Privacy Policy
This privacy policy informs you about the nature, scope, and purpose of the processing of personal data (hereinafter referred to as "data") within our online offering and the websites, functions, and content associated with it, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as "online offering"), and in the day-to-day business operations of REQUISIS GmbH. With regard to the terminology used, such as "processing" or "controller", we refer to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).
Data Protection Officer
Holger Kubisch
REQUISIS GmbH
Walter-Benjamin-Platz 8
10629 Berlin
Deutschland
Tel.: +49 (30) 536506-716
E-Mail: privacy@requisis.com
Website: https://requisis.com
Types of Data Processed
Inventory data (e.g., names, addresses).
- Contact data (e.g., email addresses, phone numbers).
- Content data (e.g., text inputs, photographs, videos).
- Usage data (e.g., visited websites, interest in content, access times).
- Meta-/communication data (e.g., device information, IP addresses).
Categories of Affected Individuals
Visitors and users of the online service (hereinafter, we collectively refer to these individuals as “users”), as well as customers and prospective customers of REQUISIS GmbH.
Purpose of Processing
- Provision of the online offering, its functions and content.
- Responding to contact requests and communicating with users.
- Security measures.
- Reach measurement / marketing.
- Order processing.
- Service & customer support.
- Customer relationship management.
Terminology Used
"Personal data"means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Processing"means any operation or set of operations performed with or without the aid of automated means in connection with personal data. The term is broad and covers virtually any handling of data.
"Pseudonymisation"means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data cannot be attributed to an identified or identifiable natural person.
"Profiling"means any form of automated processing of personal data consisting of the use of such data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
The term "controller"refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
"Processor"means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Relevant Legal Bases
In accordance with Art. 13 GDPR, we inform you of the legal bases for our data processing. Where the legal basis is not stated in this privacy policy, the following applies: The legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR; the legal basis for processing in order to fulfil our services and carry out contractual measures as well as to respond to enquiries is Art. 6(1)(b) GDPR; the legal basis for processing to fulfil our legal obligations is Art. 6(1)(c) GDPR; and the legal basis for processing to protect our legitimate interests is Art. 6(1)(f) GDPR. Where the processing of personal data is necessary in order to protect the vital interests of the data subject or of another natural person, Art. 6(1)(d) GDPR serves as the legal basis.
Security Measures
In accordance with Art. 32 GDPR and taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include in particular ensuring the confidentiality, integrity and availability of data by controlling physical access to the data, as well as access to, input of, disclosure of, and the securing of the availability and separation of such data. Furthermore, we have established procedures to ensure the exercise of data subject rights, the deletion of data, and the ability to respond to data security incidents. We also take the protection of personal data into account from the outset when developing or selecting hardware, software and processes, in accordance with the principle of data protection by design and by default (Art. 25 GDPR).
Cooperation with Data Processors and Third Parties
Where we disclose data to other persons and companies (processors or third parties), transmit data to them, or otherwise grant them access to data in the course of our processing, this is done only on the basis of a legal permission (e.g. where the transmission of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Art. 6(1)(b) GDPR), where you have given your consent, where a legal obligation provides for this, or on the basis of our legitimate interests (e.g. when engaging agents, web hosting providers, etc.).
Where we engage third parties to process data on the basis of a so-called "data processing agreement", this is done on the basis of Art. 28 GDPR.
Transfers to Third Countries
Where we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in the context of using third-party services or disclosing or transferring data to third parties, this takes place only where it is necessary for the fulfilment of our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation, or on the basis of our legitimate interests. Subject to statutory or contractual permissions, we process or have data processed in a third country only where the specific requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of specific guarantees, such as the officially recognised determination of a level of data protection equivalent to that of the EU (e.g. for the USA through the EU-US Data Privacy Framework), or compliance with officially recognised special contractual obligations (so-called "standard contractual clauses").
Collection of General Data and Information
Each time the website of REQUISIS GmbH is accessed by a data subject or an automated system, a range of general data and information is collected. This general data and information is stored in the server log files. The data collected may include (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrers), (4) the sub-pages accessed on our website via an accessing system, (5) the date and time of access to the website, (6) an Internet Protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) other similar data and information that serves to avert threats in the event of attacks on our information technology systems.
When using this general data and information, REQUISIS GmbH does not draw any conclusions about the data subject. Rather, this information is required in order to (1) deliver the content of our website correctly, (2) optimise the content of our website and the advertising for it, (3) ensure the long-term functionality of our information technology systems and the technology of our website, and (4) provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack. The anonymously collected data and information is therefore evaluated by REQUISIS GmbH on a statistical basis and with the aim of increasing data protection and data security within our company, in order to ultimately ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files is stored separately from all personal data provided by a data subject.
Cookies and the Right to Object to Direct Marketing
"Cookies" are small files stored on users' computers. Cookies can store various types of information. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or after their visit to an online offering. Cookies that are deleted after a user leaves an online offering and closes their browser are referred to as temporary cookies, "session cookies" or "transient cookies". Such a cookie may store, for example, the contents of a shopping cart in an online shop or a login status. Cookies that remain stored even after the browser is closed are referred to as "permanent" or "persistent" cookies. For example, the login status can be stored so that users can retrieve it after several days. Such cookies can also store users' interests, which are used for reach measurement or marketing purposes. "Third-party cookies" are cookies offered by providers other than the controller operating the online offering (where only the controller's own cookies are used, these are referred to as "first-party cookies").
We may use temporary and permanent cookies, and provide information about this in our privacy policy.
If users do not wish to have cookies stored on their computer, they are asked to disable the relevant option in their browser's system settings. Stored cookies can be deleted in the browser's system settings. Disabling cookies may result in functional limitations of this online offering.
A general objection to the use of cookies for online marketing purposes can be raised for a large number of services, particularly in the case of tracking, via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, cookies can be prevented from being stored by disabling them in the browser settings. Please note that in this case it may not be possible to use all functions of this online offering.
Deletion of Data
The data processed by us is deleted or its processing restricted in accordance with Art. 17 and 18 GDPR. Unless expressly stated in this privacy policy, the data stored by us is deleted as soon as it is no longer required for its intended purpose and no statutory retention obligations preclude deletion. Where data is not deleted because it is required for other legally permissible purposes, its processing is restricted. This means the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
Under statutory requirements in Germany, retention applies in particular for 10 years pursuant to §§ 147(1) AO, 257(1) nos. 1 and 4, (4) HGB (books, records, management reports, accounting documents, commercial books, documents relevant for taxation, etc.) and for 6 years pursuant to § 257(1) nos. 2 and 3, (4) HGB (commercial letters).
Under statutory requirements in Austria, retention applies in particular for 7 years pursuant to § 132(1) BAO (accounting records, vouchers/invoices, accounts, documents, business papers, records of income and expenditure, etc.), for 22 years in connection with real property, and for 10 years for documents relating to electronically supplied services, telecommunications, broadcasting and television services provided to non-entrepreneurs in EU member states for which the Mini-One-Stop-Shop (MOSS) is used.
Business-Related Processing
We additionally process
- Contract data (e.g., subject matter of contract, duration, customer category).
- Payment data (e.g., bank details, payment history)
from our customers, prospective customers and business partners for the purposes of providing contractual services, customer service and relationship management, marketing, advertising and market research.
Use of Artificial Intelligence (AI)
Claude (Anthropic)
We use the AI system "Claude" by Anthropic, PBC (San Francisco, USA) to support internal workflows, including the drafting and summarisation of texts, the analysis of documents, the creation and review of source code, and the drafting and summarisation of emails. A personal reference arises only indirectly, to the extent that inputs by our employees contain personal data (e.g. in emails, documents or tickets).
Data processed:
Identification and contact data (e.g. name, email address)
as well as content data from internal emails, documents and tickets, to the extent entered by the employee. We generally avoid processing special categories of personal data within the meaning of Art. 9 GDPR and, where necessary in individual cases, limit such processing to the minimum required; given the volume of communications processed, however, we cannot entirely exclude the possibility that such data may be inadvertently included.
Purpose of data processing:
Efficient fulfilment of internal work tasks and support of operational processes.
Legal basis:
Art. 6(1)(f) GDPR (legitimate interest in efficient task fulfilment); where employee data is processed, additionally § 26 BDSG in conjunction with Art. 88 GDPR.
Data processing agreement and third-country transfer:
The use of this service is based on a data processing agreement (DPA) with Anthropic, PBC, which automatically forms part of the contractual terms of use. Since processing takes place in the USA (a third country), we rely on the EU Standard Contractual Clauses (Module 2, Art. 46 GDPR) included in the DPA; an additional certification of Anthropic under the EU-US Data Privacy Framework is possible and can be verified on the official DPF list.
Security measures:
- Your data is not used to train or improve the underlying AI models.
- Access is restricted to REQUISIS and its employees.
- All processed data is automatically deleted by the provider after no more than 30 days.
Retention period:
Standard retention at the processor's end is approximately 30 days, after which automatic deletion takes place. Internally, inputs are not stored permanently beyond the completion of the relevant task.
Your right to object as a customer or business partner:
If you wish to restrict the processing of data exchanged with us by AI systems, you may:
- mark individual emails, documents or tickets with one of the keywords no-ai-processing, vertraulich, confidential, geheim, secret or persönlich (e.g. in the subject line, file name, ticket title or as a tag), or
- notify us in writing of one or more email domains that you wish to have excluded entirely from processing by AI systems.
Such marking or notification takes effect only for the future; content that has already been processed is not covered retroactively.
Further information:
Information on data protection at Anthropic can be found at anthropic.com/legal/privacy.
Order Processing in the Online Store and Customer Account
We process our customers' data in the context of order transactions in our online shop in order to enable them to select and order the chosen products and services, as well as to process payment and delivery or performance thereof.
The data processed includes inventory data, communication data, contract data and payment data; the persons affected by the processing include our customers, prospective customers and other business partners. Processing is carried out for the purpose of providing contractual services in the context of operating an online shop, billing, delivery and customer services. For this purpose, we use session cookies to store the contents of the shopping cart and permanent cookies to store the login status.
Processing is carried out on the basis of Art. 6(1)(b) (execution of order transactions) and (c) (legally required archiving) GDPR. The information marked as mandatory is required for the establishment and fulfilment of the contract. We disclose data to third parties only in the context of delivery and payment, or within the framework of legal permissions and obligations vis-à-vis legal advisors and authorities. Data is processed in third countries only where this is necessary for the performance of the contract (e.g. at the customer's request in the case of delivery or payment).
Users may optionally create a user account, through which they can view their orders in particular. The required mandatory information is communicated to users at the time of registration. User accounts are not public and cannot be indexed by search engines. Where users have terminated their user account, their data relating to the user account will be deleted, unless retention is required for commercial or tax law reasons pursuant to Art. 6(1)(c) GDPR. Information in the customer account is retained until it is deleted, followed by archiving in the event of a legal obligation. It is the responsibility of users to back up their data prior to the end of the contract in the event of termination.
In the context of registration, subsequent logins and use of our online services, we store the IP address and the time of the respective user action. Storage is carried out on the basis of our legitimate interests as well as those of users in protection against misuse and other unauthorised use. This data is not generally passed on to third parties, unless such disclosure is necessary to pursue our claims or there is a statutory obligation to do so pursuant to Art. 6(1)(c) GDPR.
Deletion takes place upon expiry of statutory warranty and comparable obligations; the necessity of retaining the data is reviewed every three years. In the case of statutory archiving obligations, deletion takes place upon their expiry (end of the commercial law retention period (6 years) and the tax law retention period (10 years)).
Ticketing System
As part of order processing and systematic operations, we use a ticket system.
The data required for the respective process is collected and stored in the ticket system.
The ticket system may also be used by the customer or user.
In this case, the customer enters the data themselves.
In particular, the following data is collected and stored:
- Personal data (email address, name, company)
- Description of the (support) incident
- Communication content
- Attachments, where applicable
License Management
To manage the licences we issue for our software products, we use a licence management system.
In the context of order processing and customer support, the following data in particular is collected and stored in the licence management system:
- Personal data of the primary licence user, the commercial contact and the technical contact, including name, telephone number, email address and postal address.
- Licence data: type of licence, licence validity, software maintenance period, comments and notes on the history.
- Communication content.
Agency Services
We process our customers' data in the context of our contractual services, which include conceptual and strategic consulting, campaign planning, software and design development/consulting or maintenance, implementation of campaigns and processes/handling, server administration, data analysis/consulting services and training services.
In this context, we process inventory data (e.g. customer master data such as names or addresses), contact data (e.g. email addresses, telephone numbers), content data (e.g. text inputs, photographs, videos), contract data (e.g. subject matter of contract, duration), payment data (e.g. bank details, payment history), and usage and metadata (e.g. in the context of evaluating and measuring the success of marketing activities). We do not generally process special categories of personal data, unless these form part of a commissioned processing task. Data subjects include our customers, prospective customers and their customers, users, website visitors or employees, as well as third parties. The purpose of processing is the provision of contractual services, billing and customer service. The legal bases for processing arise from Art. 6(1)(b) GDPR (contractual services) and Art. 6(1)(f) GDPR (analysis, statistics, optimisation, security measures). We process data that is necessary for the establishment and fulfilment of contractual services and indicate where the provision of such data is required. Disclosure to third parties takes place only where necessary in the context of a commission. When processing data made available to us in the context of a commission, we act in accordance with the instructions of the client and the statutory requirements for commissioned processing pursuant to Art. 28 GDPR, and do not process the data for any purposes other than those specified in the commission.
We delete data upon expiry of statutory warranty and comparable obligations; the necessity of retaining the data is reviewed every three years. In the case of statutory archiving obligations, deletion takes place upon their expiry (6 years pursuant to § 257(1) HGB, 10 years pursuant to § 147(1) AO). In the case of data disclosed to us by the client in the context of a commission, we delete the data in accordance with the requirements of the commission, generally upon its completion.
Additional contractual services
We process the data of our contractual partners and prospective customers, as well as other clients, customers and contracting parties (collectively referred to as "contractual partners") pursuant to Art. 6(1)(b) GDPR, in order to provide them with our contractual or pre-contractual services. The data processed in this context, as well as the nature, scope, purpose and necessity of its processing, are determined by the underlying contractual relationship.
The data processed includes the master data of our contractual partners (e.g. names and addresses), contact data (e.g. email addresses and telephone numbers), contract data (e.g. services used, contract contents, contractual correspondence, names of contact persons) and payment data (e.g. bank details, payment history).
We do not generally process special categories of personal data, unless these form part of a commissioned or contractually required processing task.
We process data that is necessary for the establishment and fulfilment of contractual services and, where this is not self-evident to the contractual partner, indicate that its provision is required. Disclosure to external persons or companies takes place only where necessary in the context of a contract. When processing data made available to us in the context of a commission, we act in accordance with the instructions of the client and the applicable statutory requirements.
In the context of the use of our online services, we may store the IP address and the time of the respective user action. Storage is carried out on the basis of our legitimate interests as well as the interests of users in protection against misuse and other unauthorised use. This data is not generally passed on to third parties, unless such disclosure is necessary to pursue our claims pursuant to Art. 6(1)(f) GDPR or there is a statutory obligation to do so pursuant to Art. 6(1)(c) GDPR.
Data is deleted when it is no longer required for the fulfilment of contractual or statutory duties of care and for dealing with any warranty and comparable obligations; the necessity of retaining the data is reviewed every three years. Statutory retention obligations apply in all other respects.
Contact Us
When you contact us (e.g. via contact form, email, telephone or social media), the information provided by the user is processed for the purpose of handling and processing the contact request pursuant to Art. 6(1)(b) GDPR. User information may be stored in a customer relationship management system ("CRM system") or a comparable request management system.
We delete entries in the CRM system once they are no longer required. We review the necessity of retention every two years; statutory archiving obligations apply in addition.
Below we provide information on how we handle the various communication channels.
Communication by email
- Complete storage as necessary to ensure operational continuity and compliance with statutory requirements.
- Full content of the communication, including any personal data contained therein.
- Retention for an indefinite period; deletion is generally the responsibility of the respective recipient.
- Long-term archiving may apply where applicable.
Communication by letter
- Electronic recording of all incoming and outgoing mail.
- Text recognition, indexing of content, manual tagging where applicable, storage in a central location.
- Complete storage as necessary to ensure operational continuity and compliance with statutory requirements.
- Full content of the communication, including any personal data contained therein.
- Long-term archiving may apply where applicable.
Communication by telephone
We store call logs of incoming and outgoing calls to optimise operational processes (e.g. CTI) and to ensure the traceability of business transactions.
Data collected:
- Full telephone number, unabbreviated.
- Time and duration of the call.
- Employee within the company involved in the call.
In individual cases, calls may be recorded:
- Recording initiated by the employee within the company.
- Recordings in the context of quality assurance.
- Recordings in the context of documentation obligations (in particular upon conclusion of contracts).
Customer Relation Management
HubSpot
On our website we use the services of HubSpot, a leading provider of marketing, sales and customer service software. HubSpot helps us to analyse interactions with our visitors and to improve our services.
Data collected:
The following data may be collected when using HubSpot:
- IP address
- Information about usage behaviour on our website
- Contact data that you voluntarily provide to us (e.g. when registering or submitting enquiries)
Purpose of data processing:
The data is used to:
- analyse the use of our website
- optimise marketing activities
- provide you with personalised content and offers
Disclosure of data:
We do not pass your data on to third parties unless this is necessary for the purposes stated above or required by law.
Your rights:
You have the right to request information about the data stored about you, to have it corrected or deleted. You may also object to the processing of your data.
Further information:
For detailed information on data processing by HubSpot and your rights, please refer to HubSpot's privacy policy: HubSpot Privacy Policy.
By using our website, you consent to the processing of your data by HubSpot to the extent described above.
Registration Feature
Users may create a user account. During registration, the required mandatory information is communicated to users and processed on the basis of Art. 6(1)(b) GDPR for the purpose of providing the user account. The data processed includes in particular the login information (name, password and an email address). The data entered during registration is used for the purposes of using the user account and its intended function.
Users may be informed by email about information relevant to their user account, such as technical changes. Where users have terminated their user account, their data relating to the user account will be deleted, subject to any statutory retention obligation. It is the responsibility of users to back up their data prior to the end of the contract in the event of termination. We are entitled to permanently delete all data stored during the term of the contract.
In the context of the use of our registration and login functions and the use of the user account, we store the IP address and the time of the respective user action. Storage is carried out on the basis of our legitimate interests as well as the interests of users in protection against misuse and other unauthorised use. This data is not generally passed on to third parties, unless such disclosure is necessary to pursue our claims or there is a statutory obligation to do so pursuant to Art. 6(1)(c) GDPR. IP addresses are anonymised or deleted no later than 7 days after collection.
Newsletter
The following information sets out the content of our newsletter, the registration, distribution and statistical evaluation procedures, and your right to object. By subscribing to our newsletter, you consent to receiving it and to the procedures described.
Content of the newsletter: We send newsletters, emails and other electronic notifications containing promotional information (hereinafter "newsletter") only with the consent of the recipients or on the basis of a statutory permission. Where the content of the newsletter is specifically described at the time of registration, that description is binding for the purposes of user consent. Otherwise, our newsletters contain information about our services and our company.
Double opt-in and logging: Registration for our newsletter takes place using a so-called double opt-in procedure. This means that after registering you will receive an email asking you to confirm your registration. This confirmation is necessary to prevent anyone from registering with another person's email address. Newsletter registrations are logged in order to demonstrate the registration process in accordance with legal requirements. This includes storing the time of registration and confirmation, as well as the IP address. Changes to the data stored with the distribution service provider are also logged.
Registration data: To subscribe to the newsletter, it is sufficient to provide your email address. Optionally, we ask you to provide a name for the purpose of personal address in the newsletter.
The distribution of the newsletter and the associated success measurement are carried out on the basis of recipients' consent pursuant to Art. 6(1)(a) and Art. 7 GDPR in conjunction with § 7(2) no. 3 UWG, or, where consent is not required, on the basis of our legitimate interests in direct marketing pursuant to Art. 6(1)(f) GDPR in conjunction with § 7(3) UWG.
The logging of the registration procedure is carried out on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR. Our interest is directed towards operating a user-friendly and secure newsletter system that serves both our business interests and the expectations of users, and that also enables us to demonstrate consent.
The newsletters of REQUISIS GmbH contain so-called tracking pixels. A tracking pixel is a miniature graphic embedded in emails sent in HTML format to enable log file recording and analysis. This allows a statistical evaluation of the success or failure of online marketing campaigns. By means of the embedded tracking pixel, REQUISIS GmbH can determine whether and when an email was opened by a data subject and which links contained in the email were accessed by the data subject.
Personal data collected via tracking pixels contained in newsletters is stored and evaluated by the controller in order to optimise newsletter distribution and to tailor the content of future newsletters more closely to the interests of the data subject. This personal data is not passed on to third parties. Data subjects are entitled at any time to revoke the separate declaration of consent given via the double opt-in procedure. Following revocation, this personal data will be deleted by the controller. REQUISIS GmbH automatically treats an unsubscribe from the newsletter as a revocation.
Cancellation/revocation — You may cancel your subscription to our newsletter at any time, i.e. revoke your consent. A link to unsubscribe from the newsletter can be found at the end of each newsletter. We may retain unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to demonstrate that consent was previously given. The processing of this data is restricted to the purpose of defending against potential claims. An individual request for deletion is possible at any time, provided that the prior existence of consent is confirmed at the same time.
Newsletter — HubSpot
Newsletters are sent via the distribution service provider "HubSpot".
The privacy policy of the distribution service provider can be viewed here: HubSpot Privacy Policy
HubSpot, Inc. is certified under the EU-US Data Privacy Framework (DPF) and thereby provides a guarantee of maintaining a level of data protection equivalent to that of the EU. The certification can be verified via the official DPF participant list ([www.dataprivacyframework.gov](https://www.dataprivacyframework.gov)).
The distribution service provider is engaged on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR and a data processing agreement pursuant to Art. 28(3) sentence 1 GDPR.
Online-Marketing
Google Tag Manager
Google Tag Manager is a solution that allows us to manage so-called website tags via a single interface (and thereby integrate Google Analytics and other Google marketing services into our online offering). The Tag Manager itself (which implements the tags) does not process any personal data of users. With regard to the processing of users' personal data, please refer to the following information on Google services. Usage policy: https://www.google.com/intl/de/tagmanager/use-policy.html.
Google Analytics
On the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and economical operation of our online offering within the meaning of Art. 6(1)(f) GDPR), we use Google Analytics, a web analytics service provided by Google LLC ("Google"). Google uses cookies. The information generated by the cookie about users' use of the online offering is generally transmitted to a Google server in the USA and stored there.
Google LLC is certified under the EU-US Data Privacy Framework (DPF) and thereby provides a guarantee of maintaining a level of data protection equivalent to that of the EU. The certification can be verified via the official DPF participant list ([www.dataprivacyframework.gov](https://www.dataprivacyframework.gov)).
Google will use this information on our behalf to evaluate users' use of our online offering, to compile reports on activity within this online offering, and to provide us with further services associated with the use of this online offering and internet use in general. Pseudonymous usage profiles of users may be created from the processed data.
We only use Google Analytics with IP anonymisation enabled. This means that users' IP addresses are truncated by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there.
The IP address transmitted by the user's browser is not merged with other data held by Google. Users can prevent the storage of cookies by adjusting their browser software settings; users can also prevent the collection by Google of data generated by the cookie and relating to their use of the online offering, and the processing of such data by Google, by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
For further information on data use by Google, and on options for settings and objection, please refer to Google's privacy policy (https://policies.google.com/technologies/ads) and Google's ad settings (https://adssettings.google.com/authenticated).
Users' personal data is deleted or anonymised after 14 months.
Google Universal Analytics
We use Google Analytics in the form of "Universal Analytics". "Universal Analytics" refers to a Google Analytics method by which user analysis is carried out on the basis of a pseudonymous user ID, thereby creating a pseudonymous profile of the user with information from their use of various devices (so-called "cross-device tracking").
Audience building with Google Analytics
We use Google Analytics to display advertisements placed within Google's advertising services and those of its partners only to users who have shown an interest in our online offering, or who exhibit certain characteristics (e.g. interests in particular topics or products, as determined by the websites visited) that we transmit to Google (so-called "remarketing" or "Google Analytics Audiences"). With the help of Remarketing Audiences, we also aim to ensure that our advertisements correspond to the potential interests of users.
Google AdWords and conversion tracking
On the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and economical operation of our online offering within the meaning of Art. 6(1)(f) GDPR), we use the services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google").
Google LLC is certified under the EU-US Data Privacy Framework (DPF) and thereby provides a guarantee of maintaining a level of data protection equivalent to that of the EU. The certification can be verified via the official DPF participant list ([www.dataprivacyframework.gov](https://www.dataprivacyframework.gov)).
We use the online marketing method Google AdWords to place advertisements in the Google advertising network (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who have a presumed interest in the advertisements. This allows us to display advertisements for and within our online offering in a more targeted manner, so that users are only shown advertisements that potentially correspond to their interests. If, for example, a user is shown advertisements for products in which they have shown an interest on other online offerings, this is referred to as "remarketing". For these purposes, when our website and other websites on which the Google advertising network is active are accessed, Google directly executes a code and so-called (re)marketing tags (invisible graphics or code, also referred to as "web beacons") are integrated into the website. These are used to store an individual cookie — i.e. a small file — on the user's device (comparable technologies may be used instead of cookies). This file records which websites the user has visited, which content they have shown an interest in, which offers the user has clicked on, as well as technical information about the browser and operating system, referring websites, time of visit and further details about the use of the online offering.
We also receive an individual "conversion cookie". The information obtained with the help of the cookie is used by Google to compile conversion statistics for us. However, we only learn the anonymous total number of users who clicked on our advertisement and were redirected to a page equipped with a conversion tracking tag. We do not receive any information that would allow users to be personally identified.
Users' data is processed pseudonymously within the Google advertising network. This means that Google does not store or process, for example, users' names or email addresses, but instead processes the relevant data on a cookie-related basis within pseudonymous user profiles. From Google's perspective, the advertisements are therefore not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who that cookie holder is. This does not apply where a user has expressly permitted Google to process the data without this pseudonymisation. The information collected about users is transmitted to Google and stored on Google's servers in the USA.
For further information on data use by Google, and on options for settings and objection, please refer to Google's privacy policy (https://policies.google.com/technologies/ads) and Google's ad settings (https://adssettings.google.com/authenticated).
Integration of Third-Party Services and Content
Within our online offering, we use content or service offerings from third-party providers on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and economical operation of our online offering within the meaning of Art. 6(1)(f) GDPR) in order to integrate their content and services, such as videos or fonts (hereinafter collectively referred to as "content").
This always requires that the third-party providers of such content are able to access users' IP addresses, as they would be unable to send the content to users' browsers without the IP address. The IP address is therefore necessary for the display of this content. We endeavour to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. Pixel tags can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on users' devices and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and further details about the use of our online offering, and may be combined with such information from other sources.
YouTube
We integrate videos from the platform "YouTube", provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy/, Opt-out: https://adssettings.google.com/authenticated.
Google Fonts
We integrate fonts ("Google Fonts") provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy/, Opt-out: https://adssettings.google.com/authenticated.
Google Maps
We integrate maps from the service "Google Maps", provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The data processed may include in particular users' IP addresses and location data, which are not collected without their consent (generally given via the settings of their mobile devices). The data may be processed in the USA. Privacy policy: https://www.google.com/policies/privacy/, Opt-out: https://adssettings.google.com/authenticated.
Google+
Functions and content of the Google+ platform, offered by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"), may be integrated within our online offering. These may include, for example, content such as images, videos or text and buttons that allow users to share content from this online offering on Google+. Where users are members of the Google+ platform, Google may associate the retrieval of the above-mentioned content and functions with users' profiles on that platform.
Google is certified under the Privacy Shield agreement and thereby provides a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). For further information on data use by Google, and on options for settings and objection, please refer to Google's privacy policy (https://policies.google.com/technologies/ads) and Google's ad settings (https://adssettings.google.com/authenticated).
Rights of Data Subjects
You have the right to request confirmation as to whether data concerning you is being processed, and to obtain information about that data as well as further details and a copy of the data in accordance with Art. 15 GDPR.
You have the right, pursuant to Art. 16 GDPR, to request the completion of data concerning you or the rectification of inaccurate data concerning you.
You have the right, in accordance with Art. 17 GDPR, to request that data concerning you be deleted without undue delay, or alternatively, in accordance with Art. 18 GDPR, to request a restriction of the processing of the data.
You have the right to receive the data concerning you that you have provided to us, in accordance with Art. 20 GDPR, and to request its transmission to other controllers.
You also have the right, pursuant to Art. 77 GDPR, to lodge a complaint with the competent supervisory authority.
Right of withdrawal
You have the right to withdraw consent you have given pursuant to Art. 7(3) GDPR with effect for the future.
Right to object
You may object at any time to the future processing of data concerning you in accordance with Art. 21 GDPR. The objection may in particular be made against processing for the purposes of direct marketing.