Privacy Policy
Introduction and Overview
To protect personal data, we have implemented both technical and organizational measures. Where possible, we encrypt or pseudonymize personal data. This makes it as difficult as possible, within our capabilities, for third parties to draw conclusions about personal information from our data.
Art. 25 GDPR refers to “data protection by design and by default” and means that security is always considered and appropriate measures are implemented, both for software (e.g., forms) and hardware (e.g., access to the server room). Where necessary, we address specific measures below.
TLS Encryption with HTTPS
TLS, encryption, and https sound very technical—and they are. We use HTTPS (Hypertext Transfer Protocol Secure) to transmit data securely over the internet, protected against interception. This means that the complete transmission of all data from your browser to our web server is secured—no one can “listen in”.
This adds an additional layer of security and fulfills data protection by design (Art. 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the internet, we can ensure the protection of confidential data.
You can recognize this protection by the small lock symbol in the upper left of the browser, to the left of the internet address (e.g., beispielseite.de), and by the use of the scheme https (instead of http) as part of our internet address.
If you would like to learn more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find good links to further information.
Communication
Communication Summary Affected persons: Everyone who communicates with us by phone, email, or online form
Processed data: e.g., phone number, name, email address, entered form data. More details can be found under the respective method of contact
Purpose: Handling communication with customers, business partners, etc.
Storage period: Duration of the business case and statutory requirements
⚖ Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)
If you contact us and communicate by phone, email, or online form, personal data may be processed. The data is processed to handle and respond to your inquiry and the related business transaction. The data is stored for as long as the business case lasts and/or as long as required by law.
Affected persons
All those who seek contact with us via the communication channels we provide are affected.
Telephone
If you call us, the call data is stored pseudonymized on the respective end device and by the telecommunications provider used. In addition, data such as name and phone number may subsequently be sent by email and stored to answer the inquiry. The data will be deleted as soon as the business case has ended and statutory requirements allow it.
Email
If you communicate with us by email, data may be stored on the respective end device (computer, laptop, smartphone, etc.) and data is stored on the email server. The data will be deleted as soon as the business case has ended and statutory requirements allow it.
Online forms
If you communicate with us via an online form, data is stored on our web server and may be forwarded to one of our email addresses. The data will be deleted as soon as the business case has ended and statutory requirements allow it. To fend off mass-mailed advertising, the form checks a single-use token issued by the server and the number of submissions per sender when you submit it. No cookie and no session are used for this. Only checksums are stored: of your IP address, of your email address and – to recognise messages sent twice – of your email address together with the other details you entered in the form. Without the server’s secret key, nothing can be derived from them; they are deleted after 24 hours at the latest.
Legal bases
Processing is based on the following legal bases:
Art. 6(1)(a) GDPR (consent): You consent to us storing your data and continuing to use it for purposes related to the specific business case;
Art. 6(1)(b) GDPR (contract): Processing is necessary to fulfill a contract with you or with a processor (e.g., the phone provider), or we must process the data for pre-contractual measures such as preparing an offer;
Art. 6(1)(f) GDPR (legitimate interests): We want to handle customer inquiries and business communication professionally. Certain technical systems such as email programs, Exchange servers, and mobile network operators are necessary to operate communication efficiently.
Data Processing Agreement (DPA)
In this section, we explain what a data processing agreement is and why it is required. Because the term “data processing agreement” is quite a mouthful, we will also use the acronym DPA in this text. Like most companies, we do not work alone; we also use services from other companies or individuals. By involving various companies and service providers, it may be necessary to disclose personal data for processing. These partners then act as processors, with whom we conclude a contract—the data processing agreement (DPA). The most important thing for you to know is that processing of your personal data is carried out exclusively on our instructions and must be regulated by the DPA.
Who are processors?
As a company and website operator, we are responsible for all data we process about you. In addition to controllers, there can be so-called processors. This includes any company or person that processes personal data on our behalf. More precisely, according to the GDPR definition: any natural or legal person, public authority, agency, or other body that processes personal data on our behalf is considered a processor. Processors can therefore include service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
For better understanding, here is an overview of the three roles in the GDPR:
Data subject (you as customer or interested party) → Controller (us as company and client) → Processor (service providers such as web host or cloud provider)
Content of a DPA
As mentioned above, we have concluded a DPA with our partners who act as processors. This states, above all, that the processor processes the data exclusively in accordance with the GDPR. The contract must be concluded in writing; in this context, electronic conclusion is also considered “in writing”. Processing of personal data only takes place on the basis of this contract. The contract must include:
binding to us as the controller
duties and rights of the controller
categories of data subjects
type of personal data
nature and purpose of data processing
subject matter and duration of processing
place where processing is carried out
In addition, the contract contains all obligations of the processor. The most important obligations are:
ensuring measures for data security
taking possible technical and organizational measures to protect the rights of the data subject
maintaining a record of processing activities
cooperating with the data protection supervisory authority upon request
carrying out a risk analysis regarding the personal data received
engaging sub-processors only with the written authorization of the controller
You can view what such a DPA might look like, for example, at:
https://www.wko.at/dsgvo4kmu/muster-vereinbarung-auftragsverarbeitung
A sample contract is presented there.
Web Hosting Introduction
Web Hosting Summary Affected persons: Visitors to the website
Purpose: Professional hosting of the website and securing operation
Processed data: IP address, time of website visit, browser used, and other data. More details can be found below and/or from the respective web hosting provider
Storage period: depends on the provider, but usually 2 weeks
⚖ Legal basis: Art. 6(1)(f) GDPR (legitimate interests)
What is web hosting?
When you visit websites today, certain information—including personal data—is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only with justification. By “website” we mean the totality of all web pages on a domain, i.e., everything from the home page to the very last subpage (like this one). By “domain” we mean, for example, beispiel.de or musterbeispiel.com.
To view a website on a computer, tablet, or smartphone, you use a program called a web browser. You likely know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We refer to them simply as “browser” or “web browser”.
To display the website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complex and time-consuming task, which is why this is usually handled by professional providers. They offer web hosting and thus ensure reliable and error-free storage of website data. A lot of technical terms, but please stay with us—it gets even better!
When the browser on your computer (desktop, laptop, tablet, or smartphone) establishes a connection and during data transmission to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must store data for a certain period to ensure proper operation.
A picture says more than a thousand words; the following graphic illustrates the interaction between browser, the internet, and the hosting provider.
Why do we process personal data?
The purposes of data processing are:
professional hosting of the website and securing operation
maintaining operational and IT security
anonymous evaluation of access behavior to improve our offering and, if necessary, for prosecution or assertion of claims
What data is processed?
While you are visiting our website, our web server (the computer on which this website is stored) usually automatically stores data such as:
the full internet address (URL) of the accessed page
browser and browser version (e.g., Chrome 87)
operating system used (e.g., Windows 10)
the address (URL) of the previously visited page (referrer URL) (e.g., https://www.example.com/where-i-came-from/)
the host name and IP address of the device from which access is made (e.g., COMPUTERNAME and 194.23.43.121)
date and time
in files, the so-called web server log files
How long is data stored?
As a rule, the above data is stored for two weeks and then automatically deleted. We do not pass this data on, but we cannot rule out that this data may be viewed by authorities in the event of unlawful behavior.
In short: Your visit is logged by our provider (the company that operates our website on special computers (servers)), but we do not pass on your data without consent.
Legal basis
The lawfulness of processing personal data within the scope of web hosting results from Art. 6(1)(f) GDPR (legitimate interests), because the use of professional hosting by a provider is necessary in order to present the company on the internet securely and user-friendly and to be able to pursue attacks and resulting claims where appropriate.
As a rule, a processing agreement pursuant to Art. 28 et seq. GDPR exists between us and the hosting provider, ensuring compliance with data protection and guaranteeing data security.
Explanation of Terms Used
We always strive to write our privacy policy as clearly and understandably as possible. However, this is not always easy, especially with technical and legal topics. It often makes sense to use legal terms (such as personal data) or certain technical terms (such as cookies, IP address). However, we do not want to use these without explanation. Below you will find an alphabetical list of important terms used that may not have been sufficiently explained above.
Processor
Definition according to Art. 4 GDPR:
A processor is a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
Explanation: We, as a company and website operator, are responsible for all data we process about you. In addition to controllers, there can also be processors. This includes any company or person that processes personal data on our behalf, such as hosting providers, cloud providers, payment providers, newsletter providers, or companies such as Google or Microsoft.
Consent
Definition according to Art. 4 GDPR:
Consent of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she signifies agreement to the processing of personal data.
Explanation: On websites, such consent is usually obtained via a cookie consent tool. You know this from banners that appear when you first visit a website.
Personal Data
Definition according to Art. 4 GDPR:
Personal data means any information relating to an identified or identifiable natural person.
Explanation: This includes data such as name, address, email, phone number, date of birth, ID numbers, bank data, IP address, etc.
Profiling
Definition according to Art. 4 GDPR:
Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.
Explanation: Profiling is often used for advertising purposes or credit checks.
Controller
Definition according to Art. 4 GDPR:
The natural or legal person who determines the purposes and means of processing personal data.
Explanation: In this case, we are the controller.
Processing
Definition according to Art. 4 GDPR:
Any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
Final Words
Congratulations! If you are reading these lines, you have truly made your way through our entire privacy policy or at least scrolled this far. As you can see from the scope of our privacy policy, we take the protection of your personal data very seriously.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, we want not only to tell you which data is processed, but also to explain the reasons for using various software programs. Privacy policies often sound very technical and legal. Since most of you are neither web developers nor lawyers, we wanted to take a different linguistic approach and explain the matter in simple and clear language.
If you have any questions about data protection on our website, please do not hesitate to contact us or the responsible office. We wish you a pleasant time and hope to welcome you back to our website soon.
All texts are protected by copyright.
Source: Created with the Privacy Data Generator by AdSimple
