Privacy Policy
An Overview of Data Protection
1. An Overview of Data Protection
General Information The following information will provide you with an easy to navigate overview of what will happen with your personal data when you visit this website. The term “personal data” comprises all data that can be used to personally identify you. For detailed information about the subject matter of data protection, please consult our Data Protection Declaration, which we have included beneath this copy.
Data Collection on This Website
Who is the responsible party for the recording of data on this website (i.e., the “controller”)? The data on this website is processed by the operator of the website, whose contact information is available under section “Information about the responsible party (referred to as the “controller” in the GDPR)” in this Privacy Policy.
How do we collect your data? On the one hand, your data is collected when you provide it to us. This may, for example, be data that you enter into a contact form. Other data is collected automatically or after your consent when you visit the website through our IT systems. This is primarily technical data such as internet browser, operating system, or the time of the page request. This data is collected automatically as soon as you enter this website.
What do we use your data for? Some of the data is collected to ensure the error free provision of the website. Other data may be used to analyse your user behaviour. If contracts can be concluded or initiated through the website, the transmitted data will also be processed for contract offers, orders, or other service inquiries.
What rights do you have regarding your data? You have the right at any time to receive information free of charge about the origin, recipient, and purpose of your stored personal data. You also have the right to request correction or deletion of this data. If you have given consent to data processing, you may revoke this consent at any time with effect for the future. You also have the right, under certain circumstances, to request restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority. You may contact us at any time regarding this or any other questions on the subject of data protection.
Analysis Tools and Third Party Tools When visiting this website, your surfing behaviour may be statistically analysed. This is done primarily using so called analysis programs. Detailed information on these analysis programs can be found in the following privacy policy.
2. Hosting
We host the content of our website with the following provider:
External Hosting This website is hosted externally. The personal data collected on this website is stored on the servers of the host or hosts. This may include, in particular, IP addresses, contact inquiries, meta and communication data, contract data, contact details, names, website accesses, and other data generated via a website.
External hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers pursuant to Art. 6 para. 1 lit. b GDPR and in the interest of secure, fast, and efficient provision of our online offering by a professional provider pursuant to Art. 6 para. 1 lit. f GDPR. If corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s end device, such as device fingerprinting, within the meaning of the TDDDG. Consent may be revoked at any time.
Our host or hosts will only process your data to the extent necessary to fulfill their service obligations and will follow our instructions with regard to this data.
We use the following host: Wix.com Ltd. / Base44 5 Yunitzman St., Tel Aviv, Israel
Base44 Backend For the technical provision of certain functions of this website, in particular for processing form entries and user data, we use Base44. The provider is Wix.com Ltd. / Base44, 5 Yunitzman St., Tel Aviv, Israel.
In the course of its use, form data, technical usage data, and other data entered by you may in particular be processed.
Processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR, insofar as the processing is necessary for carrying out pre contractual measures or for fulfilling a contract, as well as on the basis of Art. 6 para. 1 lit. f GDPR due to our legitimate interest in the technically stable and efficient provision of our website.
3. General Information and Mandatory Information
Data Protection The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is any data by which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this is done.
We point out that data transmission on the internet, for example when communicating by email, may have security gaps. Complete protection of data against access by third parties is not possible.
Information on the Controller The controller responsible for data processing on this website is:
StivMab Consulting Steve Danaud Mabou Nghotue Geisenfelder Straße 23, 85053 Ingolstadt Phone: +49 152 13435560 Email: infos@stivmabconsulting.com support@stivmabconsulting.com
The controller is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data, such as names or email addresses.
Storage Period Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data, such as retention periods under tax or commercial law. In the latter case, deletion will take place after these reasons cease to apply.
General Information on the Legal Bases for Data Processing on This Website If you have consented to data processing, we process your personal data on the basis of Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, insofar as special categories of data are processed in accordance with Art. 9 para. 1 GDPR. In the event of express consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information on your end device, such as via device fingerprinting, data processing is additionally carried out on the basis of Section 25 para. 1 TDDDG. Consent may be revoked at any time. If your data is required for the performance of a contract or for carrying out pre contractual measures, we process your data on the basis of Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data insofar as this is necessary for compliance with a legal obligation on the basis of Art. 6 para. 1 lit. c GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR. Information on the relevant legal basis in each individual case is provided in the following paragraphs of this privacy policy.
Recipients of Personal Data In the course of our business activities, we cooperate with various external parties. In some cases, personal data must also be transmitted to these external parties. We only pass on personal data to external parties if this is necessary for contract performance, if we are legally obliged to do so, for example passing on data to tax authorities, if we have a legitimate interest in passing it on pursuant to Art. 6 para. 1 lit. f GDPR, or if another legal basis permits the data transfer. When using processors, we only pass on personal data of our customers on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.
Revocation of Your Consent to Data Processing Many data processing operations are only possible with your express consent. You may revoke consent you have already given at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to Object to Data Collection in Special Cases and to Direct Advertising (Art. 21 GDPR) IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA. THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RELEVANT LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING SERVES TO ESTABLISH, EXERCISE, OR DEFEND LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING. THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS ASSOCIATED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL THEREAFTER NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).
Right to Lodge a Complaint with the Competent Supervisory Authority In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement. The right to lodge a complaint exists without prejudice to any other administrative or judicial remedies.
Right to Data Portability You have the right to have data which we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine readable format. If you request the direct transfer of the data to another controller, this will only take place insofar as it is technically feasible.
Information, Correction, and Deletion Within the scope of the applicable statutory provisions, you have the right at any time to obtain information free of charge about your stored personal data, its origin, recipients, and the purpose of the data processing and, if applicable, a right to correction or deletion of this data. You may contact us at any time regarding this and any other questions on the subject of personal data.
Right to Restriction of Processing You have the right to request the restriction of the processing of your personal data. You may contact us at any time for this purpose. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the review, you have the right to request restriction of the processing of your personal data.
- If the processing of your personal data was or is unlawful, you may request restriction of data processing instead of deletion.
- If we no longer need your personal data, but you require it for the establishment, exercise, or defense of legal claims, you have the right to request restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balancing of your interests and our interests must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data, apart from being stored, may only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.
SSL or TLS Encryption For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser’s address line changes from “http://” to “https://” and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Objection to Promotional Emails The use of contact data published within the scope of the imprint obligation for sending unsolicited advertising and information materials is hereby objected to. The operators of the website expressly reserve the right to take legal action in the event of unsolicited sending of advertising information, such as spam emails.
4. Data Collection on This Website
Cookies Our website uses so called “cookies”. Cookies are small data packages and do not cause any damage to your end device. They are stored either temporarily for the duration of a session, session cookies, or permanently, permanent cookies, on your end device. Session cookies are automatically deleted after the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or automatic deletion occurs via your web browser.
Cookies may originate from us, first party cookies, or from third party companies, so called third party cookies. Third party cookies enable the integration of certain services provided by third party companies within websites, such as cookies for processing payment services.
Cookies have various functions. Numerous cookies are technically necessary because certain website functions would not work without them, such as the shopping cart function or the display of videos. Other cookies may be used to analyse user behaviour or for advertising purposes.
Cookies that are required to carry out the electronic communication process, to provide certain functions you request, for example for the shopping cart function, or to optimise the website, for example cookies to measure the web audience, necessary cookies, are stored on the basis of Art. 6 para. 1 lit. f GDPR unless another legal basis is stated. The website operator has a legitimate interest in storing necessary cookies for the technically error free and optimised provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent, Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. Consent may be revoked at any time.
You can configure your browser so that you are informed about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.
If further cookies and services are used on this website, you can find this in this privacy policy.
Cookie Consent Management On our website, we use a self developed cookie consent management system that has been implemented technically via our website code. This serves to obtain, store, and manage your consent to the storage of certain cookies and the use of certain technologies in accordance with data protection requirements.
As part of the use of this consent management system, your consent or revocation, the time of the decision, technical information about the end device and browser used, and, where applicable, your IP address are processed and stored.
The processing is carried out for the purpose of legally compliant proof of granted consents and on the basis of Art. 6 para. 1 lit. c GDPR in conjunction with data protection proof obligations and additionally on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the legally secure and technically reliable control of the cookies and third party services used.
The stored consent data will be retained until you request us to delete it, you delete the cookies yourself, or the purpose for storage no longer applies. Mandatory statutory retention obligations remain unaffected.
Server Log Files The provider of the pages automatically collects and stores information in so called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources. This data is collected on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error free presentation and optimisation of its website. For this purpose, the server log files must be recorded.
Google Fonts This site uses Google Fonts for the uniform display of fonts. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When you access a page, your browser loads the required fonts in order to display texts correctly. In this process, your IP address may in particular be transmitted to Google servers.
Google Fonts are used on the basis of your consent pursuant to Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, provided that the fonts are not locally integrated. Consent may be revoked at any time.
More information can be found at: https://policies.google.com/privacy?hl=de
Supabase Storage We use Supabase Storage to store and provide image files and other media content. The provider is Supabase, Inc.
In particular, public file URLs and technical access data may be processed.
The use is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the reliable and high performance provision of media content on our website.
Further information can be found at: https://supabase.com/privacy
Unsplash Images originating from Unsplash may be used on this website. The provider is Unsplash, Inc.
When loading corresponding content, a connection to Unsplash servers may be established.
Further information can be found at: https://unsplash.com/privacy
Contact Form If you send us inquiries via the contact form, your details from the inquiry form including the contact details you provide there will be stored by us for the purpose of processing the inquiry and in the event of follow up questions. We do not pass on this data without your consent.
This data is processed on the basis of Art. 6 para. 1 lit. b GDPR, provided that your inquiry is related to the fulfillment of a contract or is necessary for carrying out pre contractual measures. In all other cases, processing is based on our legitimate interest in effectively processing the inquiries addressed to us, Art. 6 para. 1 lit. f GDPR, or on your consent, Art. 6 para. 1 lit. a GDPR, if this has been requested. Consent may be revoked at any time.
The data you enter in the contact form remains with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies, for example after your request has been processed. Mandatory statutory provisions, in particular retention periods, remain unaffected.
Communication via WhatsApp WhatsApp may be used for communication with customers and interested parties. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Communication is encrypted. However, we would like to point out that WhatsApp may have access to metadata of the communication in the course of use. Further information can be found in WhatsApp’s privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea
Use is based on Art. 6 para. 1 lit. b GDPR, provided that communication is related to the initiation or execution of a contract, or on the basis of our legitimate interest in fast and efficient communication pursuant to Art. 6 para. 1 lit. f GDPR.
The data sent to us via WhatsApp remains with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies. Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.
Inquiry by Email, Telephone, or Fax If you contact us by email, telephone, or fax, your inquiry including all personal data resulting from it, such as name and inquiry, will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
This data is processed on the basis of Art. 6 para. 1 lit. b GDPR, provided that your inquiry is related to the fulfillment of a contract or is necessary for carrying out pre contractual measures. In all other cases, processing is based on our legitimate interest in effectively processing the inquiries addressed to us, Art. 6 para. 1 lit. f GDPR, or on your consent, Art. 6 para. 1 lit. a GDPR, if this has been requested. Consent may be revoked at any time.
The data sent to us via contact inquiries remains with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies, for example after your request has been processed. Mandatory statutory provisions, in particular statutory retention periods, remain unaffected.
Email Delivery Service (Resend / SendGrid) We use external service providers (e.g. Resend Inc. or Twilio SendGrid) to send emails via our website.
In this context, personal data such as email addresses and message content are processed and transmitted to the servers of the respective provider. Processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR insofar as it is necessary for the performance of a contract or pre-contractual measures, and on the basis of Art. 6 para. 1 lit. f GDPR due to our legitimate interest in efficient and reliable communication.
It cannot be ruled out that data may be transferred to third countries (e.g. the USA). In such cases, the transfer is based on the standard contractual clauses of the EU Commission.
Further information can be found in the privacy policies of the respective providers: https://resend.com/privacy https://www.twilio.com/legal/privacy
Calendly On our website, you have the option to schedule appointments with us. We use the tool “Calendly” for appointment booking. The provider is Calendly LLC, 271 17th St NW, 10th Floor, Atlanta, Georgia 30363, USA, hereinafter “Calendly”.
For the purpose of booking an appointment, you enter the requested data and the desired appointment in the form provided for this purpose. The entered data is used for planning, carrying out, and, if necessary, following up the appointment. The appointment data is stored for us on Calendly’s servers. You can view Calendly’s privacy policy here: https://calendly.com/privacy
The data entered by you remains with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies. Mandatory statutory provisions, in particular retention periods, remain unaffected.
The legal basis for data processing is Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in making appointment booking as uncomplicated as possible for interested parties and customers. If corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user’s end device, such as device fingerprinting, within the meaning of the TDDDG. Consent may be revoked at any time.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://calendly.com/pages/dpa
The company is certified under the EU US Data Privacy Framework, DPF. The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards in data processing in the USA. Every company certified under the DPF commits to complying with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/6050
Payment Services On our website, we offer the option to process payments via external payment service providers. The data entered during the payment process will be transmitted to the respective payment provider.
We use the following payment service providers:
Stripe The provider is Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. When using Stripe, payment data such as name, email address, billing address, payment amount, and payment information may be processed. Further information can be found in Stripe’s privacy policy: https://stripe.com/privacy
PayPal The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. When using PayPal, payment data, transaction data, and technical connection data are processed. Further information can be found in PayPal’s privacy policy: https://www.paypal.com/webapps/mpp/ua/privacy-full
Processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR for the performance of a contract or pre contractual measures. Depending on the payment provider, data may be transferred to third countries, in particular the United States. Such transfers are carried out on the basis of appropriate safeguards such as standard contractual clauses or relevant certifications.
Accounting and Invoicing For the creation, management, and archiving of invoices as well as for compliance with statutory retention obligations, we use external service providers.
In this context, personal data (e.g. name, address, email address, as well as invoicing and payment data) may be processed and, where necessary, transmitted to these service providers. The processing is carried out for the performance of the contract in accordance with Art. 6 para. 1 lit. b GDPR as well as for compliance with legal obligations pursuant to Art. 6 para. 1 lit. c GDPR.
Where external service providers are used, the processing is based on corresponding data processing agreements in accordance with Art. 28 GDPR.
Contract Management and Electronic Signatures External platforms may be used for the creation, transmission, and management of contracts.
In this context, personal data such as name, address, email address, and contract related content may be processed.
The processing is carried out on the basis of Art. 6 para. 1 lit. b GDPR.
Recording of Online Sessions and Use for Marketing Purposes If online consultations, coaching sessions, language sessions, or other digital meetings are recorded, this shall only take place with the customer’s prior explicit consent. The recordings may be used for internal documentation, quality assurance and, only with separate explicit consent, for marketing and communication purposes, in particular for publication on social media platforms or the website.
The processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR (consent). Consent is voluntary and may be withdrawn at any time with effect for the future.
5. Analysis Tools and Advertising
Google Analytics This website uses functions of the web analysis service Google Analytics with the measurement ID G-KRMP0NKVV6. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics enables the website operator to analyse the behaviour of website visitors. In doing so, the website operator receives various usage data, such as page views, time spent on the site, operating systems used, and the origin of the user. This data is assigned to the respective end device of the user. Assignment to a user ID does not take place.
Furthermore, with Google Analytics we can, among other things, record your mouse and scroll movements and clicks. Google Analytics also uses various modelling approaches to supplement the recorded data sets and uses machine learning technologies in data analysis.
Google Analytics uses technologies that enable the recognition of the user for the purpose of analysing user behaviour, such as cookies or device fingerprinting. The information collected by Google about the use of this website is generally transmitted to a Google server in the USA and stored there.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. Consent may be revoked at any time.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://business.safety.google/adscontrollerterms/sccs/
The company is certified under the EU US Data Privacy Framework, DPF. The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards in data processing in the USA. Every company certified under the DPF commits to complying with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780
IP Anonymisation Google Analytics IP anonymisation is activated. This means that your IP address will be shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area before being transmitted to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide other services relating to website use and internet use to the website operator. The IP address transmitted by your browser within the scope of Google Analytics will not be merged with other Google data.
Browser Plugin You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de
More information on how Google Analytics handles user data can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de
Meta Pixel formerly Facebook Pixel This website uses Meta’s visitor action pixel for conversion measurement with the pixel ID 2008254563372958. The provider of this service is Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland.
This makes it possible to track the behaviour of website visitors after they have been redirected to the provider’s website by clicking on a Meta advertisement. This allows the effectiveness of Meta advertisements to be evaluated for statistical and market research purposes and future advertising measures to be optimised.
The data collected is anonymous for us as the operator of this website. We cannot draw any conclusions about the identity of users. However, the data is stored and processed by Meta so that a connection to the respective user profile on Facebook or Instagram is possible and Meta can use the data for its own advertising purposes in accordance with Meta’s data usage policy: https://de-de.facebook.com/about/privacy/
This enables Meta to place advertisements on Facebook or Instagram pages and other advertising channels. This use of the data cannot be influenced by us as the website operator.
The use of this service is based on your consent pursuant to Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. Consent may be revoked at any time.
Insofar as personal data is collected on our website and forwarded to Meta using the tool described here, we and Meta Platforms Ireland Limited, Merrion Road Dublin 4, Dublin, D04 X2K5, Ireland, are jointly responsible for this data processing pursuant to Art. 26 GDPR. Joint responsibility is limited exclusively to the collection of the data and its transfer to Meta. The processing carried out by Meta after the transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in an agreement on joint processing. The wording of the agreement can be found here: https://www.facebook.com/legal/controller_addendum
According to this agreement, we are responsible for providing data protection information when using the Meta tool and for the data protection compliant implementation of the tool on our website. Meta is responsible for the data security of Meta products. You can assert data subject rights, for example requests for information, regarding data processed by Facebook or Instagram directly with Meta. If you assert data subject rights with us, we are obliged to forward them to Meta.
The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381
Further information on protecting your privacy can be found in Meta’s privacy information: https://de-de.facebook.com/about/privacy/
You can also deactivate the remarketing function “Custom Audiences” in the settings for advertisements at: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen To do this, you must be logged in to Facebook.
If you do not have a Facebook or Instagram account, you can deactivate usage based advertising from Meta on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/
The company is certified under the EU US Data Privacy Framework, DPF. The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards in data processing in the USA. Every company certified under the DPF commits to complying with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452
6. Audio and Video Conferences
Data Processing For communication with our customers, we use online conference tools among others. The specific tools used by us are listed below. If you communicate with us via video or audio conference over the internet, your personal data will be collected and processed by us and by the provider of the respective conference tool.
The conference tools collect all data that you provide or use for the purpose of using the tools, such as email address and or your telephone number. Furthermore, the conference tools process the duration of the conference, the beginning and end, time, of participation in the conference, the number of participants, and other context information in connection with the communication process, metadata.
Furthermore, the provider of the tool processes all technical data required to handle the online communication. This includes in particular IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection.
If content is exchanged, uploaded, or otherwise made available within the tool, this is also stored on the servers of the tool providers. Such content includes in particular cloud recordings, chat or instant messages, voicemails, uploaded photos and videos, files, whiteboards, and other information shared while using the service.
Please note that we do not have full influence over the data processing operations of the tools used. Our options are largely determined by the corporate policy of the respective provider. Further information on data processing by the conference tools can be found in the privacy policies of the respective tools used, which we have listed below this text.
Purpose and Legal Bases The conference tools are used to communicate with prospective or existing contractual partners or to offer certain services to our customers pursuant to Art. 6 para. 1 lit. b GDPR. Furthermore, the use of the tools serves the general simplification and acceleration of communication with us or our company, legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. If consent has been requested, the relevant tools are used on the basis of this consent. Consent may be revoked at any time with effect for the future.
Storage Period The data collected directly by us via the video and conference tools will be deleted from our systems as soon as you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies. Stored cookies remain on your end device until you delete them. Mandatory statutory retention periods remain unaffected.
We have no influence on the storage period of your data stored by the operators of the conference tools for their own purposes. For details, please inform yourself directly with the operators of the conference tools.
Conference Tools Used We use the following conference tools:
Zoom We use Zoom. The provider of this service is Zoom Communications Inc., San Jose, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. Details on data processing can be found in Zoom’s privacy policy: https://www.zoom.com/de/trust/privacy/privacy-statement/ The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.zoom.com/de/trust/privacy/privacy-statement/ The company is certified under the EU US Data Privacy Framework, DPF. The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards in data processing in the USA. Every company certified under the DPF commits to complying with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5728
Microsoft Teams We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Details on data processing can be found in the privacy policy of Microsoft Teams: https://privacy.microsoft.com/de-de/privacystatement The company is certified under the EU US Data Privacy Framework, DPF. The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards in data processing in the USA. Every company certified under the DPF commits to complying with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/6474
Google Meet We use Google Meet. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Details on data processing can be found in Google’s privacy policy: https://policies.google.com/privacy?hl=de The company is certified under the EU US Data Privacy Framework, DPF. The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards in data processing in the USA. Every company certified under the DPF commits to complying with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780