction of processing” means the marking of stored personal data with the aim of limiting its future processing;
Explanation: It is one of your rights to request that data controllers restrict your personal data from further processing at any time. For this purpose, specific personal data, such as your name, date of birth, or address, will be removed.
This indicates that further processing is no longer possible. For example, you could restrict processing so that your data may no longer be used for personalized advertising.
Consent
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
Explanation: Websites typically obtain such consent via a cookie consent tool. You are probably familiar with this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree to or consent to data processing. In most cases, you can also make individual settings and thus decide for yourself which data processing you allow and which you do not. If you do not consent, no personal data may be processed. Of course, consent can also be given in writing, i.e., not via a tool.
Recipient
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Recipient” means a natural or legal person, public authority, agency or other body, to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
Explanation: Any person or company that receives personal data is considered a recipient. Therefore, we and our data processors are also considered recipients. Only public authorities that have a mandate to conduct an inquiry are not considered recipients.
Genetic Data
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“genetic data” means personal data relating to the inherited or acquired genetic characteristics of a natural person which provide unique information about the physiology or health of that natural person and which are obtained in particular from the analysis of a biological sample from the natural person concerned;
Explanation: With some effort, it is possible to identify individuals using genetic data. Therefore, genetic data also falls into the category of personal data. Genetic data is obtained, for example, from blood or saliva samples.
Main Establishment
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Main Establishment” means
a) in the case of a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions regarding the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and that establishment has the authority to have those decisions implemented; In this case, the establishment that makes such decisions shall be considered the main establishment;
(b) In the case of a processor with establishments in more than one Member State, the location of its central administration in the Union or, if the processor does not have a central administration in the Union, the establishment of the processor in the Union where the processing activities carried out in connection with the activities of an establishment of a processor mainly take place, insofar as the processor is subject to specific obligations under this Regulation;
Explanation: For example, although Google is an American company that also processes data in the USA, its European main establishment is located in Ireland (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Thus, Google Ireland Limited is legally a separate company and is responsible for all Google products offered in the European Economic Area. In contrast to a main establishment, there are also branch offices; however, these do not function as legally separate establishments and are therefore to be distinguished from subsidiaries. A principal place of business is therefore always the location where a company (commercial company) has its center of operations.
International Organization
Definition according to Article 4 of the GDPR
For the purposes of this Regulation
The term "international organization" refers to:
"international organization" means an organization governed by international law and its subordinate bodies, or any other body established by or on the basis of an agreement between two or more countries.
Explanation: The best-known examples of international organizations are probably the European Union and the United Nations. The GDPR distinguishes between data transfers between third countries and international organizations. Within the EU, the transfer of personal data poses no problem because all EU countries are bound by the GDPR. However, data transfers to third countries or international organizations are subject to certain conditions.
Relevant and reasoned objection
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Relevant and reasoned objection” means an objection to a draft decision as to whether there is an infringement of this Regulation or whether proposed measures against the controller or processor comply with this Regulation, where the objection clearly demonstrates the extent of the risks posed by the draft decision to the fundamental rights and freedoms of data subjects and, where applicable, the free movement of personal data within the Union;
Explanation: If certain measures taken by us as controllers or by our processors are not in compliance with the GDPR, you can raise a so-called “relevant and reasoned objection.” In doing so, you must explain the extent of the risks to your fundamental rights and freedoms and, where applicable, the free movement of your personal data within the EU.
Personal Data
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Explanation: Personal data is therefore all data that can identify you as a person. This is generally data such as:
Name
Address
Email address
Postal address
Telephone number
Date of birth
Identification numbers such as social security number, tax identification number, identity card number or matriculation number
Bank details such as account number, credit information, account balances, etc.
According to the European Court of Justice (ECJ), your IP address also falls under the category of personal data. IT experts can use your IP address to determine at least the approximate location of your device and, consequently, you as the internet connection owner. Therefore, storing an IP address also requires a legal basis under the GDPR. There are also so-called "special categories" of personal data that are particularly worthy of protection. These include:
racial and ethnic origin
political opinions
religious or philosophical beliefs
trade union membership
genetic data, such as data obtained from blood or saliva samples
biometric data (information relating to psychological, physical, or behavioral characteristics that can identify a person).
``` Health data
Data relating to sexual orientation or sex life
Profiling
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements;
Explanation: Profiling involves collecting various pieces of information about a person to learn more about that person. In the web sector, profiling is frequently used for advertising purposes or credit checks. Web analytics programs, for example, collect data about your behavior and interests on a website. This results in a specific user profile, which is used to target advertising to a specific audience.
can be achieved.
Pseudonymization
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Pseudonymization” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;
Explanation: Our privacy policy frequently refers to pseudonymized data. Pseudonymized data means that you can no longer be identified as a person unless other information is added. However, you should not confuse pseudonymization with anonymization. Anonymization removes all personal references, so that they can only be reconstructed with a disproportionately large technical effort.
...``
`````````````````````````````````````````````````````````````````````````
``
````````
```````
````````
````````
``````````
`````````` Undertaking
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Undertaking” means any natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity;
Explanation: For example, we are an undertaking and also engage in an economic activity via our website by offering and selling services and/or products. A formal characteristic of every undertaking is its legal entity, such as a GmbH (limited liability company) or AG (stock corporation).
Controller
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law;
Explanation: In our case, we are responsible for processing your personal data and are therefore the “controller.” If we transfer collected data to other service providers for processing, these providers are “processors.” A “Data Processing Agreement (DPA)” must be signed for this.
Processing
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
Note: When we refer to processing in our privacy policy, we mean any type of data processing. As mentioned above in the original GDPR statement, this includes not only the collection but also the storage and processing of data.
Binding Corporate Rules
Definition according to Article 4 of the GDPR
For the purposes of this Regulation, the term:
“Binding corporate rules” means measures for the protection of personal data which a controller or processor established in the territory of a Member State undertakes to comply with with regard to transfers of personal data, or a category of transfers of personal data, to a controller or processor within the same group of undertakings or group of undertakings engaged in a joint economic activity in one or more third countries;
Explanation: You may have heard or read the term “Binding Corporate Rules” before. This is the term that most often comes up when discussing binding corporate rules. Such rules are particularly recommended for companies (such as Google) that process data in third countries, as they essentially commit the company to complying with data protection regulations. These rules govern the handling of personal data that is transferred to and processed in third countries.
``` Personal data breach
Definition according to Article 4d
The GDPR
For the purposes of this Regulation, the term:
“Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
