Privacy policy
Privacy Policy
As of: 1 March 2023
Table of contents
Controller
Overview of processing operations
Relevant legal bases
Security measures
Transfer of personal data
Data processing in third countries
Deletion of data
Use of cookies
Business services
Providers and services used in the course of business
Provision of the online offering and web hosting
Blogs and publication media
Contact and enquiry management
Promotional communication via email, post, fax or telephone
Web analytics, monitoring and optimisation
Online marketing
Plugins and embedded functions and content
Amendment and update of the privacy policy
Rights of data subjects
Controller
Controller within the meaning of the GDPR:
Fortis Inkasso GmbH & Co. KG
Gehrtsstraße 16
40235 Düsseldorf
Germany
Email: info@fortis-inkasso.de
Represented by its general partner Fortis Verwaltungs GmbH.
Overview of processing operations
The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects.
Types of data processed
Inventory data.
Payment data.
Contact data.
Content data.
Contract data.
Usage data.
Meta, communication and procedural data.
Categories of data subjects
Customers.
Interested parties.
Communication partners.
Users.
Business and contractual partners.
Purposes of processing
Provision of contractual services and customer service.
Contact requests and communication.
Security measures.
Direct marketing.
Reach measurement.
Tracking.
Office and organisational procedures.
Conversion measurement.
Management and response to enquiries.
Feedback.
Marketing.
Profiles with user-related information.
Provision of our online offering and user-friendliness.
Information technology infrastructure.
Relevant legal bases
Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.
Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR) – The data subject has given their consent to the processing of the personal data concerning them for a specific purpose or several specific purposes.
Performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data.
In addition to the data protection provisions of the GDPR, national data protection provisions apply in Germany. These include in particular the Act on Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes and transmission, as well as automated decision-making in individual cases including profiling. Furthermore, it governs data processing for the purposes of the employment relationship (Section 26 BDSG), in particular with regard to the establishment, performance or termination of employment relationships and the consent of employees. Data protection laws of the individual federal states may also apply.
Security measures
In accordance with the legal requirements and taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
The measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, safeguarding of availability and separation relating to it. Furthermore, we have set up procedures that ensure the exercise of data subjects’ rights, the deletion of data and responses to threats to the data. Furthermore, we already take into account the protection of personal data during the development or selection of hardware, software and procedures in accordance with the principle of data protection by design and by privacy-friendly default settings.
Transfer of personal data
In the course of our processing of personal data, it may happen that the data is transferred to, or disclosed to, other entities, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.
Data processing in third countries
If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if the processing takes place in the context of using third-party services or the disclosure or transfer of data to other persons, entities or companies, this only takes place in accordance with the legal requirements.
Subject to express consent or transfer required by contract or law, we only process or have the data processed in third countries with a recognised level of data protection, contractual obligation through so-called standard contractual clauses of the EU Commission, in the presence of certifications or binding internal data protection rules (Art. 44 to 49 GDPR, information page of the EU Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).
Deletion of data
The data processed by us is deleted in accordance with the legal requirements as soon as the consents permitting processing are revoked or other permissions cease to apply (e.g. if the purpose of processing this data no longer applies or it is not required for the purpose). If the data is not deleted because it is required for other and legally permissible purposes, its processing is limited to these purposes. This means the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose storage is necessary for the assertion, exercise or defence of legal claims or for the protection of the rights of another natural or legal person.
Our data protection notices may also contain further information on the retention and deletion of data that take precedence for the respective processing operations.
Use of cookies
Cookies are small text files, or other storage markers, that store information on end devices and read information from end devices. For example, to store the login status in a user account, the contents of a shopping cart in an e-shop, the content accessed or functions used of an online offering. Cookies can also be used for various purposes, e.g. for the functionality, security and convenience of online offerings and to create analyses of visitor flows.
Notes on consent: We use cookies in accordance with the legal provisions. Therefore, we obtain prior consent from users, unless this is not required by law. Consent is in particular not necessary if the storage and reading of the information, including cookies, are strictly necessary in order to provide users with a telemedia service (i.e. our online offering) they have expressly requested. The revocable consent is clearly communicated to users and contains the information on the respective cookie use.
Notes on the data protection legal bases: The data protection legal basis on which we process users’ personal data with the help of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is the declared consent. Otherwise, the data processed with the help of cookies is processed on the basis of our legitimate interests (e.g. in the commercial operation of our online offering and the improvement of its usability) or, if this takes place within the framework of the performance of our contractual obligations, if the use of cookies is necessary to fulfil our contractual obligations. We clarify the purposes for which we process cookies in the course of this privacy policy or within the framework of our consent and processing procedures.
Storage period: With regard to the storage period, the following types of cookies are distinguished:
Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offering and closed their end device (e.g. browser or mobile application).
Permanent cookies: Permanent cookies remain stored even after the end device is closed. For example, the login status can be stored or preferred content can be displayed directly when the user visits a website again. Likewise, the user data collected with the help of cookies can be used for reach measurement. Insofar as we do not provide users with explicit information on the type and storage period of cookies (e.g. when obtaining consent), users should assume that cookies are permanent and that the storage period can be up to two years.
General notes on revocation and objection (opt-out): Users can revoke the consents they have given at any time and also object to the processing in accordance with the legal requirements in Art. 21 GDPR. Users can also declare their objection via the settings of their browser, e.g. by deactivating the use of cookies (whereby this may also restrict the functionality of our online services). An objection to the use of cookies for online marketing purposes can also be declared via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/.
Further notes on processing operations, procedures and services:
Processing of cookie data on the basis of consent: We use a cookie consent management procedure, within the framework of which the consents of users to the use of cookies, or the processing operations and providers named within the cookie consent management procedure, can be obtained as well as managed and revoked by users. The declaration of consent is stored so that it does not have to be requested again and so that the consent can be proven in accordance with the legal obligation. Storage can take place on the server side and/or in a cookie (so-called opt-in cookie, or with the help of comparable technologies) in order to be able to assign the consent to a user or their device. Subject to individual information about the providers of cookie management services, the following notes apply: The duration of the storage of the consent can be up to two years. A pseudonymous user identifier is formed and stored with the time of consent, information on the scope of the consent (e.g. which categories of cookies and/or service providers) as well as the browser, system and end device used.
Business services
We process data of our contractual and business partners, e.g. customers and interested parties (collectively referred to as “contractual partners”), within the framework of contractual and comparable legal relationships and associated measures, and within the framework of communication with the contractual partners (or pre-contractually), e.g. to answer enquiries.
We process this data to fulfil our contractual obligations. This includes in particular the obligations to provide the agreed services, any update obligations and remedy in the event of warranty and other performance disruptions. In addition, we process the data to safeguard our rights and for the purpose of the administrative tasks associated with these obligations, as well as the organisation of the company. Furthermore, we process the data on the basis of our legitimate interests in proper and commercial business management, as well as in security measures to protect our contractual partners and our business operations from misuse, threats to their data, secrets, information and rights (e.g. for the involvement of telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Within the scope of applicable law, we only pass on the data of contractual partners to third parties insofar as this is necessary for the aforementioned purposes or to fulfil legal obligations. Contractual partners are informed about further forms of processing, e.g. for marketing purposes, within the framework of this privacy policy.
We inform the contractual partners which data is required for the aforementioned purposes before or in the course of data collection, e.g. in online forms, by means of special marking (e.g. colours) or symbols (e.g. asterisks or similar), or in person.
We delete the data after expiry of statutory warranty and comparable obligations, i.e. in principle after 4 years, unless the data is stored in a customer account, e.g. as long as it must be retained for legal reasons of archiving. The statutory retention period for tax-relevant documents as well as for commercial books, inventories, opening balance sheets, annual financial statements, the work instructions and other organisational documents required to understand these documents and accounting vouchers is ten years, and for received commercial and business letters and reproductions of the dispatched commercial and business letters six years. The period begins with the end of the calendar year in which the last entry was made in the book, the inventory, opening balance sheet, annual financial statement or management report was drawn up, the commercial or business letter was received or dispatched, or the accounting voucher was created, and also in which the record was made or the other documents were created.
Insofar as we use third-party providers or platforms to provide our services, the terms and conditions and data protection notices of the respective third-party providers or platforms apply in the relationship between the users and the providers.
Types of data processed: inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. email, telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
Data subjects: customers; interested parties; business and contractual partners.
Purposes of processing: provision of contractual services and customer service; security measures; contact requests and communication; office and organisational procedures; management and response to enquiries.
Legal bases: performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Customer account: Contractual partners can create an account within our online offering (e.g. customer or user account, “customer account” for short). If the registration of a customer account is required, contractual partners are informed of this as well as of the information required for registration. The customer accounts are not public and cannot be indexed by search engines. Within the framework of registration and subsequent logins and use of the customer account, we store the IP addresses of the customers along with the access times in order to be able to prove the registration and to prevent any misuse of the customer account. If customers have terminated their customer account, the data relating to the customer account is deleted, subject to its retention being required for legal reasons. It is incumbent on customers to secure their data upon termination of the customer account; legal bases: performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Shop and e-commerce: We process the data of our customers in order to enable them to select, purchase or order the chosen products, goods and associated services, as well as their payment and delivery or execution. Insofar as necessary for the execution of an order, we use service providers, in particular postal, freight and shipping companies, to carry out the delivery or execution vis-à-vis our customers. For the handling of the payment transactions, we use the services of banks and payment service providers. The required information is marked as such within the framework of the order or comparable purchase process and includes the information required for delivery or provision and billing as well as contact information in order to be able to hold any consultation; legal bases: performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Providers and services used in the course of business
In the course of our business activities, we use, in compliance with the legal requirements, additional services, platforms, interfaces or plug-ins from third-party providers (“services” for short). Their use is based on our interests in the proper, lawful and economic management of our business operations and our organisational measures.
Types of data processed: inventory data (e.g. names, addresses); payment data (e.g. bank details, invoices, payment history); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); contract data (e.g. subject matter of the contract, term, customer category).
Data subjects: customers; interested parties; users (e.g. website visitors, users of online services); business and contractual partners.
Purposes of processing: provision of contractual services and customer service; office and organisational procedures.
Legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Provision of the online offering and web hosting
We process the data of users in order to be able to provide them with our online services. For this purpose, we process the IP address of the user, which is necessary in order to transmit the content and functions of our online services to the browser or end device of the users.
Types of data processed: usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status); content data (e.g. entries in online forms).
Data subjects: users (e.g. website visitors, users of online services).
Purposes of processing: provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)); security measures.
Legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Collection of access data and log files: Access to our online offering is logged in the form of so-called “server log files”. The server log files may include the address and name of the accessed web pages and files, the date and time of access, the transferred data volumes, notification of successful access, browser type and version, the operating system of the user, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files can be used, on the one hand, for security purposes, e.g. to avoid overloading the servers (in particular in the case of abusive attacks, so-called DDoS attacks) and, on the other hand, to ensure the utilisation of the servers and their stability; legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); deletion of data: log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further retention is required for evidentiary purposes is excluded from deletion until the respective incident has been finally clarified.
Email dispatch and hosting: The web hosting services we use also include the dispatch, receipt and storage of emails. For these purposes, the addresses of the recipients and senders as well as further information concerning the email dispatch (e.g. the providers involved) and the contents of the respective emails are processed. The aforementioned data may also be processed for the purposes of detecting SPAM. Please note that emails on the internet are generally not sent in encrypted form. As a rule, emails are encrypted in transit, but (unless a so-called end-to-end encryption procedure is used) not on the servers from which they are sent and received. We can therefore not assume any responsibility for the transmission path of the emails between the sender and receipt on our server; legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Content delivery network: We use a “content delivery network” (CDN). A CDN is a service with the help of which the content of an online offering, in particular large media files such as graphics or program scripts, can be delivered more quickly and securely with the help of regionally distributed servers connected via the internet; legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Blogs and publication media
We use blogs or comparable means of online communication and publication (hereinafter “publication medium”). The data of readers is processed for the purposes of the publication medium only insofar as it is necessary for its presentation and the communication between authors and readers or for reasons of security. Otherwise, we refer to the information on the processing of visitors to our publication medium within the framework of these data protection notices.
Types of data processed: inventory data (e.g. names, addresses); contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
Data subjects: users (e.g. website visitors, users of online services).
Purposes of processing: provision of contractual services and customer service; feedback (e.g. collecting feedback via online form); provision of our online offering and user-friendliness.
Legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Contact and enquiry management
When contacting us (e.g. by post, contact form, email, telephone or via social media) as well as within the framework of existing user and business relationships, the information of the enquiring persons is processed insofar as this is necessary to respond to the contact enquiries and any requested measures.
Types of data processed: contact data (e.g. email, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
Data subjects: communication partners.
Purposes of processing: contact requests and communication; management and response to enquiries; feedback (e.g. collecting feedback via online form); provision of our online offering and user-friendliness.
Legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).
Further notes on processing operations, procedures and services:
Contact form: When users contact us via our contact form, email or other communication channels, we process the data communicated to us in this context to process the communicated concern; legal bases: performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Promotional communication via email, post, fax or telephone
We process personal data for the purposes of promotional communication, which can take place via various channels, such as email, telephone, post or fax, in accordance with the legal requirements.
Recipients have the right to revoke consent granted at any time or to object to promotional communication at any time.
After revocation or objection, we store the data required to prove the previous authorisation for contact or dispatch for up to three years after the end of the year of the revocation or objection on the basis of our legitimate interests. The processing of this data is limited to the purpose of a possible defence against claims. On the basis of the legitimate interest in permanently observing the revocation or objection of users, we also store the data required to avoid renewed contact (e.g. depending on the communication channel, the email address, telephone number, name).
Types of data processed: inventory data (e.g. names, addresses); contact data (e.g. email, telephone numbers).
Data subjects: communication partners.
Purposes of processing: direct marketing (e.g. by email or post).
Legal bases: consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Web analytics, monitoring and optimisation
Web analytics (also referred to as “reach measurement”) serves to evaluate the visitor flows of our online offering and may include behaviour, interests or demographic information about visitors, such as age or gender, as pseudonymous values. With the help of reach analysis, we can, for example, recognise at what time our online offering or its functions or content are used most frequently or invite reuse. Likewise, we can understand which areas require optimisation.
In addition to web analytics, we may also use test procedures, e.g. to test and optimise different versions of our online offering or its components.
Unless otherwise stated below, for these purposes profiles, i.e. data combined into a usage process, may be created and information may be stored in a browser or an end device and read from it. The collected information includes in particular websites visited and elements used there, as well as technical information such as the browser used, the computer system used and information on usage times. If users have declared their consent to the collection of their location data to us or to the providers of the services we use, location data may also be processed.
The IP addresses of the users are also stored. However, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no clear data of the users (such as email addresses or names) is stored within the framework of web analytics, A/B testing and optimisation, but pseudonyms. This means that we as well as the providers of the software used do not know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
Types of data processed: usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
Data subjects: users (e.g. website visitors, users of online services).
Purposes of processing: reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creating user profiles); tracking (e.g. interest/behaviour-related profiling, use of cookies); provision of our online offering and user-friendliness.
Security measures: IP masking (pseudonymisation of the IP address).
Legal bases: consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
Further notes on processing operations, procedures and services:
Google Analytics: web analytics, reach measurement and measurement of user flows; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); website: https://marketingplatform.google.com/intl/de/about/analytics/; privacy policy: https://policies.google.com/privacy; data processing agreement: https://business.safety.google/adsprocessorterms; standard contractual clauses (safeguarding the level of data protection for processing in third countries): https://business.safety.google/adsprocessorterms; opt-out option: opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://adssettings.google.com/authenticated; further information: https://privacy.google.com/businesses/adsservices (types of processing and of the data processed).
Google Analytics 4: We use Google Analytics to measure and analyse the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data such as names or email addresses. It serves to assign analysis information to an end device in order to recognise which content the users have accessed within one or various usage processes, which search terms they used, accessed these again or interacted with our online offering. Likewise, the time of use and its duration are stored, as well as the sources of the users referring to our online offering and technical aspects of their end devices and browsers. In doing so, pseudonymous profiles of users are created with information from the use of various devices, whereby cookies can be used. In Analytics, data on the geographical location is provided at a higher level by collecting the following metadata based on the IP lookup: “city” (and the derived latitude and longitude of the city), “continent”, “country”, “region”, “subcontinent” (and the ID-based equivalents). In order to ensure the protection of user data in the EU, Google receives and processes all user data via domains and servers within the EU. The IP address of the users is not logged and, by default, the last two digits are shortened. The shortening of the IP address takes place on EU servers for EU users. In addition, all sensitive data collected from users in the EU is deleted before it is collected via EU domains and servers; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); website: https://marketingplatform.google.com/intl/de/about/analytics/; privacy policy: https://policies.google.com/privacy; data processing agreement: https://business.safety.google/adsprocessorterms/; standard contractual clauses (safeguarding the level of data protection for processing in third countries): https://business.safety.google/adsprocessorterms; opt-out option: opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://adssettings.google.com/authenticated; further information: https://privacy.google.com/businesses/adsservices (types of processing and of the data processed).
Online marketing
We process personal data for the purposes of online marketing, which can include in particular the marketing of advertising space or the display of advertising and other content (collectively referred to as “content”) based on the potential interests of users, as well as the measurement of their effectiveness.
For these purposes, so-called user profiles are created and stored in a file (so-called “cookie”), or similar procedures are used, by means of which the information about the user relevant for the display of the aforementioned content is stored. This information may include, for example, content viewed, websites visited, online networks used, but also communication partners and technical information such as the browser used, the computer system used and information on usage times and functions used. If users have consented to the collection of their location data, this may also be processed.
The IP addresses of the users are also stored. However, we use available IP masking procedures (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no clear data of the users (such as email addresses or names) is stored within the framework of the online marketing procedure, but pseudonyms. This means that we as well as the providers of the online marketing procedures do not know the actual identity of the users, but only the information stored in their profiles.
The information in the profiles is generally stored in the cookies or by means of similar procedures. These cookies can later generally also be read on other websites that use the same online marketing procedure, and analysed for the purposes of displaying content as well as supplemented with further data and stored on the server of the online marketing procedure provider.
In exceptional cases, clear data can be assigned to the profiles. This is the case if, for example, the users are members of a social network whose online marketing procedure we use and the network connects the profiles of the users with the aforementioned information. Please note that users can make additional agreements with the providers, e.g. by consent within the framework of registration.
In principle, we only gain access to summarised information about the success of our advertisements. However, within the framework of so-called conversion measurements, we can check which of our online marketing procedures have led to a so-called conversion, i.e. for example to a conclusion of a contract with us. Conversion measurement is used solely to analyse the success of our marketing measures.
Unless otherwise stated, we ask you to assume that cookies used are stored for a period of two years.
Types of data processed: usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
Data subjects: users (e.g. website visitors, users of online services).
Purposes of processing: reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest/behaviour-related profiling, use of cookies); marketing; profiles with user-related information (creating user profiles); conversion measurement (measuring the effectiveness of marketing measures).
Security measures: IP masking (pseudonymisation of the IP address).
Legal bases: consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Opt-out option: We refer to the data protection notices of the respective providers and the opt-out options specified for the providers (so-called “opt-out”). If no explicit opt-out option has been specified, there is, on the one hand, the possibility that you switch off cookies in the settings of your browser. However, this may restrict functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered collectively for the respective areas: a) Europe: https://www.youronlinechoices.eu. b) Canada: https://www.youradchoices.ca/choices. c) USA: https://www.aboutads.info/choices. d) cross-area: https://optout.aboutads.info.
Further notes on processing operations, procedures and services:
Google Ads and conversion measurement: Online marketing procedure for the purpose of placing content and advertisements within the advertising network of the service provider (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who have a presumed interest in the advertisements. In addition, we measure the conversion of the advertisements, i.e. whether the users took them as an occasion to interact with the advertisements and use the advertised offers (so-called conversion). However, we only receive anonymous information and no personal information about individual users; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6 para. 1 sentence 1 lit. a) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); website: https://marketingplatform.google.com; privacy policy: https://policies.google.com/privacy; further information: types of processing and of the data processed: https://privacy.google.com/businesses/adsservices; data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
Google AdSense with personalised advertisements: We use the Google AdSense service with personalised advertisements, with the help of which advertisements are displayed within our online offering and we receive remuneration for their display or other use; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); website: https://marketingplatform.google.com; privacy policy: https://policies.google.com/privacy; further information: types of processing and of the data processed: https://privacy.google.com/businesses/adsservices; data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
Google AdSense with non-personalised advertisements: We use the Google AdSense service with non-personalised advertisements, with the help of which advertisements are displayed within our online offering and we receive remuneration for their display or other use; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6 para. 1 sentence 1 lit. a) GDPR); website: https://marketingplatform.google.com; privacy policy: https://policies.google.com/privacy; further information: types of processing and of the data processed: https://privacy.google.com/businesses/adsservices; data processing terms between controllers and standard contractual clauses for third-country transfers of data: https://business.safety.google/adscontrollerterms.
Plugins and embedded functions and content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These can be, for example, graphics, videos or city maps (hereinafter uniformly referred to as “content”).
The integration always requires that the third-party providers of this content process the IP address of the users, since without the IP address they could not send the content to their browser. The IP address is thus necessary for the display of this content or functions. We endeavour to use only such content whose respective providers use the IP address solely to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and, among other things, contain technical information about the browser and operating system, referring websites, visit time and further information on the use of our online offering, as well as be linked with such information from other sources.
Types of data processed: usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, consent status).
Data subjects: users (e.g. website visitors, users of online services).
Purposes of processing: provision of our online offering and user-friendliness.
Legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Further notes on processing operations, procedures and services:
Integration of third-party software, scripts or frameworks (e.g. jQuery): We integrate into our online offering software that we retrieve from the servers of other providers (e.g. function libraries that we use for the display or user-friendliness of our online offering). In doing so, the respective providers collect the IP address of the users and can process it for the purposes of transmitting the software to the browser of the users, as well as for the purposes of security, and to evaluate and optimise their offering; legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Google Fonts (obtained from the Google server): Obtaining fonts (and symbols) for the purpose of a technically secure, maintenance-free and efficient use of fonts and symbols with regard to timeliness and loading times, their uniform display and consideration of possible licensing restrictions. The provider of the fonts is informed of the IP address of the user so that the fonts can be made available in the browser of the user. In addition, technical data (language settings, screen resolution, operating system, hardware used) are transmitted that are necessary for the provision of the fonts depending on the devices used and the technical environment. This data may be processed on a server of the provider of the fonts in the USA. When visiting our online offering, the browsers of the users send their browser HTTP requests to the Google Fonts Web API (i.e. a software interface for retrieving the fonts). The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) of Google Fonts and thereafter the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the internet, (2) the requested URL on the Google server and (3) the HTTP headers, including the user agent, which describes the browser and operating system versions of the website visitors, as well as the referrer URL (i.e. the web page on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers and they are not analysed. The Google Fonts Web API logs details of the HTTP requests (requested URL, user agent and referrer URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wants to load fonts. This data is logged so that Google can determine how often a particular font family is requested. With the Google Fonts Web API, the user agent must adapt the font that is generated for the respective browser type. The user agent is primarily logged for debugging and used to generate aggregated usage statistics that measure the popularity of font families. These aggregated usage statistics are published on the “Analytics” page of Google Fonts. Finally, the referrer URL is logged so that the data can be used for the maintenance of production and an aggregated report on the top integrations based on the number of font requests can be generated. According to its own information, Google does not use any of the information collected by Google Fonts to create profiles of end users or to serve targeted advertisements; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); website: https://fonts.google.com/; privacy policy: https://policies.google.com/privacy; further information: https://developers.google.com/fonts/faq/privacy?hl=de.
Font Awesome (provided on our own server): display of fonts and symbols; service provider: the Font Awesome Icons are hosted on our server, no data is transmitted to the provider of Font Awesome; legal bases: legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
Amendment and update of the privacy policy
We ask you to regularly inform yourself about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Insofar as we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time and please check the information before making contact.
Rights of data subjects
As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of the personal data concerning you which is based on Art. 6 para. 1 lit. e or f GDPR; this also applies to profiling based on these provisions. If the personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of the personal data concerning you for the purpose of such advertising; this also applies to profiling insofar as it is connected with such direct marketing.
Right to withdraw consent: You have the right to withdraw consent granted at any time.
Right of access: You have the right to request confirmation as to whether data concerning you is being processed and to obtain access to this data as well as further information and a copy of the data in accordance with the legal requirements.
Right to rectification: You have the right, in accordance with the legal requirements, to request the completion of the data concerning you or the rectification of the incorrect data concerning you.
Right to erasure and restriction of processing: You have the right, in accordance with the legal requirements, to request that data concerning you be deleted without delay, or alternatively, in accordance with the legal requirements, to request a restriction of the processing of the data.
Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used and machine-readable format in accordance with the legal requirements, or to request its transmission to another controller.
Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of the personal data concerning you infringes the requirements of the GDPR.