Privacy Statement

1. Overview of Data Protection

General Information This document provides a simple overview of what happens to your personal data when you visit our website. Personal data refers to any data that can personally identify you. Detailed information on data protection is outlined in our privacy policy below.

Data Collection on this Website

Who is responsible for data collection on this website?

Data processing on this website is conducted by the website operator. The operator’s contact details are provided in the section "Notice about the Responsible Party" in this privacy policy.

How do we collect your data?

Some data are collected when you provide it to us, such as data you enter on a contact form. Other data are automatically collected or with your consent when you visit the website. This includes primarily technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right to receive information about the origin, recipient, and purpose of your stored personal data at any time for free. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for future processing. Additionally, you have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to file a complaint with the competent supervisory authority. For further information on data protection, you can contact us at any time.

Analysis Tools and Tools from Third-Party Providers

When visiting this website, your surfing behavior can be statistically analyzed, primarily with analysis programs. Detailed information on these analysis programs can be found in the following privacy policy.

 

2. General Information and Mandatory Information

Data Protection

The operators of this site take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.

When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens. We would like to point out that data transmission over the internet (e.g., communication by email) can have security gaps. Complete protection of the data against access by third parties is not possible.

Notice concerning the responsible party

The responsible party for data processing on this website is:

ISL Internet Sicherheitslösungen GmbH
Alte Wittener Str. 70
44803 Bochum
Germany
Tel.: +49 234 976672-0
E-Mail: info(at)isl.de

The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Duration

Unless a specific storage period has been mentioned in this privacy policy, your personal data will remain with us until the purpose for the data processing ceases to apply. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., retention periods under tax or commercial law); in the latter case, the deletion will occur after these reasons cease to apply.

General Information on the Legal Bases for Data Processing on this Website

If you have consented to data processing, we process your personal data based on Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR if special data categories according to Art. 9 para. 1 GDPR are processed. In the case of an explicit consent to the transfer of personal data to third countries, the data processing is also based on Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information in your end device (e.g., via device fingerprinting), the data processing is additionally based on § 25 para. 1 TTDSG. The consent can be revoked at any time. If your data is necessary for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data based on Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data insofar as it is necessary for the fulfillment of a legal obligation based on Art. 6 para. 1 lit. c GDPR. Data processing can also be based on our legitimate interest according to Art. 6 para. 1 lit. f GDPR. Information on the relevant legal basis in each case is provided in the following paragraphs of this privacy policy.

Notice on Data Transfer to the USA and Other Third Countries

We use tools from companies based in the USA or other third countries that are not secure under data protection law. When these tools are active, your personal data can be transferred to these third countries and processed there. We would like to point out that in these countries, no level of data protection comparable to that in the EU can be guaranteed. For instance, US companies are obligated to hand over personal data to security authorities without you as the data subject being able to take legal action against this. It can therefore not be ruled out that US authorities (e.g., secret services) may process, evaluate, and permanently store your data located on US servers for surveillance purposes. We have no influence on these processing activities.

Recipients of Personal Data

In the course of our business activities, we may disclose personal data to external parties. Such data transfers are carried out based on legal requirements, your consent, our legitimate interests, or if necessary, for the performance of a contract.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You can revoke an already given consent at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Object to Data Collection in Special Cases and Direct Advertising (Art. 21 GDPR)

If the data processing is based on Art. 6 para. 1 lit. e or f GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation; this also applies to profiling based on these provisions. The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defense of legal claims (objection according to Art. 21 para. 1 GDPR). If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing; this also applies to profiling insofar as it is related to such direct marketing. If you object, your personal data will subsequently no longer be used for direct marketing purposes (objection according to Art. 21 para. 2 GDPR).

Right to Lodge a Complaint with a Supervisory Authority

In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the Member State of their habitual residence, place of work, or the place of the alleged breach. The right to lodge a complaint exists without prejudice to other administrative or judicial remedies.

Right to Data Portability

You have the right to have data that we process based on your consent or in fulfillment of a contract automatically delivered to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent technically feasible.

Information, Correction, and Deletion

Within the framework of the applicable legal provisions, you have the right to free information about your stored personal data, their origin, and recipients and the purpose of data processing and, if necessary, a right to correction or deletion of this data at any time. For further information on personal data, you can contact us at any time.

Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restrict processing applies in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you need them for the exercise, defense, or establishment of legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
  • If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, a balance must be struck between your and our interests. As long as it is not yet clear whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data may – apart from their storage – only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.

SSL/TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser’s address line changes from "http://" to "https://" and by the lock symbol in your browser line. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Objection to Advertising Emails

We hereby object to the use of contact data published in the context of the imprint obligation for sending unsolicited advertising and informational materials. The operators of these pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam emails.

 

3. Data Collection on This Website

Cookies

Our websites use so-called "cookies." Cookies are small data packets that do not harm your device. They are either temporarily stored for the duration of a session (session cookies) or permanently (permanent cookies) stored on your device. Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your device until you delete them or an automatic deletion occurs through your web browser. Cookies can be from us (first-party cookies) or from third-party companies (third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services). Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies can be used to analyze user behavior or for advertising purposes. Cookies that are necessary to carry out the electronic communication process, provide certain functions you desire (e.g., for the shopping cart function), or optimize the website (e.g., cookies to measure web audience) are stored based on Art. 6 para. 1 lit. f GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, processing is based solely on this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG); consent can be revoked at any time. You can set your browser to inform you about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for specific cases or in general, and enable the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website. You can find out which cookies and services are used on this website in this privacy policy.

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

This data is not combined with other data sources. The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website - for this purpose, the server log files must be recorded.

Contact Form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not pass on this data without your consent. The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry is related to the performance of a contract or necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the inquiries directed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if requested; consent can be revoked at any time. The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions - especially retention periods - remain unaffected.

Inquiry by Email, Telephone, or Fax

If you contact us by email, telephone, or fax, your inquiry, including all resulting personal data (name, inquiry), will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent. The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your inquiry is related to the performance of a contract or necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the inquiries directed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if requested; consent can be revoked at any time. The data you send to us via contact inquiries will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions - especially statutory retention periods - remain unaffected.

Use of Chatbots

We use chatbots to communicate with you. Chatbots can respond to your questions and other inputs without human assistance. To do this, chatbots analyze your inputs and additional data to provide appropriate responses (e.g., names, email addresses, and other contact information, customer numbers, orders, and chat histories). Furthermore, chatbots can capture your IP address, log files, location information, and other metadata. These data are stored on the servers of the chatbot provider. User profiles can be created based on the collected data. The data can also be used to display targeted advertising if the other legal requirements (especially consent) are met. Chatbots may be linked to analysis and advertising tools for this purpose. The data collected can also be used to improve our chatbots and their response behavior (machine learning). The data you enter during communication will remain with us or the chatbot operator until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions - especially retention periods - remain unaffected. The legal basis for using chatbots is Art. 6 para. 1 lit. b GDPR if the chatbot is used for pre-contractual measures or in the context of contract performance. If consent is requested, processing is based solely on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information on the user's end device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time. In all other cases, the use is based on our legitimate interest in the most effective customer communication possible (Art. 6 para. 1 lit. f GDPR). We use the following chatbots: LoyJoy. The provider is LoyJoy GmbH, Kapuzinerstr. 20, 48149 Münster (hereinafter LoyJoy). LoyJoy primarily serves to improve our offerings and conduct marketing campaigns, such as sweepstakes. The following data, which LoyJoy itself does not have access to, is processed by the chatbot:

  • IP address, browser used
  • Email address and password/code upon registration
  • Interaction such as entered messages, login/logout, opt-in/opt-out, sweepstakes participation, etc.
  • If the user comes via Facebook Messenger or other messaging apps: the user ID provided by Facebook and data provided by the third party (name).

The mentioned data is aggregated and anonymized for statistical evaluations to measure success and, if advertising consent is given, to optimize the display of messages. The legal basis for processing is your consent under Art. 6 para. 1 a) GDPR and our legitimate interest under Art. 6 para. 1 f) GDPR. LoyJoy uses services from "Cloudflare" (provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare operates a content delivery network (CDN) and provides security functions for the LoyJoy web application (web application firewall). Data transfer between the browser and the LoyJoy servers flows through Cloudflare's infrastructure and is analyzed there to fend off attacks. Cloudflare uses technically necessary cookies to enable access to LoyJoy. Using Cloudflare is in the interest of secure use of LoyJoy and protection against harmful external attacks. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR. Further information can be found in the Cloudflare privacy policy: www.cloudflare.com/de-de/privacypolicy/.

Order Processing

We have concluded a contract for order processing (AVV) for using the above-mentioned service. This is a data protection contract required by law to ensure that this service processes the personal data of our website visitors only in accordance with our instructions and following the GDPR.

Registration on This Website

You can register on this website to use additional features on the site. The data entered for this purpose will only be used for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be fully provided. Otherwise, we will reject the registration.

For important changes such as changes in the scope of the offer or technically necessary changes, we use the email address provided during registration to inform you in this way.

The processing of the data entered during registration is based on the purpose of performing the user relationship established by the registration and, if applicable, to initiate further contracts (Art. 6 para. 1 lit. b GDPR).

The data collected during registration will be stored by us as long as you are registered on this website and will then be deleted. Statutory retention periods remain unaffected.

 

4. Analysis Tools and Advertising

Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool that allows us to integrate tracking or statistical tools and other technologies on our website. Google Tag Manager itself does not create user profiles, store cookies, or perform any independent analyses. It only serves to manage and display the tools integrated through it. However, Google Tag Manager does capture your IP address, which can also be transmitted to Google's parent company in the United States.

The use of Google Tag Manager is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in a quick and uncomplicated integration and management of various tools on its website. If consent has been requested, processing is carried out exclusively based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, as far as the consent includes the storage of cookies or access to information in the user’s end device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.

The company has certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards in data processing in the USA. Any company certified under the DPF is committed to adhering to these data protection standards. Further information can be obtained from the provider at the following link: Data Privacy Framework Participant Search.

Google Analytics

This website uses functions of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyze the behavior of website visitors. The website operator receives various usage data, such as page views, time spent on the site, operating systems used, and user origin. This data is compiled into a user ID and assigned to the respective end device of the website visitor.

Furthermore, Google Analytics can record your mouse and scroll movements and clicks, and it uses various modeling approaches to supplement the collected data sets and employs machine learning technologies for data analysis.

Google Analytics uses technologies that allow the recognition of the user for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about your use of this website is usually transmitted to a Google server in the USA and stored there.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: Google Privacy.

The company has certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards in data processing in the USA. Any company certified under the DPF is committed to adhering to these data protection standards. Further information can be obtained from the provider at the following link: Data Privacy Framework Participant Search.

IP Anonymization

We have activated IP anonymization for Google Analytics on this website. This means that your IP address is shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area before transmission to the USA. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity, and provide other services related to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.

Browser Plugin

You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available at the following link: Google Opt-Out.

More information on how Google Analytics handles user data can be found in Google's privacy policy: Google Analytics Privacy.

Google Signals

We use Google Signals. When you visit our website, Google Analytics collects, among other things, your location, search history, YouTube history, and demographic data (visitor data). This data can be used for personalized advertising with the help of Google Signals. If you have a Google account, the visitor data from Google Signals will be linked to your Google account and used for personalized advertising messages. The data is also used to create anonymized statistics about user behavior on our website.

Order Processing

We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.

Google Ads

The website operator uses Google Ads. Google Ads is an online advertising program of Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads allows us to display advertisements in the Google search engine or on third-party websites when the user enters specific search terms on Google (keyword targeting). Targeted advertisements can also be displayed based on the user data available from Google (e.g., location data and interests) (audience targeting). We as the website operator can quantitatively evaluate this data by analyzing, for example, which search terms led to the display of our advertisements and how many ads resulted in corresponding clicks.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: Google Policies and Google Business Controller Terms.

The company has certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards in data processing in the USA. Any company certified under the DPF is committed to adhering to these data protection standards. Further information can be obtained from the provider at the following link: Data Privacy Framework Participant Search.

Google AdSense (non-personalized)

This website uses Google AdSense, a service for integrating advertisements. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

We use Google AdSense in "non-personalized" mode. Unlike personalized mode, the advertisements are not based on your past user behavior and no user profile is created for you. Instead, "contextual information" is used for ad selection. The selected ads are then, for example, based on your location, the content of the website you are on, or your current search terms. More about the differences between personalized and non-personalized targeting with Google AdSense can be found at: support.google.com/adsense/answer/9007336.

Please note that even when using Google AdSense in non-personalized mode, cookies or similar recognition technologies (e.g., device fingerprinting) may still be used. According to Google, these are used to combat fraud and abuse.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: privacy.google.com/businesses/controllerterms/mccs/.

You can adjust your advertising settings independently in your user account. Click on the following link and log in: adssettings.google.com/authenticated.

More information about Google's advertising technologies can be found here: policies.google.com/technologies/ads and www.google.com/policies/privacy/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards in data processing in the USA. Any company certified under the DPF is committed to adhering to these data protection standards. Further information can be obtained from the provider at the following link: www.dataprivacyframework.gov/s/participant-search/participant-detail.

Google Conversion Tracking

This website uses Google Conversion Tracking. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

With the help of Google Conversion Tracking, Google and we can recognize whether the user has performed certain actions. For example, we can evaluate which buttons on our website are clicked and which products are viewed or purchased most frequently. This information is used to create conversion statistics. We learn the total number of users who clicked on our ads and what actions they took. We do not receive any information that personally identifies users. Google itself uses cookies or similar recognition technologies for identification.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.

More information about Google Conversion Tracking can be found in Google's privacy policy: policies.google.com/privacy.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards in data processing in the USA. Any company certified under the DPF is committed to adhering to these data protection standards. Further information can be obtained from the provider at the following link: www.dataprivacyframework.gov/s/participant-search/participant-detail.

BRAME

For participating in games and processing data for marketing purposes such as customer loyalty, we use the service provider Brame (Brame AG, Neuhofstrasse 10, 8834 Schindellegi, Switzerland). Depending on the type of game, BRAME processes your name, username, personal contact information (address, postal code, city, and email address), date of birth, gender, lifestyle and activity information (including underlying GPS data).

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.

These data, which you provide to us directly via the website or through third-party devices or applications you connect to your account, are processed together with your interactions within the website as part of our ongoing efforts to improve user experience. Brame maintains adequate security measures to protect your data and takes all other necessary and appropriate administrative, organizational, technical, personnel, and physical measures to protect and ensure the integrity of your data. Further information on data usage can be found in Brame's privacy policy: brame.io/de/privacy-policy.

Meta Pixel (formerly Facebook Pixel)

This website uses the visitor action pixel from Facebook/Meta for conversion measurement. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the collected data is also transferred to the USA and other third countries.

This allows the behavior of site visitors to be tracked after they are redirected to the provider's website by clicking on a Facebook ad. This enables the effectiveness of Facebook ads to be evaluated for statistical and market research purposes and future advertising measures to be optimized.

The collected data is anonymous for us as the operator of this website; we cannot draw any conclusions about the identity of users. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes, according to the Facebook Data Usage Policy: facebook.com/about/privacy/. This allows Facebook to display ads on Facebook pages as well as outside of Facebook. This data usage cannot be influenced by us as the site operator.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.

Insofar as personal data is collected on our website using the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook. The processing by Facebook after the transfer is not part of the joint responsibility. Our joint obligations have been set out in an agreement on joint processing. The wording of the agreement can be found here: facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for the data protection-compliant implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. Data subject rights (e.g., requests for information) regarding the data processed by Facebook can be asserted directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: facebook.com/legal/EU_data_transfer_addendum and facebook.com/help/566994660333381.

In Facebook's privacy notices, you will find further information on the protection of your privacy: facebook.com/about/privacy/.

You can also deactivate the "Custom Audiences" remarketing function in the ad settings section at facebook.com/ads/preferences/. To do this, you need to be logged in to Facebook.

If you do not have a Facebook account, you can deactivate usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance: youronlinechoices.com/de/praferenzmanagement/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards in data processing in the USA. Any company certified under the DPF is committed to adhering to these data protection standards. Further information can be obtained from the provider at the following link: dataprivacyframework.gov/s/participant-search/participant-detail.

Facebook Conversion API

We have integrated Facebook Conversion API on this website. The service provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the collected data is also transferred to the USA and other third countries.

Facebook Conversion API enables us to capture the interactions of website visitors with our website and share them with Facebook to improve advertising performance on Facebook. Specifically, the time of access, the accessed website, your IP address, and your user agent, as well as other specific data (e.g., purchased products, cart value, and currency), are recorded. A complete overview of the collectable data can be found here: developers.facebook.com/docs/marketing-api/conversions-api/parameters.

The use of this service is based on your consent according to Art. 6 (1) lit. a GDPR and § 25 (1) TTDSG. The consent is revocable at any time.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). Joint responsibility is limited solely to the collection of the data and its transfer to Facebook. The processing that takes place after forwarding is not part of the joint responsibility. Our joint obligations have been set out in an agreement on joint processing. The wording of the agreement can be found at: www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the privacy information when using the Facebook tool and for the privacy-compliant implementation of the tool on our website. Facebook is responsible for the data security of Facebook products. You can assert the rights of data subjects (e.g., requests for information) regarding data processed by Facebook directly with Facebook. If you assert the data subject rights with us, we are obliged to forward them to Facebook.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: www.facebook.com/legal/EU_data_transfer_addendum and de-de.facebook.com/help/566994660333381.

For more information on how Facebook protects your privacy, please refer to Facebook's privacy policy: de-de.facebook.com/about/privacy/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. More information can be obtained from the provider at the following link: www.dataprivacyframework.gov/s/participant-search/participant-detail.

Order Processing

We have entered into a data processing agreement (DPA) for the use of the aforementioned service. This is a data protection legally required contract that ensures the processing of personal data of our website visitors only according to our instructions and in compliance with the GDPR.

Facebook Custom Audiences

We use Facebook Custom Audiences. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. When you visit or use our websites and apps, use our free or paid offers, transmit data to us, or interact with our company's Facebook content, we collect your personal data. If you give us consent to use Facebook Custom Audiences, we will transfer this data to Facebook, which can display relevant advertisements to you. Furthermore, your data can be used to define target audiences (lookalike audiences).

Facebook processes this data as our processor. Details can be found in Facebook's terms of use: www.facebook.com/legal/terms/customaudience.

The use of this service is based on your consent according to Art. 6 (1) lit. a GDPR and § 25 (1) TTDSG. The consent is revocable at any time.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: www.facebook.com/legal/terms/customaudience and www.facebook.com/legal/terms/dataprocessing.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. More information can be obtained from the provider at the following link: www.dataprivacyframework.gov/s/participant-search/participant-detail.

LinkedIn Insight Tag

This website uses the Insight Tag from LinkedIn. The service provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.

Data Processing by LinkedIn Insight Tag

With the help of the LinkedIn Insight Tag, we obtain information about the visitors of our website. If a website visitor is registered with LinkedIn, we can analyze the professional data (e.g., career level, company size, country, location, industry, and job title) of our website visitors and thus better tailor our site to the respective target groups. Furthermore, LinkedIn Insight Tags allow us to measure whether the visitors of our websites make a purchase or another action (conversion measurement). Conversion measurement can also be carried out across devices (e.g., from PC to tablet). LinkedIn Insight Tag also offers a retargeting function, allowing us to display targeted advertising to visitors of our website outside the website, without identifying the advertising recipient according to LinkedIn.

LinkedIn also collects so-called log files (URL, referrer URL, IP address, device and browser properties, and time of access). The IP addresses are shortened or hashed (pseudonymized) when used to reach LinkedIn members across devices. LinkedIn members' direct identifiers are deleted by LinkedIn after seven days. The remaining pseudonymized data will then be deleted within 180 days.

The data collected by LinkedIn cannot be assigned to specific individuals by us as the website operator. LinkedIn will store the collected personal data of the website visitors on its servers in the USA and use it for its own advertising measures. For details, refer to LinkedIn's privacy policy: www.linkedin.com/legal/privacy-policy.

Legal Basis

If consent has been obtained, the use of the above-mentioned service is based solely on Art. 6 (1) lit. a GDPR and § 25 TTDSG. The consent is revocable at any time. If no consent has been obtained, the use of this service is based on Art. 6 (1) lit. f GDPR; the website operator has a legitimate interest in effective advertising measures, including social media.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: www.linkedin.com/legal/l/dpa and www.linkedin.com/legal/l/eu-sccs.

Objection to the Use of LinkedIn Insight Tag

You can object to the analysis of your usage behavior and targeted advertising by LinkedIn at the following link: www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

Furthermore, LinkedIn members can control the use of their personal data for advertising purposes in their account settings. To prevent a connection between the data collected on our website by LinkedIn and your LinkedIn account, you must log out of your LinkedIn account before visiting our website.

Order Processing

We have entered into a data processing agreement (DPA) for the use of the above-mentioned service. This is a data protection legally required contract that ensures the processing of personal data of our website visitors only according to our instructions and in compliance with the GDPR.

Lead Gen Forms

As part of customer acquisition, we use so-called Lead Gen Forms. These are advertisements on social networks that allow the inclusion of contact forms in sponsored content. The legal basis for the use of Lead Ads tools is Art. 6 (1) lit. f GDPR. Our legitimate interest in using these tools serves marketing purposes in the context of contact and business initiation. We use the Lead Gen Forms services of LinkedIn (LinkedIn Lead Generation).

As part of contact and new customer acquisition, we also use Lead Gen Forms services. By using these Lead Gen Forms services, we offer interested parties a function to provide us with their email address or other user information as users of a social network you use. We use this functionality to address interested parties more specifically.

LinkedIn (LinkedIn Lead Generation)

This website uses LinkedIn Lead Generation from LinkedIn. The service provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses forms for lead generation, and functions and content of the LinkedIn service can be embedded. If you are a member of the LinkedIn platform, LinkedIn can associate the call of the aforementioned content and functions with the profiles of the users there.

For more information on LinkedIn's privacy and Lead Gen Ads, please refer to: www.linkedin.com/legal/privacy-policy and business.linkedin.com/de-de/marketing-solutions/native-advertising/lead-gen-ads.

You have the option to prevent this in the future by setting an opt-out cookie: www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

 

5. Our Social Media Presence

Data Processing by Social Networks

We maintain publicly accessible profiles on social networks. The specific social networks we use are listed below.

Social networks like Facebook, X, etc., can typically analyze your user behavior comprehensively when you visit their website or a website with integrated social media content (e.g., like buttons or advertising banners). When you visit our social media presences, numerous data protection-relevant processing operations are triggered. Specifically:

If you are logged into your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected if you are not logged in or do not have an account with the respective social media portal. This data collection can occur through cookies stored on your device or by capturing your IP address.

With the help of the data collected, the operators of social media portals can create user profiles where your preferences and interests are stored. This allows interest-based advertising to be displayed both inside and outside of the respective social media presence. If you have an account with the respective social network, interest-based advertising can be shown on all devices you are logged into or have been logged into.

Please note that we cannot track all processing activities on social media portals. Depending on the provider, additional processing operations may be carried out by the operators of the social media portals. Details can be found in the terms of use and privacy policies of the respective social media portals.

Legal Basis

Our social media presences aim to ensure the most comprehensive presence possible on the Internet. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. The analysis processes initiated by social networks may be based on differing legal bases specified by the social network operators (e.g., consent within the meaning of Art. 6(1)(a) GDPR).

Responsible Party and Assertion of Rights

When you visit one of our social media presences (e.g., Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered during that visit. You can generally assert your rights (information, correction, deletion, restriction of processing, data portability, and complaint) both against us and against the operator of the respective social media portal (e.g., against Facebook).

Please note that despite the joint responsibility with the social media portal operators, we do not have full control over the data processing operations of the social media portals. Our possibilities are largely determined by the corporate policy of the respective provider.

Storage Duration

The data collected directly by us via the social media presence will be deleted from our systems as soon as you request us to delete it, revoke your consent to storage, or the purpose for the data storage ceases to apply. Stored cookies remain on your device until you delete them. Mandatory legal provisions—especially retention periods—remain unaffected.

We have no influence on the storage duration of your data that is stored by the social network operators for their own purposes. For details, please refer directly to the social network operators (e.g., in their privacy policies, see below).

Your Rights

You have the right at any time to obtain information about the origin, recipient, and purpose of your stored personal data free of charge. You also have the right to object, the right to data portability, and the right to lodge a complaint with the competent supervisory authority. Furthermore, you can request the correction, blocking, deletion, and, under certain circumstances, restriction of the processing of your personal data.

Individual Social Networks

Facebook

We have a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter Meta). According to Meta, the data collected is also transferred to the USA and other third countries.

We have entered into a joint processing agreement (Controller Addendum) with Meta. This agreement specifies which data processing operations we or Meta are responsible for when you visit our Facebook page. This agreement can be viewed at the following link: www.facebook.com/legal/terms/page_controller_addendum.

You can adjust your advertising settings independently in your user account. To do this, click on the following link and log in: www.facebook.com/settings.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: www.facebook.com/legal/EU_data_transfer_addendum and de-de.facebook.com/help/566994660333381.

Details can be found in Facebook's privacy policy: www.facebook.com/about/privacy/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Each company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at the following link: www.dataprivacyframework.gov/s/participant-search/participant-detail.

X (formerly Twitter)

We use the short message service X (formerly Twitter). The provider is Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland.

You can adjust your X data privacy settings independently in your user account. To do this, click on the following link and log in: twitter.com/personalization.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: gdpr.twitter.com/en/controller-to-controller-transfers.html.

Details can be found in X's privacy policy: twitter.com/de/privacy.

Instagram

We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: www.facebook.com/legal/EU_data_transfer_addendum, privacycenter.instagram.com/policy/, and de-de.facebook.com/help/566994660333381.

Details on how Instagram handles your personal data can be found in Instagram's privacy policy: privacycenter.instagram.com/policy/.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Each company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at the following link: www.dataprivacyframework.gov/s/participant-search/participant-detail.

XING

We have a profile on XING. The provider is New Work SE, Dammtorstraße 30, 20354 Hamburg, Germany. Details on how XING handles your personal data can be found in XING's privacy policy: privacy.xing.com/de/datenschutzerklaerung.

LinkedIn

We have a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies.

If you wish to disable LinkedIn advertising cookies, please use the following link: www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

Data transfer to the USA is based on the EU Commission's standard contractual clauses. Details can be found here: www.linkedin.com/legal/l/dpa and www.linkedin.com/legal/l/eu-sccs.

Details on how LinkedIn handles your personal data can be found in LinkedIn's privacy policy: www.linkedin.com/legal/privacy-policy.

Vimeo

We have a profile on Vimeo. The provider is Vimeo, Inc., 555 West 18th Street, New York, NY 10011, USA.

Data transfer to the USA is based on the EU Commission's standard contractual clauses and, according to Vimeo, on "legitimate business interests." Details can be found here: vimeo.com/privacy.

Details on how Vimeo handles your personal data can be found in Vimeo's privacy policy: vimeo.com/privacy.

YouTube

We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Details on how YouTube handles your personal data can be found in YouTube's privacy policy: policies.google.com/privacy.

The company is certified under the "EU-US Data Privacy Framework" (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards for data processing in the USA. Each company certified under the DPF undertakes to comply with these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active.

 

6. Newsletter

Newsletter Data

If you wish to subscribe to the newsletter offered on the website, we require your email address as well as information that allows us to verify that you are the owner of the specified email address and consent to receiving the newsletter. Further data is not collected or is collected on a voluntary basis only. We use newsletter service providers to manage the newsletter process, which are described below.

Brevo

This website uses Brevo for sending newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. Brevo is a service that enables, among other things, the organization and analysis of newsletters. The data you provide for the purpose of subscribing to the newsletter is stored on Sendinblue GmbH's servers in Germany.

Data Analysis by Brevo

Using Brevo, we can analyze our newsletter campaigns. For example, we can see if a newsletter message has been opened and which links have been clicked. This allows us to determine, among other things, which links are clicked on most frequently. Furthermore, we can identify whether certain predefined actions were taken after opening/clicking (conversion rate). For instance, we can see if you made a purchase after clicking on the newsletter. Brevo also enables us to categorize newsletter recipients into different categories ("clustering"). For example, recipients can be segmented by age, gender, or location, allowing us to better tailor the newsletters to the respective target groups. If you do not wish for analysis by Brevo, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message. For detailed information about the functions of Brevo, please visit the following link: www.brevo.com/en/newsletter-software/.

Legal Basis

Data processing is based on your consent (Art. 6(1)(a) GDPR). You may revoke your consent at any time. The legality of data processing operations already conducted remains unaffected by the revocation.

Storage Duration

The data you provide us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter, either with us or the newsletter service provider, and will be deleted from the newsletter distribution list after you unsubscribe. Data stored for other purposes remains unaffected by this. After you unsubscribe from the newsletter distribution list, your email address may be stored in a blacklist by us or the newsletter service provider, if necessary, to prevent future mailings. The data from the blacklist will be used only for this purpose and will not be merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). The storage in the blacklist is not time-limited. You may object to this storage if your interests outweigh our legitimate interest. For more information, please refer to Brevo's privacy policy at: www.brevo.com/en/data-protection-overview/ and www.brevo.com/en/legal/privacypolicy/.

Data Processing Agreement

We have entered into a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required contract ensuring that the service provider processes the personal data of our website visitors only according to our instructions and in compliance with GDPR.

 

7. Plugins and Tools

YouTube

This website embeds videos from the YouTube website. The website is operated by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. When you visit one of our web pages that has a YouTube plugin, a connection to YouTube's servers is established. This informs the YouTube server about which of our pages you have visited. Furthermore, YouTube may store various cookies on your device or use similar technologies for recognition (e.g., device fingerprinting). This allows YouTube to obtain information about visitors to this website. Among other things, this information is used to collect video statistics, improve user friendliness, and prevent fraud. If you are logged into your YouTube account, YouTube allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account. The use of YouTube is for the purpose of presenting our online offerings in an appealing manner. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 para. 1 TTDSG, to the extent that the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) under TTDSG. The consent can be revoked at any time. For more information on how user data is handled, please refer to YouTube's privacy policy at: policies.google.com/privacy.

The company has certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards in data processing operations in the United States. Each company certified under the DPF commits to complying with these data protection standards. For more information, visit the provider's link: www.dataprivacyframework.gov/s/participant-search/participant-detail.

Google Maps

This site uses the Google Maps mapping service. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. To use the features of Google Maps, it is necessary to store your IP address. This information is usually transferred to a Google server in the USA and stored there. The operator of this site has no influence on this data transmission. When Google Maps is activated, Google may use Google Fonts for the purpose of uniform font display. When Google Maps is accessed, your browser loads the required web fonts into your browser cache to display texts and fonts correctly. The use of Google Maps is for the purpose of presenting our online offerings attractively and facilitating the location of places specified by us on the website. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 para. 1 TTDSG, to the extent that the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) under TTDSG. The consent can be revoked at any time. Data transfer to the USA is based on the European Commission's standard contractual clauses. Details can be found here: privacy.google.com/businesses/gdprcontrollerterms/ and privacy.google.com/businesses/gdprcontrollerterms/sccs/.

For more information about how user data is handled, please refer to Google's privacy policy: policies.google.com/privacy.

The company has certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards in data processing operations in the United States. Each company certified under the DPF commits to complying with these data protection standards. For more information, visit the provider's link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active.

Google reCAPTCHA

We use Google reCAPTCHA on this website ("reCAPTCHA"). The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA is used to check whether the data input on our website (e.g., in a contact form) is done by a human or by an automated program. To achieve this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, duration of website visit by the visitor, or mouse movements made by the user). The data collected during the analysis will be forwarded to Google. The reCAPTCHA analyses run entirely in the background. Website visitors are not informed that an analysis is taking place. The storage and analysis of the data are based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated spying and spam. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 25 para. 1 TDDDG, to the extent that the consent includes the storage of cookies or access to information on the user's device (e.g., device fingerprinting) under TDDDG. The consent can be revoked at any time. For more information about Google reCAPTCHA, please see Google's privacy policy and terms of use at the following links: policies.google.com/privacy and policies.google.com/terms.

The company has certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards in data processing operations in the United States. Each company certified under the DPF commits to complying with these data protection standards. For more information, visit the provider's link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active.

 

8. Audio and Video Conferences

Data Processing

For communication with our customers, among other tools, we use online conferencing tools. The specific tools we use are listed below. When you communicate with us via video or audio conference over the internet, your personal data is collected and processed by us and the provider of the respective conference tool. The conference tools capture all data that you provide/use to use the tools (email address and/or telephone number). Additionally, the conference tools process the duration of the conference, start and end (time) of participation in the conference, number of participants, and other "context information" related to the communication process (metadata). Furthermore, the tool provider processes all technical data required for the execution of online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection. If content is exchanged, uploaded, or otherwise provided within the tool, it is also stored on the servers of the tool providers. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards, and other information shared during the use of the service. Please note that we do not have full control over the data processing operations of the tools used. Our options are largely based on the corporate policies of the respective provider. For further information on data processing by the conference tools, please refer to the privacy policies of the respective tools listed below this text.

Purpose and Legal Basis

The conference tools are used to communicate with prospective or existing contractual partners or to offer certain services to our customers (Art. 6(1)(b) GDPR). Furthermore, the use of the tools serves the general simplification and acceleration of communication with us or our company (legitimate interest within the meaning of Art. 6(1)(f) GDPR). If consent has been requested, the use of the respective tools is based on this consent; the consent can be revoked at any time with effect for the future.

Storage Duration

The data directly collected by us through the video and conference tools will be deleted from our systems as soon as you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal retention periods remain unaffected. We do not have any influence on the storage duration of your data that is stored by the operators of the conference tools for their own purposes. For details, please contact the operators of the conference tools directly.

 

9. Used Conference Tools

We use the following conference tools:

Zoom

We use Zoom. The provider of this service is Zoom Communications Inc., San Jose, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. For details on data processing, please refer to Zoom's privacy policy: explore.zoom.us/de/privacy/.

Data transfer to the USA is based on the European Commission's standard contractual clauses. Details can be found here: explore.zoom.us/de/privacy/.

We have entered into a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required contract that ensures Zoom processes personal data of our website visitors only according to our instructions and in compliance with GDPR.

Microsoft Teams

We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For details on data processing, please refer to Microsoft Teams' privacy statement: privacy.microsoft.com/de-de/privacystatement.

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA aimed at ensuring compliance with European data protection standards for data processing in the USA. Further information can be obtained from the provider at the following link: www.dataprivacyframework.gov/s/participant-search/participant-detail.

We have entered into a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required contract that ensures Microsoft processes personal data of our website visitors only according to our instructions and in compliance with GDPR.

(As of June 2024)

Contact
Service area
Newsletter

Contact

Service area

ARP-GUARD service area

If you are already an ARP-GUARD partner, you can access your personal service area here.

Get the latest releases and up-to-date knowledgebase articles and manage your ARP-GUARD.

Partner login

Become an ARP-GUARD partner now!

Would you like to make the most of the advantages of our solution and complete your “Network Security” portfolio? 

Then you have the opportunity to become an ARP-GUARD partner!

Become a partner

Newsletter

We inform you about current topics, such as events and new product features.

Keep up-to-date at all times!

ARP-GUARD newsletter

Register Now!