Privacy Policy

Preamble

With the fol­low­ing pri­va­cy pol­i­cy, we would like to inform you about the types of your per­son­al data (here­inafter also referred to as "data") that we process, for what pur­pos­es, and to what extent. This pri­va­cy pol­i­cy applies to all pro­cess­ing of per­son­al data car­ried out by us, both in the con­text of pro­vid­ing our ser­vices and in par­tic­u­lar on our web­sites, in mobile appli­ca­tions, and with­in exter­nal online pres­ences such as our social media pro­files (here­inafter col­lec­tive­ly referred to as "Online Offer­ing").

The terms used are not gen­der-spe­cif­ic.

Last updat­ed: May 27, 2026

Table of Contents

  • Pre­am­ble
  • Con­troller
  • Overview of Pro­cess­ing Activ­i­ties
  • Applic­a­ble Legal Bases
  • Secu­ri­ty Mea­sures
  • Trans­fer of Per­son­al Data
  • Inter­na­tion­al Data Trans­fers
  • Gen­er­al Infor­ma­tion on Data Stor­age and Dele­tion
  • Rights of Data Sub­jects
  • Pro­vi­sion of the Online Offer­ing and Web Host­ing
  • Use of Cook­ies
  • Blogs and Pub­li­ca­tion Media
  • Con­tact and Inquiry Man­age­ment
  • Pro­mo­tion­al Com­mu­ni­ca­tion via Email, Post, Fax, or Tele­phone
  • Sur­veys and Ques­tion­naires
  • Web Ana­lyt­ics, Mon­i­tor­ing, and Opti­miza­tion
  • Pri­va­cy Infor­ma­tion for Whistle­blow­ers
  • Changes and Updates
  • Def­i­n­i­tions

Controller

Björn Burghard c/o Block Ser­vices Stuttgarter Str. 106 70736 Fell­bach Ger­many

Email address: contact@waycleft.com

Overview of Processing Activities

The fol­low­ing overview sum­ma­rizes the types of data processed and the pur­pos­es of their pro­cess­ing, and refers to the data sub­jects con­cerned.

Types of Data Processed

  • Mas­ter data
  • Employ­ee data
  • Con­tact data
  • Con­tent data
  • Usage data
  • Meta, com­mu­ni­ca­tion, and pro­ce­dur­al data
  • Log data

Categories of Data Subjects

  • Employ­ees
  • Com­mu­ni­ca­tion part­ners
  • Users
  • Par­tic­i­pants
  • Third par­ties
  • Whistle­blow­ers

Purposes of Processing

  • Com­mu­ni­ca­tion
  • Secu­ri­ty mea­sures
  • Direct mar­ket­ing
  • Reach mea­sure­ment
  • Track­ing
  • Orga­ni­za­tion­al and admin­is­tra­tive pro­ce­dures
  • Feed­back
  • Sur­veys and ques­tion­naires
  • Mar­ket­ing
  • Pro­files with user-relat­ed infor­ma­tion
  • Pro­vi­sion of our online offer­ing and user-friend­li­ness
  • Infor­ma­tion tech­nol­o­gy infra­struc­ture
  • Whistle­blow­er pro­tec­tion
  • Sales pro­mo­tion

Applicable Legal Bases

Applic­a­ble legal bases under the GDPR: The fol­low­ing pro­vides an overview of the legal bases of the GDPR on which we process per­son­al data. Please note that in addi­tion to the pro­vi­sions of the GDPR, nation­al data pro­tec­tion reg­u­la­tions may apply in your or our coun­try of res­i­dence or domi­cile. Should more spe­cif­ic legal bases be applic­a­ble in indi­vid­ual cas­es, we will inform you of these in this pri­va­cy pol­i­cy.

  • Con­sent (Art. 6(1)(a) GDPR) - The data sub­ject has giv­en con­sent to the pro­cess­ing of their per­son­al data for one or more spe­cif­ic pur­pos­es.
  • Per­for­mance of a con­tract and pre-con­trac­tu­al inquiries (Art. 6(1)(b) GDPR) - Pro­cess­ing is nec­es­sary for the per­for­mance of a con­tract to which the data sub­ject is par­ty, or for the imple­men­ta­tion of pre-con­trac­tu­al mea­sures tak­en at the request of the data sub­ject.
  • Legal oblig­a­tion (Art. 6(1)© GDPR) - Pro­cess­ing is nec­es­sary for com­pli­ance with a legal oblig­a­tion to which the con­troller is sub­ject.
  • Legit­i­mate inter­ests (Art. 6(1)(f) GDPR) - Pro­cess­ing is nec­es­sary for the pur­pos­es of the legit­i­mate inter­ests pur­sued by the con­troller or by a third par­ty, pro­vid­ed that such inter­ests are not over­rid­den by the inter­ests, fun­da­men­tal rights, and free­doms of the data sub­ject which require the pro­tec­tion of per­son­al data.

Nation­al data pro­tec­tion reg­u­la­tions in Ger­many: In addi­tion to the data pro­tec­tion pro­vi­sions of the GDPR, nation­al data pro­tec­tion reg­u­la­tions apply in Ger­many. This includes in par­tic­u­lar the Fed­er­al Data Pro­tec­tion Act (Bun­des­daten­schutzge­setz - BDSG). The BDSG con­tains spe­cif­ic pro­vi­sions on the right of access, the right to era­sure, the right to object, the pro­cess­ing of spe­cial cat­e­gories of per­son­al data, pro­cess­ing for oth­er pur­pos­es, and the trans­fer of data as well as auto­mat­ed indi­vid­ual deci­sion-mak­ing, includ­ing pro­fil­ing. Fur­ther­more, state data pro­tec­tion laws of the indi­vid­ual Ger­man fed­er­al states may apply.

Note on the applic­a­bil­i­ty of the GDPR and the Swiss DPA: These pri­va­cy notices serve to pro­vide infor­ma­tion under both the Swiss Fed­er­al Act on Data Pro­tec­tion (DPA) and the Gen­er­al Data Pro­tec­tion Reg­u­la­tion (GDPR). For this rea­son, please note that the terms of the GDPR are used due to their broad­er geo­graph­ic applic­a­bil­i­ty and com­pre­hen­si­bil­i­ty. In par­tic­u­lar, instead of the terms used in the Swiss DPA such as "pro­cess­ing" of "per­son­al data," "over­rid­ing inter­est," and "par­tic­u­lar­ly sen­si­tive per­son­al data," the GDPR terms "pro­cess­ing" of "per­son­al data," "legit­i­mate inter­est," and "spe­cial cat­e­gories of data" are used. How­ev­er, the legal mean­ing of the terms con­tin­ues to be deter­mined under the Swiss DPA with­in the scope of its applic­a­bil­i­ty.

Applic­a­bil­i­ty of data pro­tec­tion reg­u­la­tions in the coun­try of domi­cile: In the coun­try where the con­troller is domi­ciled, nation­al data pro­tec­tion reg­u­la­tions apply in addi­tion to the Gen­er­al Data Pro­tec­tion Reg­u­la­tion (GDPR).

Security Measures

We take appro­pri­ate tech­ni­cal and orga­ni­za­tion­al mea­sures in accor­dance with legal require­ments, tak­ing into account the state of the art, imple­men­ta­tion costs, and the nature, scope, cir­cum­stances, and pur­pos­es of pro­cess­ing, as well as the vary­ing like­li­hood and sever­i­ty of risks to the rights and free­doms of nat­ur­al per­sons, to ensure a lev­el of pro­tec­tion appro­pri­ate to the risk.

These mea­sures include in par­tic­u­lar ensur­ing the con­fi­den­tial­i­ty, integri­ty, and avail­abil­i­ty of data by con­trol­ling phys­i­cal and elec­tron­ic access to data, as well as access, input, trans­fer, avail­abil­i­ty assur­ance, and sep­a­ra­tion of data. Fur­ther­more, we have estab­lished pro­ce­dures to ensure the exer­cise of data sub­ject rights, the dele­tion of data, and respons­es to data threats. We also con­sid­er the pro­tec­tion of per­son­al data from the out­set in the devel­op­ment or selec­tion of hard­ware, soft­ware, and pro­ce­dures, in accor­dance with the prin­ci­ples of data pro­tec­tion by design and by default.

Secur­ing online con­nec­tions through TLS/SSL encryp­tion tech­nol­o­gy (HTTPS): To pro­tect data trans­mit­ted via our online ser­vices from unau­tho­rized access, we use TLS/SSL encryp­tion tech­nol­o­gy. Secure Sock­ets Lay­er (SSL) and Trans­port Lay­er Secu­ri­ty (TLS) are the cor­ner­stones of secure data trans­mis­sion on the inter­net. These tech­nolo­gies encrypt the infor­ma­tion trans­mit­ted between the web­site or app and the user's brows­er (or between two servers), there­by pro­tect­ing the data from unau­tho­rized access. TLS, as the more advanced and secure ver­sion of SSL, ensures that all data trans­mis­sions meet the high­est secu­ri­ty stan­dards. When a web­site is secured by an SSL/TLS cer­tifi­cate, this is indi­cat­ed by the dis­play of HTTPS in the URL. This serves as an indi­ca­tor to users that their data is being trans­mit­ted secure­ly and in encrypt­ed form.

Transfer of Personal Data

In the course of pro­cess­ing per­son­al data, it may occur that such data is trans­ferred to or dis­closed to oth­er enti­ties, com­pa­nies, legal­ly inde­pen­dent orga­ni­za­tion­al units, or indi­vid­u­als. Recip­i­ents of this data may include, for exam­ple, ser­vice providers com­mis­sioned with IT tasks, or providers of ser­vices and con­tent inte­grat­ed into a web­site. In such cas­es, we com­ply with legal require­ments and in par­tic­u­lar enter into appro­pri­ate con­tracts or agree­ments with the recip­i­ents of your data that serve to pro­tect your data.

International Data Transfers

Data pro­cess­ing in third coun­tries: Where we trans­fer data to a third coun­try (i.e., out­side the Euro­pean Union (EU) or the Euro­pean Eco­nom­ic Area (EEA)), or where this occurs in the con­text of using third-par­ty ser­vices or dis­clos­ing or trans­fer­ring data to oth­er per­sons, enti­ties, or com­pa­nies (as indi­cat­ed by the postal address of the respec­tive provider or where the pri­va­cy pol­i­cy explic­it­ly ref­er­ences data trans­fers to third coun­tries), this is always done in accor­dance with legal require­ments.

For data trans­fers to the USA, we pri­mar­i­ly rely on the Data Pri­va­cy Frame­work (DPF), which was rec­og­nized as a secure legal frame­work by an ade­qua­cy deci­sion of the EU Com­mis­sion on July 10, 2023. In addi­tion, we have con­clud­ed Stan­dard Con­trac­tu­al Claus­es with the respec­tive providers, which com­ply with the require­ments of the EU Com­mis­sion and estab­lish con­trac­tu­al oblig­a­tions to pro­tect your data.

This dual safe­guard ensures com­pre­hen­sive pro­tec­tion of your data: the DPF forms the pri­ma­ry lay­er of pro­tec­tion, while the Stan­dard Con­trac­tu­al Claus­es serve as addi­tion­al secu­ri­ty. Should changes occur with­in the frame­work of the DPF, the Stan­dard Con­trac­tu­al Claus­es will serve as a reli­able fall­back option. In this way, we ensure that your data remains ade­quate­ly pro­tect­ed at all times, even in the event of polit­i­cal or legal changes.

For indi­vid­ual ser­vice providers, we inform you whether they are cer­ti­fied under the DPF and whether Stan­dard Con­trac­tu­al Claus­es are in place. Fur­ther infor­ma­tion on the DPF and a list of cer­ti­fied com­pa­nies can be found on the web­site of the U.S. Depart­ment of Com­merce at https://www.dataprivacyframework.gov/ (in Eng­lish).

For data trans­fers to oth­er third coun­tries, appro­pri­ate safe­guards apply, in par­tic­u­lar Stan­dard Con­trac­tu­al Claus­es, explic­it con­sent, or legal­ly required trans­fers. Infor­ma­tion on third-coun­try trans­fers and applic­a­ble ade­qua­cy deci­sions can be found in the infor­ma­tion pro­vid­ed by the EU Com­mis­sion at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

General Information on Data Storage and Deletion

We delete per­son­al data that we process in accor­dance with legal pro­vi­sions as soon as the under­ly­ing con­sents are revoked or no fur­ther legal basis for pro­cess­ing exists. This applies to cas­es where the orig­i­nal pro­cess­ing pur­pose ceas­es to exist or the data is no longer need­ed. Excep­tions to this rule exist where legal oblig­a­tions or spe­cial inter­ests require longer reten­tion or archiv­ing of data.

In par­tic­u­lar, data that must be retained for com­mer­cial or tax law rea­sons, or whose stor­age is nec­es­sary for legal pro­ceed­ings or the pro­tec­tion of the rights of oth­er nat­ur­al or legal per­sons, must be archived accord­ing­ly.

Our pri­va­cy notices con­tain addi­tion­al infor­ma­tion on the reten­tion and dele­tion of data that applies specif­i­cal­ly to cer­tain pro­cess­ing oper­a­tions.

Where mul­ti­ple reten­tion peri­ods or dele­tion dead­lines apply to a giv­en piece of data, the longest peri­od always pre­vails. Data that is no longer processed for its orig­i­nal­ly intend­ed pur­pose but is retained due to legal require­ments or oth­er rea­sons will be processed exclu­sive­ly for the rea­sons jus­ti­fy­ing its reten­tion.

Com­mence­ment of dead­lines at year-end: Where a dead­line does not express­ly begin on a spe­cif­ic date and amounts to at least one year, it auto­mat­i­cal­ly com­mences at the end of the cal­en­dar year in which the event trig­ger­ing the dead­line occurred. In the case of ongo­ing con­trac­tu­al rela­tion­ships in which data is stored, the trig­ger­ing event is the date on which the ter­mi­na­tion takes effect or the legal rela­tion­ship oth­er­wise ends.

Rights of Data Subjects

Rights of data sub­jects under the GDPR: As a data sub­ject, you are enti­tled to var­i­ous rights under the GDPR, aris­ing in par­tic­u­lar from Arti­cles 15 to 21 GDPR:

  • Right to object: You have the right to object at any time, on grounds relat­ing to your par­tic­u­lar sit­u­a­tion, to the pro­cess­ing of per­son­al data con­cern­ing you which is car­ried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to pro­fil­ing based on these pro­vi­sions. Where per­son­al data con­cern­ing you is processed for the pur­pose of direct mar­ket­ing, you have the right to object at any time to the pro­cess­ing of per­son­al data con­cern­ing you for the pur­pose of such mar­ket­ing; this also applies to pro­fil­ing inso­far as it is relat­ed to such direct mar­ket­ing.
  • Right to with­draw con­sent: You have the right to with­draw con­sent at any time.
  • Right of access: You have the right to obtain con­fir­ma­tion as to whether per­son­al data con­cern­ing you is being processed and to access such data, as well as fur­ther infor­ma­tion and a copy of the data in accor­dance with legal require­ments.
  • Right to rec­ti­fi­ca­tion: You have the right, in accor­dance with legal require­ments, to request the com­ple­tion of data con­cern­ing you or the rec­ti­fi­ca­tion of inac­cu­rate data con­cern­ing you.
  • Right to era­sure and restric­tion of pro­cess­ing: You have the right, in accor­dance with legal require­ments, to request that data con­cern­ing you be erased with­out undue delay, or alter­na­tive­ly to request restric­tion of the pro­cess­ing of such data in accor­dance with legal require­ments.
  • Right to data porta­bil­i­ty: You have the right to receive the data con­cern­ing you that you have pro­vid­ed to us in a struc­tured, com­mon­ly used, and machine-read­able for­mat, or to request its trans­fer to anoth­er con­troller, in accor­dance with legal require­ments.
  • Com­plaint to a super­vi­so­ry author­i­ty: With­out prej­u­dice to any oth­er admin­is­tra­tive or judi­cial rem­e­dy, you have the right to lodge a com­plaint with a super­vi­so­ry author­i­ty, in par­tic­u­lar in the Mem­ber State of your habit­u­al res­i­dence, your place of work, or the place of the alleged infringe­ment, if you con­sid­er that the pro­cess­ing of per­son­al data con­cern­ing you infringes the pro­vi­sions of the GDPR.

Provision of the Online Offering and Web Hosting

We process users' data in order to pro­vide our online ser­vices. For this pur­pose, we process the user's IP address, which is nec­es­sary to deliv­er the con­tent and func­tions of our online ser­vices to the user's brows­er or device.

  • Types of data processed: Usage data (e.g., page views and time spent, click paths, usage inten­si­ty and fre­quen­cy, device types and oper­at­ing sys­tems used, inter­ac­tions with con­tent and fea­tures); meta, com­mu­ni­ca­tion, and pro­ce­dur­al data (e.g., IP address­es, time­stamps, iden­ti­fi­ca­tion num­bers, per­sons involved); log data (e.g., log files relat­ing to logins, data retrieval, or access times); con­tent data (e.g., text or image mes­sages and posts as well as relat­ed infor­ma­tion such as author­ship details or time of cre­ation).
  • Data sub­jects: Users (e.g., web­site vis­i­tors, users of online ser­vices).
  • Pur­pos­es of pro­cess­ing and legit­i­mate inter­ests: Pro­vi­sion of our online offer­ing and user-friend­li­ness; infor­ma­tion tech­nol­o­gy infra­struc­ture (oper­a­tion and pro­vi­sion of infor­ma­tion sys­tems and tech­ni­cal devices (com­put­ers, servers, etc.)); secu­ri­ty mea­sures.
  • Reten­tion and dele­tion: Dele­tion in accor­dance with the infor­ma­tion pro­vid­ed in the sec­tion "Gen­er­al Infor­ma­tion on Data Stor­age and Dele­tion."
  • Legal bases: Legit­i­mate inter­ests (Art. 6(1)(f) GDPR).

Fur­ther infor­ma­tion on pro­cess­ing oper­a­tions, pro­ce­dures, and ser­vices:

  • Pro­vi­sion of the online offer­ing on rent­ed serv­er space: For the pro­vi­sion of our online offer­ing, we use stor­age space, com­put­ing capac­i­ty, and soft­ware that we rent or oth­er­wise obtain from a cor­re­spond­ing serv­er provider (also referred to as a "web host"); legal bases: legit­i­mate inter­ests (Art. 6(1)(f) GDPR).
  • Col­lec­tion of access data and log files: Access to our online offer­ing is logged in the form of so-called "serv­er log files." Serv­er log files may include the address and name of the web pages and files accessed, date and time of access, data vol­umes trans­ferred, noti­fi­ca­tion of suc­cess­ful retrieval, brows­er type and ver­sion, the user's oper­at­ing sys­tem, refer­rer URL (the pre­vi­ous­ly vis­it­ed page), and typ­i­cal­ly IP address­es and the request­ing provider. Serv­er log files may be used for secu­ri­ty pur­pos­es, e.g., to pre­vent serv­er over­load (par­tic­u­lar­ly in the case of abu­sive attacks, so-called DDoS attacks), and to ensure serv­er capac­i­ty and sta­bil­i­ty; legal bases: legit­i­mate inter­ests (Art. 6(1)(f) GDPR). Dele­tion of data: Log file infor­ma­tion is stored for a max­i­mum of 30 days and then delet­ed or anonymized. Data whose fur­ther reten­tion is nec­es­sary for evi­den­tiary pur­pos­es is exempt from dele­tion until the final res­o­lu­tion of the respec­tive inci­dent.
  • Email send­ing and host­ing: The web host­ing ser­vices we use also include the send­ing, receiv­ing, and stor­age of emails. For these pur­pos­es, the address­es of recip­i­ents and senders, as well as fur­ther infor­ma­tion relat­ing to email send­ing (e.g., the providers involved) and the con­tent of the respec­tive emails are processed. The afore­men­tioned data may also be processed for the pur­pose of spam detec­tion. Please note that emails on the inter­net are gen­er­al­ly not sent in encrypt­ed form. As a rule, emails are encrypt­ed in tran­sit, but (unless end-to-end encryp­tion is used) not on the servers from which they are sent and received. We can there­fore assume no respon­si­bil­i­ty for the trans­mis­sion path of emails between the sender and recep­tion on our serv­er; legal bases: legit­i­mate inter­ests (Art. 6(1)(f) GDPR).
  • HOSTINGER: Ser­vices in the field of pro­vid­ing infor­ma­tion tech­nol­o­gy infra­struc­ture and relat­ed ser­vices (e.g., stor­age space and/or com­put­ing capac­i­ty); ser­vice provider: HOSTINGER INTERNATIONAL LIMITED; 61 Lor­dou Vironos Street; Lumiel Build­ing, 4th floor; CYP-6023 Lar­naca; Cyprus; legal bases: legit­i­mate inter­ests (Art. 6(1)(f) GDPR); web­site: https://www.hostinger.de/; pri­va­cy pol­i­cy: https://www.hostinger.de/datenschutz-bestimmungen; data pro­cess­ing agree­ment: https://www.hostinger.com/legal/dpa

Use of Cookies

The term "cook­ies" refers to func­tions that store infor­ma­tion on users' devices and read infor­ma­tion from them. Cook­ies may also be used for var­i­ous pur­pos­es, such as ensur­ing the func­tion­al­i­ty, secu­ri­ty, and con­ve­nience of online offer­ings, as well as for ana­lyz­ing vis­i­tor traf­fic. We use cook­ies in accor­dance with legal require­ments. Where nec­es­sary, we obtain users' pri­or con­sent. If con­sent is not required, we rely on our legit­i­mate inter­ests. This applies where the stor­age and read­ing of infor­ma­tion is essen­tial to pro­vide explic­it­ly request­ed con­tent and func­tions. This includes, for exam­ple, sav­ing set­tings and ensur­ing the func­tion­al­i­ty and secu­ri­ty of our online offer­ing. Con­sent may be with­drawn at any time. We clear­ly inform users about the scope and which cook­ies are used.

Notes on data pro­tec­tion legal bases: Whether we process per­son­al data using cook­ies depends on con­sent. If con­sent is giv­en, it serves as the legal basis. With­out con­sent, we rely on our legit­i­mate inter­ests, which are explained in this sec­tion and in the con­text of the respec­tive ser­vices and pro­ce­dures.

Stor­age dura­tion: The fol­low­ing types of cook­ies are dis­tin­guished with regard to stor­age dura­tion:

  • Tem­po­rary cook­ies (also: ses­sion cook­ies): Tem­po­rary cook­ies are delet­ed at the lat­est after a user has left an online offer­ing and closed their device (e.g., brows­er or mobile appli­ca­tion).
  • Per­ma­nent cook­ies: Per­ma­nent cook­ies remain stored even after the device is closed. For exam­ple, login sta­tus can be saved and pre­ferred con­tent dis­played direct­ly when the user revis­its a web­site. User data col­lect­ed through cook­ies may also be used for reach mea­sure­ment. Unless we pro­vide users with explic­it infor­ma­tion about the type and stor­age dura­tion of cook­ies (e.g., when obtain­ing con­sent), they should assume that cook­ies are per­ma­nent and may have a stor­age dura­tion of up to two years.

Gen­er­al infor­ma­tion on with­draw­al and objec­tion (opt-out): Users may with­draw their con­sent at any time and also file an objec­tion to pro­cess­ing in accor­dance with legal require­ments, includ­ing through the pri­va­cy set­tings of their brows­er.

  • Types of data processed: Meta, com­mu­ni­ca­tion, and pro­ce­dur­al data (e.g., IP address­es, time­stamps, iden­ti­fi­ca­tion num­bers, per­sons involved).
  • Data sub­jects: Users (e.g., web­site vis­i­tors, users of online ser­vices).
  • Legal bases: Legit­i­mate inter­ests (Art. 6(1)(f) GDPR); con­sent (Art. 6(1)(a) GDPR).

Fur­ther infor­ma­tion on pro­cess­ing oper­a­tions, pro­ce­dures, and ser­vices:

  • Pro­cess­ing of cook­ie data based on con­sent: We use a con­sent man­age­ment solu­tion through which users' con­sent to the use of cook­ies or to the pro­ce­dures and providers named in the con­sent man­age­ment solu­tion is obtained. This pro­ce­dure serves to obtain, log, man­age, and with­draw con­sent, in par­tic­u­lar with regard to the use of cook­ies and com­pa­ra­ble tech­nolo­gies used to store, read, and process infor­ma­tion on users' devices. As part of this pro­ce­dure, users' con­sent for the use of cook­ies and the asso­ci­at­ed pro­cess­ing of infor­ma­tion, includ­ing the spe­cif­ic pro­cess­ing oper­a­tions and providers named in the con­sent man­age­ment pro­ce­dure, is obtained. Users also have the option to man­age and with­draw their con­sent. Con­sent dec­la­ra­tions are stored to avoid repeat­ed queries and to be able to pro­vide proof of con­sent in accor­dance with legal require­ments. Stor­age takes place on the serv­er side and/or in a cook­ie (so-called opt-in cook­ie) or by means of com­pa­ra­ble tech­nolo­gies, in order to be able to assign con­sent to a spe­cif­ic user or their device. Unless spe­cif­ic infor­ma­tion on the providers of con­sent man­age­ment ser­vices is avail­able, the fol­low­ing gen­er­al infor­ma­tion applies: The dura­tion of con­sent stor­age is up to two years. A pseu­do­ny­mous user iden­ti­fi­er is cre­at­ed and stored togeth­er with the time of con­sent, infor­ma­tion on the scope of con­sent (e.g., rel­e­vant cat­e­gories of cook­ies and/or ser­vice providers), and infor­ma­tion about the brows­er, sys­tem, and device used; legal bases: con­sent (Art. 6(1)(a) GDPR).

Blogs and Publication Media

We use blogs or com­pa­ra­ble means of online com­mu­ni­ca­tion and pub­li­ca­tion (here­inafter "pub­li­ca­tion medi­um"). Read­ers' data is processed for the pur­pos­es of the pub­li­ca­tion medi­um only inso­far as this is nec­es­sary for its pre­sen­ta­tion and com­mu­ni­ca­tion between authors and read­ers, or for secu­ri­ty rea­sons. For fur­ther infor­ma­tion, we refer to the infor­ma­tion on the pro­cess­ing of vis­i­tors to our pub­li­ca­tion medi­um with­in these pri­va­cy notices.

  • Types of data processed: Mas­ter data (e.g., full name, res­i­den­tial address, con­tact infor­ma­tion, cus­tomer num­ber, etc.); con­tact data (e.g., postal and email address­es or tele­phone num­bers); con­tent data (e.g., text or image mes­sages and posts as well as relat­ed infor­ma­tion such as author­ship details or time of cre­ation); usage data (e.g., page views and time spent, click paths, usage inten­si­ty and fre­quen­cy, device types and oper­at­ing sys­tems used, inter­ac­tions with con­tent and fea­tures); meta, com­mu­ni­ca­tion, and pro­ce­dur­al data (e.g., IP address­es, time­stamps, iden­ti­fi­ca­tion num­bers, per­sons involved).
  • Data sub­jects: Users (e.g., web­site vis­i­tors, users of online ser­vices).
  • Pur­pos­es of pro­cess­ing and legit­i­mate inter­ests: Feed­back (e.g., col­lect­ing feed­back via online form); pro­vi­sion of our online offer­ing and user-friend­li­ness; secu­ri­ty mea­sures.
  • Reten­tion and dele­tion: Dele­tion in accor­dance with the infor­ma­tion pro­vid­ed in the sec­tion "Gen­er­al Infor­ma­tion on Data Stor­age and Dele­tion."
  • Legal bases: Legit­i­mate inter­ests (Art. 6(1)(f) GDPR).

Fur­ther infor­ma­tion on pro­cess­ing oper­a­tions, pro­ce­dures, and ser­vices:

  • Retrieval of Word­Press emo­jis and smi­lies: With­in our Word­Press blog, graph­ic emo­jis (or smi­lies), i.e., small graph­ic files express­ing emo­tions, are used for the pur­pose of effi­cient­ly inte­grat­ing con­tent ele­ments, retrieved from exter­nal servers. The serv­er providers col­lect users' IP address­es. This is nec­es­sary so that the emo­ji files can be deliv­ered to users' browsers; ser­vice provider: Aut O'Mat­tic A8C Ire­land Ltd., Grand Canal Dock, 25 Her­bert Pl, Dublin, D02 AY86, Ire­land; legal bases: legit­i­mate inter­ests (Art. 6(1)(f) GDPR); web­site: https://automattic.com; pri­va­cy pol­i­cy: https://automattic.com/privacy; data pro­cess­ing agree­ment: pro­vid­ed by the ser­vice provider. Basis for third-coun­try trans­fers: Data Pri­va­cy Frame­work (DPF), Stan­dard Con­trac­tu­al Claus­es (pro­vid­ed by the ser­vice provider).
  • Akismet anti-spam check: We use the "Akismet" ser­vice on the basis of our legit­i­mate inter­ests. Akismet is used to dis­tin­guish com­ments from real peo­ple from spam com­ments. For this pur­pose, all com­ment data is sent to a serv­er in the USA, where it is ana­lyzed and stored for com­par­i­son pur­pos­es for four days. If a com­ment has been clas­si­fied as spam, the data is stored beyond this peri­od. This data includes the name entered, the email address, the IP address, the com­ment con­tent, the refer­rer, infor­ma­tion about the brows­er and com­put­er sys­tem used, and the time of entry. Users are wel­come to use pseu­do­nyms or to refrain from enter­ing their name or email address. They can pre­vent the trans­mis­sion of data entire­ly by not using our com­ment sys­tem. This would be unfor­tu­nate, but unfor­tu­nate­ly we see no alter­na­tives that work equal­ly effec­tive­ly; ser­vice provider: Aut O'Mat­tic A8C Ire­land Ltd., Grand Canal Dock, 25 Her­bert Pl, Dublin, D02 AY86, Ire­land; legal bases: legit­i­mate inter­ests (Art. 6(1)(f) GDPR); web­site: https://automattic.com; pri­va­cy pol­i­cy: https://automattic.com/privacy/; data pro­cess­ing agree­ment: pro­vid­ed by the ser­vice provider. Basis for third-coun­try trans­fers: Data Pri­va­cy Frame­work (DPF), Stan­dard Con­trac­tu­al Claus­es (pro­vid­ed by the ser­vice provider).
  • Updraft­Plus: Back­up soft­ware and back­up stor­age; ser­vice provider: Sim­ba Host­ing Ltd., 11, Bar­ringer Way, St. Neots, Cambs., PE19 1LW, GB; legal bases: legit­i­mate inter­ests (Art. 6(1)(f) GDPR); web­site: https://teamupdraft.com/updraftplus/; pri­va­cy pol­i­cy: https://teamupdraft.com/privacy/.

Contact and Inquiry Management

When con­tact­ing us (e.g., by post, con­tact form, email, tele­phone, or via social media) and in the con­text of exist­ing user and busi­ness rela­tion­ships, the infor­ma­tion pro­vid­ed by the inquir­ing per­sons is processed inso­far as this is nec­es­sary to respond to the con­tact inquiries and any request­ed mea­sures.

  • Types of data processed: Con­tact data (e.g., postal and email address­es or tele­phone num­bers); con­tent data (e.g., text or image mes­sages and posts as well as relat­ed infor­ma­tion such as author­ship details or time of cre­ation); meta, com­mu­ni­ca­tion, and pro­ce­dur­al data (e.g., IP address­es, time­stamps, iden­ti­fi­ca­tion num­bers, per­sons involved).
  • Data sub­jects: Com­mu­ni­ca­tion part­ners.
  • Pur­pos­es of pro­cess­ing and legit­i­mate inter­ests: Com­mu­ni­ca­tion; orga­ni­za­tion­al and admin­is­tra­tive pro­ce­dures; feed­back (e.g., col­lect­ing feed­back via online form); pro­vi­sion of our online offer­ing and user-friend­li­ness.
  • Reten­tion and dele­tion: Dele­tion in accor­dance with the infor­ma­tion pro­vid­ed in the sec­tion "Gen­er­al Infor­ma­tion on Data Stor­age and Dele­tion."
  • Legal bases: Legit­i­mate inter­ests (Art. 6(1)(f) GDPR); per­for­mance of a con­tract and pre-con­trac­tu­al inquiries (Art. 6(1)(b) GDPR).

Fur­ther infor­ma­tion on pro­cess­ing oper­a­tions, pro­ce­dures, and ser­vices:

  • Con­tact form: When con­tact­ing us via our con­tact form, email, or oth­er com­mu­ni­ca­tion chan­nels, we process the per­son­al data trans­mit­ted to us for the pur­pose of respond­ing to and han­dling the respec­tive inquiry. This typ­i­cal­ly includes infor­ma­tion such as name, con­tact details, and, where applic­a­ble, fur­ther infor­ma­tion com­mu­ni­cat­ed to us that is nec­es­sary for appro­pri­ate han­dling. We use this data exclu­sive­ly for the stat­ed pur­pose of con­tact and com­mu­ni­ca­tion; legal bases: per­for­mance of a con­tract and pre-con­trac­tu­al inquiries (Art. 6(1)(b) GDPR), legit­i­mate inter­ests (Art. 6(1)(f) GDPR).

Promotional Communication via Email, Post, Fax, or Telephone

We process per­son­al data for the pur­pos­es of pro­mo­tion­al com­mu­ni­ca­tion, which may take place through var­i­ous chan­nels such as email, tele­phone, post, or fax, in accor­dance with legal require­ments.

Recip­i­ents have the right to with­draw their con­sent at any time or to object to pro­mo­tion­al com­mu­ni­ca­tion at any time free of charge via the con­tact options men­tioned above.

After with­draw­al or objec­tion, we store the data nec­es­sary to prove the pre­vi­ous autho­riza­tion for con­tact or dis­patch for up to three years after the end of the year of with­draw­al or objec­tion, on the basis of our legit­i­mate inter­ests. The pro­cess­ing of this data is lim­it­ed to the pur­pose of a poten­tial defense against claims. On the basis of our legit­i­mate inter­est in per­ma­nent­ly respect­ing the with­draw­al or objec­tion of users, we also store the data nec­es­sary to avoid renewed con­tact (e.g., depend­ing on the com­mu­ni­ca­tion chan­nel, the email address, tele­phone num­ber, or name).

  • Types of data processed: Mas­ter data (e.g., full name, res­i­den­tial address, con­tact infor­ma­tion, cus­tomer num­ber, etc.); con­tact data (e.g., postal and email address­es or tele­phone num­bers); con­tent data (e.g., text or image mes­sages and posts as well as relat­ed infor­ma­tion such as author­ship details or time of cre­ation).
  • Data sub­jects: Com­mu­ni­ca­tion part­ners.
  • Pur­pos­es of pro­cess­ing and legit­i­mate inter­ests: Direct mar­ket­ing (e.g., by email or post); mar­ket­ing; sales pro­mo­tion.
  • Reten­tion and dele­tion: Dele­tion in accor­dance with the infor­ma­tion pro­vid­ed in the sec­tion "Gen­er­al Infor­ma­tion on Data Stor­age and Dele­tion."
  • Legal bases: Con­sent (Art. 6(1)(a) GDPR); legit­i­mate inter­ests (Art. 6(1)(f) GDPR).

Surveys and Questionnaires

We con­duct sur­veys and ques­tion­naires to col­lect infor­ma­tion for the respec­tive­ly com­mu­ni­cat­ed sur­vey or ques­tion­naire pur­pose. The sur­veys and ques­tion­naires con­duct­ed by us (here­inafter "sur­veys") are eval­u­at­ed anony­mous­ly. Per­son­al data is only processed to the extent nec­es­sary for the pro­vi­sion and tech­ni­cal exe­cu­tion of the sur­veys (e.g., pro­cess­ing of the IP address to dis­play the sur­vey in the user's brows­er, or using a cook­ie to enable resump­tion of the sur­vey).

  • Types of data processed: Mas­ter data (e.g., full name, res­i­den­tial address, con­tact infor­ma­tion, cus­tomer num­ber, etc.); con­tact data (e.g., postal and email address­es or tele­phone num­bers); con­tent data (e.g., text or image mes­sages and posts as well as relat­ed infor­ma­tion such as author­ship details or time of cre­ation); usage data (e.g., page views and time spent, click paths, usage inten­si­ty and fre­quen­cy, device types and oper­at­ing sys­tems used, inter­ac­tions with con­tent and fea­tures).
  • Data sub­jects: Par­tic­i­pants.
  • Pur­pos­es of pro­cess­ing and legit­i­mate inter­ests: Feed­back (e.g., col­lect­ing feed­back via online form); sur­veys and ques­tion­naires (e.g., sur­veys with input options, mul­ti­ple-choice ques­tions).
  • Reten­tion and dele­tion: Dele­tion in accor­dance with the infor­ma­tion pro­vid­ed in the sec­tion "Gen­er­al Infor­ma­tion on Data Stor­age and Dele­tion."
  • Legal bases: Legit­i­mate inter­ests (Art. 6(1)(f) GDPR).

Web Analytics, Monitoring, and Optimization

Web ana­lyt­ics (also referred to as "reach mea­sure­ment") serves to eval­u­ate vis­i­tor traf­fic to our online offer­ing and may encom­pass behav­ior, inter­ests, or demo­graph­ic infor­ma­tion about vis­i­tors, such as age or gen­der, as pseu­do­ny­mous val­ues. With the help of reach analy­sis, we can iden­ti­fy, for exam­ple, at what time our online offer­ing or its func­tions or con­tent are used most fre­quent­ly, or when they invite reuse. Sim­i­lar­ly, we can deter­mine which areas require opti­miza­tion.

In addi­tion to web ana­lyt­ics, we may also use test­ing pro­ce­dures to test and opti­mize dif­fer­ent ver­sions of our online offer­ing or its com­po­nents.

Unless oth­er­wise stat­ed below, pro­files - i.e., data con­sol­i­dat­ed for a usage process - may be cre­at­ed for these pur­pos­es, and infor­ma­tion may be stored in or read from a brows­er or device. The infor­ma­tion col­lect­ed includes in par­tic­u­lar web­sites vis­it­ed and ele­ments used there­in, as well as tech­ni­cal infor­ma­tion such as the brows­er used, the com­put­er sys­tem used, and infor­ma­tion on usage times. Where users have con­sent­ed to the col­lec­tion of their loca­tion data by us or by the providers of the ser­vices we use, loca­tion data may also be processed.

In addi­tion, users' IP address­es are stored. How­ev­er, we use an IP mask­ing pro­ce­dure (i.e., pseu­do­nymiza­tion by trun­cat­ing the IP address) to pro­tect users. In gen­er­al, no clear-text user data (such as email address­es or names) is stored in the con­text of web ana­lyt­ics, A/B test­ing, and opti­miza­tion, but rather pseu­do­nyms. This means that nei­ther we nor the providers of the soft­ware used know the actu­al iden­ti­ty of users, but only the infor­ma­tion stored in their pro­files for the pur­pose of the respec­tive pro­ce­dures.

Notes on legal bases: Where we ask users for their con­sent to the use of third-par­ty providers, the legal basis for data pro­cess­ing is con­sent. Oth­er­wise, user data is processed on the basis of our legit­i­mate inter­ests (i.e., inter­est in effi­cient, eco­nom­i­cal, and recip­i­ent-friend­ly ser­vices). In this con­text, we would also like to draw your atten­tion to the infor­ma­tion on the use of cook­ies in this pri­va­cy pol­i­cy.

  • Types of data processed: Usage data (e.g., page views and time spent, click paths, usage inten­si­ty and fre­quen­cy, device types and oper­at­ing sys­tems used, inter­ac­tions with con­tent and fea­tures); meta, com­mu­ni­ca­tion, and pro­ce­dur­al data (e.g., IP address­es, time­stamps, iden­ti­fi­ca­tion num­bers, per­sons involved).
  • Data sub­jects: Users (e.g., web­site vis­i­tors, users of online ser­vices).
  • Pur­pos­es of pro­cess­ing and legit­i­mate inter­ests: Reach mea­sure­ment (e.g., access sta­tis­tics, iden­ti­fi­ca­tion of return­ing vis­i­tors); pro­files with user-relat­ed infor­ma­tion (cre­ation of user pro­files); track­ing (e.g., inter­est/be­hav­ior-based pro­fil­ing, use of cook­ies); pro­vi­sion of our online offer­ing and user-friend­li­ness.
  • Reten­tion and dele­tion: Dele­tion in accor­dance with the infor­ma­tion pro­vid­ed in the sec­tion "Gen­er­al Infor­ma­tion on Data Stor­age and Dele­tion." Stor­age of cook­ies for up to 2 years (unless oth­er­wise stat­ed, cook­ies and sim­i­lar stor­age meth­ods may be stored on users' devices for a peri­od of two years).
  • Secu­ri­ty mea­sures: IP mask­ing (pseu­do­nymiza­tion of the IP address).
  • Legal bases: Con­sent (Art. 6(1)(a) GDPR); legit­i­mate inter­ests (Art. 6(1)(f) GDPR).

Fur­ther infor­ma­tion on pro­cess­ing oper­a­tions, pro­ce­dures, and ser­vices:

  • Burst Sta­tis­tics: Ser­vice provider: oper­at­ed on servers and/or com­put­ers under our own data pro­tec­tion respon­si­bil­i­ty; legal bases: con­sent (Art. 6(1)(a) GDPR); web­site: https://de.wordpress.org/plugins/burst-statistics/.

Changes and Updates

We ask you to reg­u­lar­ly inform your­self about the con­tent of our pri­va­cy pol­i­cy. We adapt the pri­va­cy pol­i­cy as soon as changes to the data pro­cess­ing car­ried out by us make this nec­es­sary. We will inform you as soon as the changes require an act of par­tic­i­pa­tion on your part (e.g., con­sent) or oth­er indi­vid­ual noti­fi­ca­tion.

Where we pro­vide address­es and con­tact infor­ma­tion of com­pa­nies and orga­ni­za­tions in this pri­va­cy pol­i­cy, please note that address­es may change over time, and please ver­i­fy the infor­ma­tion before con­tact­ing them.

Definitions

This sec­tion pro­vides an overview of the terms used in this pri­va­cy pol­i­cy. Where terms are legal­ly defined, their legal def­i­n­i­tions apply. The fol­low­ing expla­na­tions are intend­ed pri­mar­i­ly to aid under­stand­ing.

  • Employ­ees: Employ­ees are per­sons who are in an employ­ment rela­tion­ship, whether as staff, salaried employ­ees, or in sim­i­lar posi­tions. An employ­ment rela­tion­ship is a legal rela­tion­ship between an employ­er and an employ­ee that is estab­lished by an employ­ment con­tract or agree­ment. It includes the employ­er's oblig­a­tion to pay the employ­ee remu­ner­a­tion, while the employ­ee pro­vides their work per­for­mance. The employ­ment rela­tion­ship encom­pass­es var­i­ous phas­es, includ­ing its estab­lish­ment (when the employ­ment con­tract is con­clud­ed), its exe­cu­tion (when the employ­ee car­ries out their work), and its ter­mi­na­tion (when the employ­ment rela­tion­ship ends, whether through dis­missal, ter­mi­na­tion agree­ment, or oth­er­wise). Employ­ee data refers to all infor­ma­tion relat­ing to these per­sons in the con­text of their employ­ment. This includes aspects such as per­son­al iden­ti­fi­ca­tion data, iden­ti­fi­ca­tion num­bers, salary and bank data, work­ing hours, leave enti­tle­ments, health data, and per­for­mance eval­u­a­tions.
  • Mas­ter data: Mas­ter data encom­pass­es essen­tial infor­ma­tion nec­es­sary for the iden­ti­fi­ca­tion and man­age­ment of con­trac­tu­al part­ners, user accounts, pro­files, and sim­i­lar assign­ments. This data may include per­son­al and demo­graph­ic infor­ma­tion such as names, con­tact infor­ma­tion (address­es, tele­phone num­bers, email address­es), dates of birth, and spe­cif­ic iden­ti­fiers (user IDs). Mas­ter data forms the basis for any for­mal inter­ac­tion between per­sons and ser­vices, insti­tu­tions, or sys­tems by enabling unam­bigu­ous iden­ti­fi­ca­tion and com­mu­ni­ca­tion.
  • Con­tent data: Con­tent data encom­pass­es infor­ma­tion gen­er­at­ed in the course of cre­at­ing, edit­ing, and pub­lish­ing con­tent of all types. This cat­e­go­ry of data may include texts, images, videos, audio files, and oth­er mul­ti­me­dia con­tent pub­lished on var­i­ous plat­forms and media. Con­tent data is not lim­it­ed to the actu­al con­tent but also includes meta­da­ta that pro­vides infor­ma­tion about the con­tent itself, such as tags, descrip­tions, author infor­ma­tion, and pub­li­ca­tion dates.
  • Con­tact data: Con­tact data is essen­tial infor­ma­tion that enables com­mu­ni­ca­tion with per­sons or orga­ni­za­tions. It includes tele­phone num­bers, postal address­es, and email address­es, as well as com­mu­ni­ca­tion tools such as social media han­dles and instant mes­sag­ing iden­ti­fiers.
  • Meta, com­mu­ni­ca­tion, and pro­ce­dur­al data: Meta, com­mu­ni­ca­tion, and pro­ce­dur­al data are cat­e­gories that con­tain infor­ma­tion about the man­ner in which data is processed, trans­mit­ted, and man­aged. Meta­da­ta, also known as data about data, includes infor­ma­tion that describes the con­text, ori­gin, and struc­ture of oth­er data. It may include infor­ma­tion on file size, cre­ation date, doc­u­ment author, and change his­to­ries. Com­mu­ni­ca­tion data records the exchange of infor­ma­tion between users through var­i­ous chan­nels, such as email traf­fic, call logs, mes­sages on social net­works, and chat his­to­ries, includ­ing the per­sons involved, time­stamps, and trans­mis­sion paths. Pro­ce­dur­al data describes the process­es and work­flows with­in sys­tems or orga­ni­za­tions, includ­ing work­flow doc­u­men­ta­tion, trans­ac­tion and activ­i­ty logs, and audit logs used for track­ing and ver­i­fy­ing oper­a­tions.
  • Usage data: Usage data refers to infor­ma­tion that cap­tures how users inter­act with dig­i­tal prod­ucts, ser­vices, or plat­forms. This data encom­pass­es a broad range of infor­ma­tion that shows how users use appli­ca­tions, which fea­tures they pre­fer, how long they spend on cer­tain pages, and the paths through which they nav­i­gate an appli­ca­tion. Usage data may also include fre­quen­cy of use, time­stamps of activ­i­ties, IP address­es, device infor­ma­tion, and loca­tion data. It is par­tic­u­lar­ly valu­able for ana­lyz­ing user behav­ior, opti­miz­ing user expe­ri­ences, per­son­al­iz­ing con­tent, and improv­ing prod­ucts or ser­vices. Fur­ther­more, usage data plays a crit­i­cal role in iden­ti­fy­ing trends, pref­er­ences, and poten­tial prob­lem areas with­in dig­i­tal offer­ings.
  • Per­son­al data: "Per­son­al data" means any infor­ma­tion relat­ing to an iden­ti­fied or iden­ti­fi­able nat­ur­al per­son (here­inafter "data sub­ject"); an iden­ti­fi­able nat­ur­al per­son is one who can be iden­ti­fied, direct­ly or indi­rect­ly, in par­tic­u­lar by ref­er­ence to an iden­ti­fi­er such as a name, an iden­ti­fi­ca­tion num­ber, loca­tion data, an online iden­ti­fi­er (e.g., cook­ie), or to one or more fac­tors spe­cif­ic to the phys­i­cal, phys­i­o­log­i­cal, genet­ic, men­tal, eco­nom­ic, cul­tur­al, or social iden­ti­ty of that nat­ur­al per­son.
  • Pro­files with user-relat­ed infor­ma­tion: The pro­cess­ing of "pro­files with user-relat­ed infor­ma­tion," or "pro­files" for short, encom­pass­es any form of auto­mat­ed pro­cess­ing of per­son­al data that con­sists of using such per­son­al data to eval­u­ate cer­tain per­son­al aspects relat­ing to a nat­ur­al per­son (depend­ing on the type of pro­fil­ing, this may include var­i­ous infor­ma­tion con­cern­ing demo­graph­ics, behav­ior, and inter­ests, such as inter­ac­tion with web­sites and their con­tent, etc.), to ana­lyze or pre­dict them (e.g., inter­ests in cer­tain con­tent or prod­ucts, click behav­ior on a web­site, or loca­tion). Cook­ies and web bea­cons are fre­quent­ly used for pro­fil­ing pur­pos­es.
  • Log data: Log data is infor­ma­tion about events or activ­i­ties that have been logged in a sys­tem or net­work. This data typ­i­cal­ly con­tains infor­ma­tion such as time­stamps, IP address­es, user actions, error mes­sages, and oth­er details about the use or oper­a­tion of a sys­tem. Log data is often used for ana­lyz­ing sys­tem prob­lems, secu­ri­ty mon­i­tor­ing, or gen­er­at­ing per­for­mance reports.
  • Reach mea­sure­ment: Reach mea­sure­ment (also referred to as web ana­lyt­ics) serves to eval­u­ate vis­i­tor traf­fic to an online offer­ing and may encom­pass the behav­ior or inter­ests of vis­i­tors in cer­tain infor­ma­tion, such as web­site con­tent. With the help of reach analy­sis, oper­a­tors of online offer­ings can iden­ti­fy, for exam­ple, at what time users vis­it their web­sites and what con­tent they are inter­est­ed in. This enables them, for exam­ple, to bet­ter tai­lor web­site con­tent to the needs of their vis­i­tors. Pseu­do­ny­mous cook­ies and web bea­cons are fre­quent­ly used for reach analy­sis pur­pos­es to iden­ti­fy return­ing vis­i­tors and thus obtain more accu­rate analy­ses of the use of an online offer­ing.
  • Track­ing: "Track­ing" refers to the abil­i­ty to trace users' behav­ior across mul­ti­ple online offer­ings. As a rule, behav­ioral and inter­est infor­ma­tion is stored in cook­ies or on the servers of the track­ing tech­nol­o­gy providers (so-called pro­fil­ing) with regard to the online offer­ings used. This infor­ma­tion can then be used, for exam­ple, to dis­play adver­tise­ments to users that are like­ly to cor­re­spond to their inter­ests.
  • Con­troller: The "con­troller" is the nat­ur­al or legal per­son, pub­lic author­i­ty, agency, or oth­er body which, alone or joint­ly with oth­ers, deter­mines the pur­pos­es and means of the pro­cess­ing of per­son­al data.
  • Pro­cess­ing: "Pro­cess­ing" means any oper­a­tion or set of oper­a­tions per­formed on per­son­al data, whether or not by auto­mat­ed means. The term is broad and cov­ers vir­tu­al­ly any han­dling of data, whether col­lec­tion, eval­u­a­tion, stor­age, trans­mis­sion, or dele­tion.

Cre­at­ed with the free pri­va­cy pol­i­cy gen­er­a­tor at Datenschutz-Generator.de by Dr. Thomas Schwenkeomments may be checked through an auto­mat­ed spam detec­tion ser­vice.