Privacy Policy
Preamble
The following privacy policy is intended to inform you about the types of personal data (hereinafter also referred to as ‘data’) that we process, the purposes for which we do so, and the extent of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in the course of providing our services and, in particular, on our websites, in mobile applications and within external online platforms, such as our social media profiles (hereinafter collectively referred to as the “online offering”).
The terms used are not gender-specific.
Date: 13 September 2026
Table of Contents
- Preamble
- Data controller
- Overview of data processing
- Relevant legal bases
- Security measures
- International data transfers
- General information on data storage and deletion
- Rights of data subjects
- Provision of the online service and web hosting
- Use of cookies
- Blogs and publication media
- Contact and enquiry management
- Newsletters and electronic notifications
- Marketing communications via email, post, fax or telephone
- Web analytics, monitoring and optimisation
- Social media presence
- Plug-ins, embedded functions and content
- Audio content
- Amendments and updates
- Definitions of terms
Data controller
Joan Chandelíers
c/o IP-Management #9095
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany
Email address: social@norabellehart.com
Legal notice: https://norabellehart.com/legal-notice
Overview of data processing
The following overview summarises the types of data processed and the purposes of such processing, and identifies the data subjects.
Types of data processed
- Master data.
- Employee data.
- Contact data.
- Content data.
- Usage data.
- Meta, communication and procedural data.
- Event data (Facebook).
- Log data.
Categories of data subjects
- Service recipients and clients.
- Communication partners.
- Third parties.
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations.
- Security measures.
- Direct marketing.
- Audience measurement.
- Target audience segmentation.
- A/B testing.
- Organisational and administrative procedures.
- Profiles containing user-related information.
- Provision of our online services and user-friendliness.
- IT infrastructure.
- Whistleblower protection.
- Public relations.
- Sales promotion.
Relevant legal bases
Relevant legal bases under the GDPR: Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or ours, depending on where you or we are resident or have our registered office. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6(1), first sentence, point (a) of the GDPR) – The data subject has given their consent to the processing of their personal data for a specific purpose or for several specific purposes.
- Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR) – The processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
- Legal obligation (Article 6(1), first sentence, point (c) of the GDPR) – The processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR) – The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights and freedoms of the data subject which require the protection of personal data do not override those interests.
National data protection regulations in Germany: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (BDSG). The BDSG contains, in particular, specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply.
Security measures
In accordance with statutory requirements, and taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and safeguarding of the availability of the data, and its segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted, and that appropriate action is taken in the event of a data breach. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and through privacy-friendly default settings.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect users’ data transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transfers meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of ‘HTTPS’ in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
International data transfers
Data processing in third countries: Where we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in connection with the use of third-party services or the disclosure or transfer of data to other persons, organisations or companies (which can be identified by the postal address of the respective provider or if the privacy policy expressly refers to data transfers to third countries), this is always carried out in accordance with legal requirements.
For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the European Commission dated 10 July 2023. In addition, we have entered into standard contractual clauses with the relevant providers, which comply with the European Commission’s requirements and set out contractual obligations to protect your data.
This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary layer of protection, whilst the standard contractual clauses serve as an additional safeguard. Should any changes arise within the framework of the DPF, the standard contractual clauses act as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of any political or legal changes.
For each service provider, we will inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the US Department of Commerce’s website at https://www.dataprivacyframework.gov/ (in English).
Appropriate security measures apply to data transfers to other third countries, in particular standard contractual clauses, explicit consent or transfers required by law. Information on transfers to third countries and applicable adequacy decisions can be found on the European Commission’s website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
General information on data storage and erasure
We delete the personal data we process in accordance with statutory provisions as soon as the underlying consents are withdrawn or there are no longer any legal grounds for processing. This applies to cases where the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule apply where statutory obligations or specific interests require the data to be retained or archived for a longer period.
In particular, data that must be retained for commercial or tax law reasons, or where storage is necessary for the purposes of legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy policy contains additional information on the retention and erasure of data, which applies specifically to certain processing operations.
Where there are multiple specifications regarding the retention period or deletion deadlines for a particular piece of data, the longest period shall always apply. We process data that is no longer retained for its originally intended purpose, but rather due to legal requirements or other reasons, exclusively for the purposes that justify its retention.
Retention and deletion of data: The following general time limits apply to the retention and archiving of data under German law:
- 10 years – retention period for books and records, annual accounts, inventories, management reports, opening balance sheets, as well as the working instructions and other organisational documents necessary for their understanding (Section 147(1)(1) in conjunction with (3) of the German Fiscal Code (AO), Section 257(1)(1) in conjunction with (4) of the German Commercial Code (HGB)).
- 8 years – accounting documents, such as invoices and expense receipts (Section 147(1)(4) and (4a) in conjunction with (3), first sentence, of the German Fiscal Code (AO), Section 14b(1) of the German Value Added Tax Act (UStG) and Section 257(1)(4) in conjunction with (4) of the German Commercial Code (HGB)).
- 6 years – Other business records: commercial or business correspondence received, copies of commercial or business correspondence sent, other documents in so far as they are relevant for tax purposes, e.g. hourly pay slips, operational accounting sheets, costing documents, price labels, as well as payroll records, in so far as they are not already accounting vouchers, and cash register receipts (Section 147(1)(2), 3, 5 in conjunction with para. 3 of the German Fiscal Code (AO), Section 257(1)(2) and (3) in conjunction with para. 4 of the German Commercial Code (HGB)).
- 3 years – Data required to take into account potential warranty and compensation claims or similar contractual claims and rights, and to process related enquiries, based on previous business experience and standard industry practices, is retained for the duration of the standard statutory limitation period of three years (Sections 195, 199 of the German Civil Code (BGB)).
Commencement of the limitation period at the end of the year: If a limitation period does not expressly commence on a specific date and is at least one year in duration, it automatically commences at the end of the calendar year in which the event triggering the limitation period occurred. In the case of ongoing contractual relationships in which data is stored, the event triggering the limitation period is the date on which the termination or other cessation of the legal relationship takes effect.
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. Where personal data relating to you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data relating to you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to this data, as well as further information and a copy of the data in accordance with the statutory requirements.
- Right to rectification: In accordance with the statutory provisions, you have the right to request that data relating to you be completed or that any inaccurate data relating to you be rectified.
- Right to erasure and restriction of processing: In accordance with the statutory provisions, you have the right to request that data relating to you be erased without delay or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of the data.
- Right to data portability: You have the right, in accordance with the statutory provisions, to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another data controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. In particular, you may lodge a complaint with a supervisory authority in the Member State of your habitual residence, your place of work or the place where the alleged infringement occurred.
Provision of the online service and web hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.
- Types of data processed: usage data (e.g. page views and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved); Log data (e.g. log files relating to logins, data retrieval or access times); content data (e.g. textual or visual messages and posts, as well as related information such as details of authorship or the time of creation).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
- Retention and erasure: Erasure in accordance with the details set out in the section ‘General information on data storage and erasure’.
- Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Provision of the online service on rented storage space: To provide our online service, we use storage space, computing capacity and software which we rent or otherwise obtain from a relevant server provider (also known as a ‘web host’); legal basis: legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- Collection of access data and log files: Access to our online service is logged in the form of so-called ‘server log files’. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, confirmation of successful access, browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g. to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks), and, on the other hand, to ensure server capacity utilisation and stability; legal basis: legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and is then deleted or anonymised. Data that must be retained for evidential purposes is exempt from deletion until the relevant incident has been fully resolved.
- Email transmission and hosting: The web hosting services we use also include the sending, receiving and storage of emails. For these purposes, the addresses of the recipients and senders, as well as further information relating to email transmission (e.g. the providers involved) and the content of the respective emails, are processed. The aforementioned data may also be processed for the purpose of detecting spam. Please note that emails are generally not sent in encrypted form over the internet. Whilst emails are usually encrypted whilst in transit, they are not encrypted on the servers from which they are sent and received (unless a so-called end-to-end encryption method is used). We are therefore unable to accept any responsibility for the transmission of emails between the sender and our server; legal basis: legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- STRATO: Services relating to the provision of IT infrastructure and associated services (e.g. storage space and/or computing capacity); Service provider: STRATO AG, Pascalstraße 10, 10587 Berlin, Germany; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://www.strato.de ; Privacy policy: https://www.strato.de/datenschutz/ . Data processing agreement: Provided by the service provider.
- com: Hosting and software for the creation, deployment and operation of websites, blogs and other online services; Service provider: Aut O’Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://wordpress.com ; Privacy Policy: https://automattic.com/de/privacy/ ; Data Processing Agreement: https://wordpress.com/support/data-processing-agreements/ . Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (provided by the service provider).
Use of cookies
The term ‘cookies’ refers to functions that store and retrieve information on users’ devices. Cookies may also be used for various purposes, such as ensuring the functionality, security and convenience of online services, as well as analysing visitor traffic. We use cookies in accordance with legal requirements. To this end, we obtain users’ consent in advance where necessary. Where consent is not required, we rely on our legitimate interests. This applies where the storage and retrieval of information is essential to provide explicitly requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online service. Consent may be withdrawn at any time. We provide clear information on the scope of this and which cookies are used.
Information on the legal basis for data protection: Whether we process personal data using cookies depends on consent. Where consent has been given, this serves as the legal basis. Where consent has not been given, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Retention period: With regard to the retention period, a distinction is made between the following types of cookies:
- Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once a user has left an online service and closed their device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the device has been closed. This allows, for example, the login status to be saved and preferred content to be displayed directly when the user visits a website again. Similarly, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage duration of cookies (e.g. when seeking consent), they should assume that these are permanent and that the storage period may be up to two years.
General information on withdrawal of consent and opting out: Users may withdraw the consent they have given at any time and may also object to the processing of their data in accordance with legal requirements, including via their browser’s privacy settings.
Cookie settings/opt-out options:
- Types of data processed: Meta data, communication data and procedural data (e.g. IP addresses, time stamps, identification numbers, individuals involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Consent (Article 6(1), first sentence, point (a) of the GDPR).
Further information on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: We use a consent management solution through which users’ consent is obtained for the use of cookies or for the procedures and providers specified within the scope of the consent management solution. This procedure serves to obtain, log, manage and revoke consents, in particular with regard to the use of cookies and similar technologies employed to store, read and process information on users’ end devices. As part of this procedure, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers mentioned in the consent management procedure. Users also have the option to manage and withdraw their consents. The declarations of consent are stored to avoid having to request them again and to be able to provide evidence of consent in accordance with legal requirements. Storage takes place on the server and/or in a cookie (a so-called ‘opt-in’ cookie) or by means of comparable technologies, in order to be able to associate the consent with a specific user or their device. In the absence of specific details regarding the providers of consent management services, the following general information applies: Consent is stored for up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, details of the scope of consent (e.g. relevant categories of cookies and/or service providers) and information about the browser, the system and the end device used; legal basis: consent (Article 6(1), first sentence, point (a) of the GDPR).
Blogs and publication media
We use blogs or similar means of online communication and publication (hereinafter referred to as the “publication medium”). Readers’ data is processed for the purposes of the publication medium only to the extent necessary for its presentation and for communication between authors and readers, or for security reasons. For all other matters, please refer to the information regarding the processing of visitors to our publication medium set out in this privacy policy.
- Types of data processed: Personal details (e. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Feedback (e. collecting feedback via an online form); provision of our online services and user-friendliness; security measures; organisational and administrative procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Comments and posts: When users leave comments or other posts, their IP addresses may be stored on the basis of our legitimate interests. This is done for our own security in the event that someone posts unlawful content in comments or posts (insults, prohibited political propaganda, etc.). In such cases, we ourselves may be held liable for the comment or post and are therefore interested in the author’s identity.Furthermore, we reserve the right to process users’ data for the purpose of spam detection on the basis of our legitimate interests.On the same legal basis, we reserve the right, in the case of surveys, to store users’ IP addresses for the duration of the survey and to use cookies to prevent multiple votes.
The personal information provided in comments and posts, any contact and website details, as well as the content itself, will be stored by us on a permanent basis until the user objects; legal basis: legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- Retrieval of WordPress emojis and smileys: Retrieval of WordPress emojis and smileys – Within our WordPress blog, graphical emojis (or smileys) – i.e. small graphic files that express emotions – are used for the purpose of efficiently integrating content elements; these are retrieved from external servers. The server providers collect users’ IP addresses. This is necessary so that the emoji files can be transmitted to users’ browsers; service provider: Aut O’Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://automattic.com ; Privacy policy: https://automattic.com/privacy ; Data processing agreement: Provided by the service provider. Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (provided by the service provider).
- Gravatar profile pictures: Profile pictures – We use the Gravatar service within our online offering and, in particular, on our blog.Gravatar is a service where users can register and store profile pictures and their email addresses. When users post articles or comments on other websites (particularly blogs) using their email address, their profile pictures may be displayed alongside the posts or comments. To this end, the email address provided by users is transmitted to Gravatar in encrypted form to check whether a profile is stored for that address. This is the sole purpose of transmitting the email address. It is not used for any other purposes and is deleted afterwards.The use of Gravatar is based on our legitimate interests, as we use Gravatar to offer authors of posts and comments the opportunity to personalise their posts with a profile picture.
By displaying the images, Gravatar obtains the users’ IP addresses, as this is necessary for communication between a browser and an online service.
If users do not wish a profile picture linked to their email address on Gravatar to appear in the comments, they should use an email address that is not registered with Gravatar when commenting. We would also like to point out that it is possible to use an anonymous email address or no email address at all if users do not wish their own email address to be sent to Gravatar. Users can prevent the transfer of data entirely by not using our commenting system; Service provider: Aut O’Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://automattic.com ; Privacy policy: https://automattic.com/privacy ; Data processing agreement: Provided by the service provider. Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (provided by the service provider).
Contact and enquiry management
When you contact us (e.g. by post, via the contact form, by email, by telephone or via social media), and in the context of existing user and business relationships, the details provided by the enquirers are processed to the extent necessary to respond to enquiries and carry out any requested actions.
- Types of data processed: contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online services and user-friendliness.
- Retention and erasure: Erasure in accordance with the information in the section ‘General information on data storage and erasure’.
- Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).
Further information on processing operations, procedures and services:
- Contact form: When you contact us via our contact form, by email or through other communication channels, we process the personal data provided to us in order to respond to and handle the relevant enquiry. This generally includes details such as your name, contact details and, where applicable, any further information provided to us that is necessary for the appropriate handling of your enquiry. We use this data exclusively for the stated purpose of establishing contact and communication; legal bases: performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Newsletters and electronic notifications
We send out newsletters, emails and other electronic notifications (hereinafter ‘newsletters’) exclusively with the consent of the recipients or on a legal basis. Where the content of the newsletter is specified as part of the subscription process, this content is decisive for the user’s consent. To subscribe to our newsletter, providing your email address is normally sufficient. However, in order to offer you a personalised service, we may ask you to provide your name so that we can address you personally in the newsletter, or to provide further information if this is necessary for the purpose of the newsletter.
Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to provide evidence of consent previously given. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for erasure may be made at any time, provided that the prior existence of consent is confirmed at the same time. In the event of obligations to permanently comply with objections, we reserve the right to store the email address solely for this purpose in a block list.
The logging of the registration process is carried out on the basis of our legitimate interests for the purpose of verifying that it has been carried out correctly. Where we engage a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure delivery system.
Content:
Information about us, our services, promotions and offers.
- Types of data processed: Master data (e. full name, home address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved). Usage data (e.g. page views and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions).
- Data subjects: Communication partners. Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Direct marketing (e.g. by email or post). Provision of contractual services and fulfilment of contractual obligations.
- Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR).
- Right to object (opt-out): You may unsubscribe from our newsletter at any time, i.e. withdraw your consent or object to receiving further issues. You will find a link to unsubscribe from the newsletter either at the end of each newsletter or you may use one of the contact options listed above, preferably by email.
Further information on processing operations, procedures and services:
- Measurement of open and click rates: The newsletters contain so-called “web beacons,” i.e., a pixel-sized file that is retrieved from our server or that of the newsletter provider—if we use a mailing service provider—when you open the newsletter. As part of this retrieval, technical information—such as details about your browser and system—as well as your IP address and the time of retrieval are initially collected. This information is used to technically improve our newsletter based on technical data or the target groups and their reading behavior, determined by their access locations (which can be identified using the IP address) or access times. This analysis also includes determining whether the newsletters are opened, when they are opened, and which links are clicked. This information is assigned to individual newsletter recipients and stored in their profiles until they are deleted . The analyses help us identify our users’ reading habits and tailor our content to them, or send different content based on our users’ interests. The measurement of open rates and click-through rates, as well as the storage of measurement results in user profiles and their further processing, are based on the users’ consent. Unfortunately, it is not possible to revoke consent for performance measurement separately; in this case, the entire newsletter subscription must be canceled or you must object to it. In this case, the stored profile information will be deleted; Legal basis: Consent (Art. 6(1)(a) GDPR).
- Condition for using free services: Consent to receive mailings may be made a condition for using free services (e.g. access to certain content or participation in certain promotions). If users wish to use the free service without subscribing to the newsletter, please contact us.
Marketing communications via email, post, fax or telephone
We process personal data for the purposes of marketing communications, which may be carried out via various channels, such as email, telephone, post or fax, in accordance with legal requirements.
Recipients have the right to withdraw their consent at any time or to object to promotional communications at any time, free of charge, via the contact details provided above.
Following revocation or objection, we will retain the data necessary to prove the previous legitimacy of contacting you or sending you communications for up to three years after the end of the year in which the revocation or objection took place, on the basis of our legitimate interests. The processing of this data is limited to the purpose of potentially defending against claims. On the basis of the legitimate interest in permanently complying with users’ withdrawals or objections, we also store the data necessary to prevent further contact (e.g. depending on the communication channel, the email address, telephone number or name).
- Types of data processed: Master data (e. full name, home address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Direct marketing (e.g. by email or post); marketing; sales promotion.
- Retention and erasure: Erasure in accordance with the details set out in the section ‘General information on data storage and erasure’.
- Legal bases: Consent (Article 6(1), first sentence, point (a) of the GDPR). Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Web analytics, monitoring and optimisation
Web analytics (also referred to as ‘reach measurement’) serves to analyse visitor traffic to our online offering and may include pseudonymised data on visitors’ behaviour, interests or demographic information, such as age or gender. With the help of reach analysis, we can, for example, identify at what times our online offering or its functions and content are used most frequently, or encourage repeat visits. It also enables us to identify which areas require optimisation.
In addition to web analytics, we may also use testing procedures to, for example, test and optimise different versions of our online service or its components.
Unless otherwise stated below, profiles – that is, data aggregated to a specific usage session – may be created for these purposes, and information may be stored in a browser or on a device and subsequently retrieved. The data collected includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used and details of usage times. Where users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.
In addition, users’ IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation by truncating the IP address) to protect users. Generally, no personally identifiable data of users (such as email addresses or names) is stored in the context of web analytics, A/B testing and optimisation; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.
Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Audience measurement (e.g. access statistics, identification of returning visitors); profiles containing user-related information (creation of user profiles); A/B testing; feedback (e.g. collection of feedback via online forms). Heatmaps (users’ mouse movements, which are aggregated to form an overall picture).
- Retention and deletion: Deletion in accordance with the information provided in the section ‘General information on data storage and deletion’. Cookies may be stored for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal basis: Consent (Article 6(1)(a) of the GDPR). Legitimate interests (Article 6(1)(f) of the GDPR).
Further information on processing operations, procedures and services:
- Visual Website Optimizer: Visual Website Optimizer – testing and optimisation; service provider: Wingify Software Private Limited, 404, Gopal Heights, Netaji Subhash Place, Pitam Pura, Delhi 110034, India; legal basis: consent (Article 6(1), first sentence, point (a) of the GDPR); Website: https://vwo.com . Privacy policy: https://vwo.com/privacy-policy/ .
Social media presence
We maintain online presences on social media platforms and, in this context, process user data in order to communicate with users active on these platforms or to provide information about us.
Please note that user data may be processed outside the European Union in this context. This may entail risks for users, as it could, for example, make it more difficult to enforce their rights.
Furthermore, users’ data within social media platforms is generally processed for market research and advertising purposes. For example, usage profiles may be created based on users’ behaviour and the resulting interests. These profiles may in turn be used, for instance, to display advertisements within and outside the platforms that are presumed to correspond to users’ interests. Consequently, cookies are usually stored on users’ computers, in which their usage behaviour and interests are recorded. In addition, data may also be stored in these user profiles regardless of the devices used by the users (particularly if they are members of the respective platforms and are logged in there).
For a detailed description of the respective forms of processing and the options for objecting (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.
We would also like to point out that, in the case of requests for information and the exercise of data subjects’ rights, these can most effectively be exercised with the providers themselves. Only the providers have access to the user data and can take appropriate action and provide information directly. Should you nevertheless require assistance, please do not hesitate to contact us.
- Types of data processed: contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Master data (e.g. full name, residential address, contact details, customer number, etc.). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: communication; feedback (e.g. collecting feedback via online forms); public relations; provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)).
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Instagram: social network enabling the sharing of photos and videos, commenting on and favouriting posts, sending messages, and following profiles and pages; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://www.instagram.com ; Privacy policy: https://privacycenter.instagram.com/policy/ . Basis for transfers to third countries: Data Privacy Framework (DPF).
- Facebook Pages: Profiles within the Facebook social network – The data controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data relating to visitors to our Facebook page (‘fan page’). This includes, in particular, information on user behaviour (e.g. content viewed or interacted with, actions taken) as well as device information (e.g. IP address, operating system, browser type, language settings, cookie data). Further details can be found in Facebook’s Data Policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us, via the ‘Page Insights’ service, with statistical analyses that provide information on how people interact with our page and its content. This is based on an agreement with Facebook (‘Information on Page Insights’: https://www.facebook.com/legal/terms/page_controller_addendum ), which, amongst other things, sets out security measures and the exercise of data subjects’ rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data. Users may therefore submit requests for access or erasure directly to Facebook. Users’ rights (in particular the right of access, erasure, objection and the right to lodge a complaint with a supervisory authority) remain unaffected by this. Joint controllership is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for any further processing, including any possible transfer to Meta Platforms Inc. in the USA; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal basis: legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); website: https://www.facebook.com ; Privacy policy: https://www.facebook.com/privacy/policy/ . Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses ( https://www.facebook.com/legal/EU_data_transfer_addendum ).
- Pinterest: social network enabling users to share photos, comment on, favourite and curate posts, send messages and follow profiles; service provider: Pinterest Europe Limited, 2nd Floor, Palmerston House, Fenian Street, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.pinterest.com . Privacy policy: https://policy.pinterest.com/de/privacy-policy .
- Threads: social network; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.threads.com/ . Privacy policy: https://help.instagram.com/515230437301944 .
- YouTube: Social network and video platform; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: legitimate interests (Article 6(1)(f) of the GDPR); privacy policy: https://business.safety.google/privacy/ ; basis for transfers to third countries: Data Privacy Framework (DPF). Right to object (opt-out): https://myadcenter.google.com/ .
Plug-ins, embedded functions and content
We incorporate functional and content elements into our online offering that are sourced from the servers of their respective providers (hereinafter referred to as ‘third-party providers’). These may include, for example, graphics, videos or city maps (hereinafter collectively referred to as ‘content’).
This integration always requires the third-party providers of this content to process the user’s IP address, as they would be unable to send the content to the user’s browser without it. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only such content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as ‘web beacons’) for statistical or marketing purposes. These ‘pixel tags’ enable information, such as visitor traffic on the pages of this website, to be analysed. This pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical details regarding the browser and operating system, referring websites, the time of visit and further details on the use of our online service; it may also be linked to such information from other sources.
Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is that consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved). Event data (Facebook) (‘Event data’ refers to information sent to the provider Meta – for example, via Meta pixels (whether via apps or other channels) – which relates to individuals or their actions. This data includes, for example, details of website visits, interactions with content and features, app installations and product purchases. Event data is processed for the purpose of creating target audiences for content and advertising messages (Custom Audiences). It is important to note that event data does not include actual content such as comments posted, login details, or contact information such as names, email addresses or telephone numbers. “Event data” is deleted by Meta after a maximum of two years, and the target audiences created from it are deleted when our Meta user accounts are deleted.
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; audience measurement (e.g. access statistics, identification of returning visitors); tracking (e.g. interest-based/behavioural profiling, use of cookies); target group analysis; marketing. Profiles containing user-related information (creation of user profiles).
- Retention and deletion: Deletion in accordance with the information in the section ‘General information on data storage and deletion’. Storage of cookies for up to 2 years (Unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
- Legal bases: Consent (Article 6(1), first sentence, point (a) of the GDPR). Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Facebook plugins and content: Facebook social plugins and content – these may include, for example, content such as images, videos or text, as well as buttons that allow users to share content from this website on Facebook. The list and appearance of the Facebook social plugins can be viewed here: https://developers.facebook.com/documentation/plugins – We are jointly responsible with Meta Platforms Ireland Limited for the collection or receipt, as part of a transfer (but not the further processing), of ‘event data’ which Facebook collects via the Facebook social plugins (and content embedding features) running on our online service, or which it receives as part of a transfer, for the following purposes: a) Displaying content and advertising information that corresponds to users’ presumed interests; b) Delivering commercial and transaction-related messages (e.g. contacting users via Facebook Messenger); c) Improving ad delivery and the personalisation of features and content (e.g. improving the identification of which content or advertising information is likely to correspond to users’ interests). We have entered into a specific agreement with Facebook (‘Addendum for Data Controllers’, https://www.facebook.com/legal/controller_addendum ), which specifically sets out the security measures Facebook must observe ( https://www.facebook.com/legal/terms/data_security_terms ) and in which Facebook has agreed to fulfil data subjects’ rights (i.e. users may, for example, submit requests for information or erasure directly to Facebook). Note: Where Facebook provides us with metrics, analyses and reports (which are aggregated, i.e. do not contain any information on individual users and are anonymous to us), this processing does not take place within the framework of joint controllership, but on the basis of a data processing agreement (“Data Processing Terms”, https://www.facebook.com/legal/terms/dataprocessing), the “Data Security Terms” ( https://www.facebook.com/legal/terms/data_security_terms ) and, with regard to processing in the USA, on the basis of standard contractual clauses (“Facebook-EU Data Transfer Addendum”,https://www.facebook.com/legal/EU_data_transfer_addendum ). Users’ rights (in particular the right to access, erasure, objection and to lodge a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Consent (Article 6(1)(a) of the GDPR); Website: https://www.facebook.com ; Privacy policy: https://www.facebook.com/privacy/policy/ . Basis for transfers to third countries: Data Privacy Framework (DPF).
- Google Fonts (retrieved from the Google server): Retrieval of fonts (and icons) for the purpose of ensuring the technically secure, maintenance-free and efficient use of fonts and icons, taking into account their up-to-date status and loading times, their consistent display and compliance with any licence restrictions. The font provider is provided with the user’s IP address so that the fonts can be made available in the user’s browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) is transmitted, which is necessary for the provision of the fonts depending on the devices used and the technical environment. This data may be processed on a server belonging to the font provider in the USA – when visiting our website, users’ browsers send HTTP requests to the Google Fonts Web API (i.e. a software interface for retrieving the fonts). The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) from Google Fonts and, subsequently, the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the internet, (2) the requested URL on the Google server, and (3) the HTTP headers, including the User-Agent, which describes the browser and operating system versions of website visitors, as well as the referrer URL (i.e. the web page on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers, and they are not analysed. The Google Fonts Web API logs details of the HTTP requests (requested URL, user-agent and referrer URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wishes to load fonts. This data is logged so that Google can determine how often a particular font family is requested. With the Google Fonts Web API, the user-agent must match the font generated for the respective browser type. The user-agent is primarily logged for debugging purposes and used to generate aggregated usage statistics that measure the popularity of font families. These aggregated usage statistics are published on the ‘Analytics’ page of Google Fonts. Finally, the referrer URL is logged so that the data can be used for production maintenance and to generate an aggregated report on the top integrations based on the number of font requests. According to Google’s own information, Google does not use any of the information collected by Google Fonts to create profiles of end users or to serve targeted adverts; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal basis: legitimate interests (Article 6(1)(f) of the GDPR); Website: https://fonts.google.com/ ; Privacy policy: https://business.safety.google/privacy/ ; Basis for transfers to third countries: Data Privacy Framework (DPF). Further information: https://fonts.google.com/faq?hl=de#privacy .
- Instagram plugins and content: Instagram plugins and content – this may include, for example, content such as images, videos or text, as well as buttons that allow users to share content from this online service within Instagram. – We are jointly responsible with Meta Platforms Ireland Limited for the collection or receipt, as part of a transfer (but not the subsequent processing), of ‘event data’ which Facebook collects via Instagram features (e.g. content embedding features) running on our online service, or which it receives as part of a transfer, for the following purposes: a) Displaying content and advertising information that corresponds to users’ presumed interests; b) Delivering commercial and transaction-related messages (e.g. contacting users via Facebook Messenger); c) Improving ad delivery and personalising features and content (e.g. improving the identification of which content or advertising information is likely to correspond to users’ interests). We have entered into a specific agreement with Facebook (“Addendum for Data Controllers”, https://www.facebook.com/legal/controller_addendum ), which specifically sets out the security measures Facebook must observe ( https://www.facebook.com/legal/terms/data_security_terms ) and in which Facebook has agreed to fulfil data subjects’ rights (i.e. users may, for example, submit requests for information or erasure directly to Facebook). Note: Where Facebook provides us with metrics, analyses and reports (which are aggregated, i.e. do not contain any information on individual users and are anonymous to us), this processing does not take place within the framework of joint controllership, but on the basis of a data processing agreement (“Data Processing Terms”, https://www.facebook.com/legal/terms/dataprocessing), the “Data Security Terms” ( https://www.facebook.com/legal/terms/data_security_terms ) and, with regard to processing in the USA, on the basis of standard contractual clauses (“Facebook-EU Data Transfer Addendum”,https://www.facebook.com/legal/EU_data_transfer_addendum ). Users’ rights (in particular the right to access, erasure, objection and to lodge a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://www.instagram.com . Privacy policy: https://privacycenter.instagram.com/policy/ .
- Pinterest plugins and content: Pinterest plugins and content – this may include, for example, content such as images, videos or text, as well as buttons that allow users to share content from this website on Pinterest; Service provider: Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.pinterest.com . Privacy policy: https://policy.pinterest.com/de/privacy-policy .
- YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR); Website: https://www.youtube.com ; Privacy policy: https://business.safety.google/privacy/ ; Basis for transfers to third countries: Data Privacy Framework (DPF). Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de ; settings for the display of adverts: https://myadcenter.google.com/personalizationoff .
Audio Content
We use hosting services provided by third-party providers to make our audio content available for listening and downloading. To do so, we use platforms that enable the uploading, storage, and distribution of audio material.
- Types of data processed: Usage data (e.g., page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features); meta, communication, and procedural data (e.g., IP addresses, time stamps, identification numbers, individuals involved); Log data (e.g., log files regarding logins, data retrieval, or access times).
- Data subjects: Users (e.g., website visitors, users of online services).
- Purposes of processing and legitimate interests: Audience measurement (e.g., access statistics, identification of returning visitors); conversion measurement (measuring the effectiveness of marketing measures); profiles containing user-related information (creation of user profiles); provision of our online services and user-friendliness.
- Retention and Deletion: Deletion in accordance with the information provided in the section “General Information on Data Storage and Deletion.”
- Legal Bases: Legitimate interests (Art. 6(1), sentence 1, lit. f) GDPR).
Additional Information on Processing Activities, Procedures, and Services:
SoundCloud: SoundCloud—music hosting; Service provider: SoundCloud Limited, Rheinsberger Str. 76/77, 10115 Berlin, Germany; Legal basis: Legitimate interests (Art. 6(1), first sentence, lit. f) GDPR); Website: https://soundcloud.com; Privacy Policy: https://soundcloud.com/pages/privacy.
Changes and updates
We ask that you check the content of our privacy policy regularly. We will amend the privacy policy as soon as changes to the data processing activities we carry out make this necessary. We will inform you as soon as the changes require action on your part (e.g. consent) or any other individual notification.
Where we provide addresses and contact details for companies and organisations in this privacy policy, please note that these details may change over time; we therefore ask you to check the information before making contact.
Definitions of Terms
This section provides an overview of the terms used in this privacy policy. Where terms are defined by law, their statutory definitions apply. The explanations below, however, are primarily intended to aid understanding.
- A/B testing: A/B testing is used to improve the user-friendliness and performance of online services. In this process, users are shown, for example, different versions of a website or its elements – such as input forms – in which the placement of content or the labels of navigation elements may differ. Subsequently, based on user behaviour – such as spending more time on the website or interacting more frequently with the elements – it can be determined which of these web pages or elements better meet users’ needs.
- Employees: The term ‘employees’ refers to individuals who are in an employment relationship, whether as staff members, employees or in similar roles. An employment relationship is a legal relationship between an employer and an employee, established by an employment contract or agreement. It entails the employer’s obligation to pay the employee remuneration whilst the employee performs their work. The employment relationship comprises various phases, including the commencement phase, during which the employment contract is concluded; the performance phase, during which the employee carries out their work; and the termination phase, when the employment relationship ends, whether through dismissal, a termination agreement or otherwise. Employee data refers to all information relating to these individuals and arising in the context of their employment. This includes aspects such as personal identification details, identification numbers, salary and bank details, working hours, holiday entitlements, health data and performance appraisals.
- Master data: Master data comprises essential information required for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include, amongst other things, personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for any formal interaction between individuals and services, organisations or systems by enabling unique identification and communication.
- Heatmaps: ‘Heatmaps’ are users’ mouse movements aggregated into an overall picture, which can be used, for example, to identify which website elements are most frequently visited and which are less favoured by users.
- Content data: Content data comprises information generated in the course of creating, editing and publishing content of all kinds. This category of data may include text, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content itself, but also includes metadata that provides information about the content, such as tags, descriptions, author details and publication dates.
- Contact details: Contact details are essential information that enables communication with individuals or organisations. They include, amongst other things, telephone numbers, postal addresses and email addresses, as well as communication channels such as social media handles and instant messaging identifiers.
- Meta, communication and procedural data: Meta, communication and procedural data are categories that contain information about the way in which data is processed, transmitted and managed. Meta-data, also known as ‘data about data’, comprises information that describes the context, origin and structure of other data. It may include details on file size, creation date, the author of a document and revision histories. Communication data records the exchange of information between users via various channels, such as email correspondence, call logs, social media messages and chat histories, including the individuals involved, timestamps and transmission routes. Process data describes the processes and procedures within systems or organisations, including workflow documentation, transaction and activity logs, as well as audit logs used to track and verify operations.
- Usage data: Usage data refers to information that records how users interact with digital products, services or platforms. This data encompasses a wide range of information that reveals how users utilise applications, which features they prefer, how long they spend on specific pages and the paths they take when navigating through an application. Usage data may also include the frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. Furthermore, usage data plays a crucial role in identifying trends, preferences and potential problem areas within digital offerings
- Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles containing user-related information: The processing of ‘profiles containing user-related information’, or ‘profiles’ for short, encompasses any form of automated processing of personal data that involves using such personal data to analyse, evaluate or predict certain personal aspects relating to a natural person (depending on the nature of the profiling, this may include various information concerning demographics, behaviour and interests, such as interaction with websites and their content, etc.) or to predict them (e.g. interests in specific content or products, clicking behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
- Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details regarding the use or operation of a system. Log data is often used to analyse system issues, for security monitoring or to generate performance reports.
- Audience measurement: Audience measurement (also known as web analytics) is used to analyse visitor traffic to an online service and may include the behaviour or interests of visitors in relation to specific information, such as website content. With the help of reach analysis, operators of online services can, for example, identify at what times users visit their websites and what content they are interested in. This enables them, for example, to better tailor the content of their websites to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are frequently used to identify returning visitors and thus obtain more accurate analyses of the use of an online service.
- Tracking: The term ‘tracking’ is used when users’ behaviour can be tracked across multiple online services. As a rule, information relating to behaviour and interests in relation to the online services used is stored in cookies or on the servers of the providers of the tracking technologies (so-called ‘profiling’). This information can then be used, for example, to display advertisements to users that are likely to match their interests.
- Data controller: The term ‘data controller’ refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: ‘Processing’ means any operation or set of operations which is carried out on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, be it collection, analysis, storage, transmission or erasure.
- Target audience creation: The term ‘target audience creation’ (English: ‘Custom Audiences’) is used when target audiences are defined for advertising purposes, e.g. the display of advertisements. For example, based on a user’s interest in certain products or topics on the internet, it can be inferred that this user is interested in adverts for similar products or the online shop where they viewed the products. The term ‘Lookalike Audiences’ (or similar target groups) is used, on the other hand, when content deemed suitable is displayed to users whose profiles or interests are presumed to correspond to those of the users on whose profiles the groups were based. Cookies and web beacons are generally used for the purpose of creating Custom Audiences and Lookalike Audiences.
