Updated: ◌ 30 • December • 2022
Introduction and Overview
Please note that this version of our Privacy Policy is a translation of the German version. The German version is the authoritative and favorable document and can be viewed at https://sysfacts.com/de/privacy/.
We have written this privacy statement (version 22.08.2022-312099147) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we as the controller – and the processors (e.g. providers) commissioned by us – process, will process in the future and what lawful options you have. The terms used are to be understood as gender-neutral.
In short, we inform you comprehensively about data we process about you.
Privacy statements usually sound very technical and use legal terminology. This privacy statement, on the other hand, is intended to describe the most important things to you as simply and transparently as possible. To the extent that it is conducive to transparency, technical terms are explained in a reader-friendly manner, links to further information are provided and graphics are used. In this way, we inform you in clear and simple language that we only process personal data in the course of our business activities if there is a corresponding legal basis. This is certainly not possible by providing the most concise, unclear and legalistic explanations possible, as is often standard practice on the Internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is one or two pieces of information that you did not yet know.
If you still have questions, we would like to ask you to contact the responsible party named below or in the imprint, to follow the available links and to look at further information on third-party sites. Our contact details can of course also be found in the imprint.
Scope of application
This data protection declaration applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (order processors). By personal data, we mean information within the meaning of Art. 4 No. 1 DSGVO, such as a person’s name, e-mail address and postal address. The processing of personal data ensures that we can offer and invoice our services and products, whether online or offline. The scope of this privacy policy includes:
- all online presences (websites, online stores) that we operate
- social media presences and email communications
- mobile apps for smartphones and other devices
In short, the data protection declaration applies to all areas in which personal data is processed in a structured manner within the company via the aforementioned channels. If we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.
Legal basis
In the following privacy statement, we provide you with transparent information on the legal principles and regulations, i.e. the legal bases of the General Data Protection Regulation, which enable us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can of course read
this EU General Data Protection Regulation online on EUR-Lex, the access to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.
We only process your data if at least one of the following conditions applies:
- Consent (Article 6(1) lit. a DSGVO): You have given us your consent to process data for a specific purpose. An example would be the storage of your entered data of a contact form.
- contract (Article 6(1)(b) DSGVO): In order to fulfill a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase contract with you, we need personal information in advance.
- Legal obligation (Article 6(1)(c) DSGVO): If we are subject to a legal obligation, we process your data. For example, we are legally obliged to keep invoices for accounting purposes. These usually contain personal data.
- Legitimate interests (Article 6(1)(f) DSGVO): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and economically efficiently. This processing is therefore a legitimate interest.
Further conditions such as the performance of recordings in the public interest and the exercise of official authority as well as the protection of vital interests do not generally occur with us. If such a legal basis should be relevant, it will be indicated at the appropriate place.
In addition to the EU regulation, national laws also apply:
- In Austria, this is the Federal Act on the Protection of Individuals with regard to the Processing of Personal Data (Data Protection Act), or DSG for short.
- In Germany, the Federal Data Protection Act, or BDSG for short, applies.
If other regional or national laws apply, we will inform you about them in the following sections.
Contact details of the responsible person
If you have any questions regarding data protection or the processing of personal data, you will find the contact details of the responsible person or office below:
Marcus Pockrandt
Rudolfplatz 3
50674 Cologne, Germany
privacy@sysfacts.com
+49 221 670572 15
Email: privacy@sysfacts.com
Phone: +49 221 670572 15
Contact details of the data protection officer
Below you will find the contact details of the data protection officer:
Marcus Pockrandt
Rudolfplatz 3
50674 Cologne, Germany
E-mail: privacy@sysfacts.com
Phone: +49 221 670572 15
Storage duration
The fact that we only store personal data for as long as is absolutely necessary for the provision of our services and products applies as a general criterion at our company. This means that we delete personal data as soon as the reason for processing the data no longer exists. In some cases, we are required by law to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.
Should you wish your data to be deleted or revoke your consent to data processing, the data will be deleted as soon as possible and insofar as there is no obligation to store it.
We will inform you about the specific duration of the respective data processing below, provided that we have further information on this.
Rights under the General Data Protection Regulation
In accordance with Articles 13, 14 of the GDPR, we inform you about the following rights you have to ensure that data processing is fair and transparent:
- According to Article 15 of the GDPR, you have the right to know whether we are processing data about you. If this is the case, you have the right to receive a copy of the data and the following information:
- the purpose for which we carry out the processing;
- the categories, i.e. the types of data that are processed;
- who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
- how long the data will be stored;
- the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
- that you can complain to a supervisory authority (links to these authorities can be found below);
- the origin of the data if we have not collected it from you;
- whether profiling is carried out, i.e. whether data is automatically evaluated in order to arrive at a personal profile of you.
- You have a right to rectify data according to Article 16 of the GDPR, which means that we must correct data if you find errors.
- According to Article 17 of the GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you may request the deletion of your data.
- According to Article 18 of the GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it any further.
- According to Article 20 DSGVO, you have the right to data portability, which means that we will provide you with your data in a common format upon request.
- According to Article 21 of the GDPR, you have a right to object, which, once enforced, entails a change in processing.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then check as soon as possible whether we can legally comply with this objection.
- If data is used to conduct direct marketing, you may object to this type of data processing at any time. We may not use your data for direct marketing thereafter.
- If data is used to perform profiling, you can object to this type of data processing at any time. We may not use your data for profiling thereafter.
- According to Article 22 of the GDPR, you may have the right not to be subject to a decision based solely on automated processing (for example, profiling).
- According to Article 77 of the GDPR, you have the right to lodge a complaint. This means that you can complain to the data protection authority at any time if you believe that the data processing of personal data violates the GDPR.
In short, you have rights – do not hesitate to contact the responsible party listed above with us!
If you believe that the processing of your data violates data protection law or that your data protection rights have been violated in any other way, you can complain to the supervisory authority. For Austria, this is the data protection authority, whose website can be found at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
North Rhine-Westphalia Data Protection Authority
State Commissioner for Data Protection: Bettina Gayk
Address: Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
Telephone number: 02 11/384 24-0
E-mail address: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de/
Data transmission to third-party countries
We only transfer or process data to countries outside the EU (third countries) if you consent to this processing, if this is required by law or contractually necessary and in any case only to the extent that this is generally permitted. Your consent is in most cases the most important reason that we have data processed in third countries. Processing personal data in third countries such as the U.S., where many software vendors provide services and have their server locations, may mean that personal data is processed and stored in unexpected ways.
We expressly point out that according to the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. Data processing by US services (such as Google Analytics) may result in data not being processed and stored anonymously. Furthermore, US government authorities may be able to access individual data. In addition, it may happen that collected data is linked with data from other services of the same provider, if you have a corresponding user account. Where possible, we try to use server locations within the EU, if this is offered.
We will inform you in more detail about data transfer to third countries, if applicable, at the appropriate places in this privacy policy.
Data processing security
To protect personal data, we have implemented both technical and organizational measures. Where possible, we encrypt or pseudonymize personal data. In this way, we make it as difficult as possible for third parties to infer personal information from our data.
Article 25 of the GDPR refers to “data protection through technical design and data protection-friendly default settings” and thus means that both software (e.g., forms) and hardware (e.g., access to the server room) should always be designed with security in mind and that appropriate measures should be taken. If necessary, we will go into more detail on specific measures below.
TLS encryption with https
TLS, encryption and https sound very technical and they are. We use HTTPS (the Hypertext Transfer Protocol Secure stands for “secure hypertext transfer protocol”) to transfer data over the internet in a tap-proof way.
This means that the complete transmission of all data from your browser to our web server is secured – no one can “listen in”.
We have thus introduced an additional layer of security and comply with data protection by design of technology (Article 25(1) DSGVO). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the Internet, we can ensure the protection of confidential data.
You can recognize the use of this protection of data transmission by the small lock symbol at the top left of the browser, to the left of the Internet address (e.g., beispielseite.de) and the use of the scheme https (instead of http) as part of our Internet address.
If you want to know more about encryption, we recommend the Google search for “Hypertext Transfer Protocol Secure wiki” to get good links to further information.
Communication
Communication Summary
👥 Betroffene: Alle, die mit uns per Telefon, E-Mail oder Online-Formular kommunizieren
📓 Verarbeitete Daten: z. B. Telefonnummer, Name, E-Mail-Adresse, eingegebene Formulardaten. Mehr Details dazu finden Sie bei der jeweils eingesetzten Kontaktart
🤝 Zweck: Abwicklung der Kommunikation mit Kunden, Geschäftspartnern usw.
📅 Speicherdauer: Dauer des Geschäftsfalls und der gesetzlichen Vorschriften
⚖️ Rechtsgrundlagen: Art. 6 Abs. 1 lit. a DSGVO (Einwilligung), Art. 6 Abs. 1 lit. b DSGVO (Vertrag), Art. 6 Abs. 1 lit. f DSGVO (Berechtigte Interessen)
Wenn Sie mit uns Kontakt aufnehmen und per Telefon, E-Mail oder Online-Formular kommunizieren, kann es zur Verarbeitung personenbezogener Daten kommen.
Die Daten werden für die Abwicklung und Bearbeitung Ihrer Frage und des damit zusammenhängenden Geschäftsvorgangs verarbeitet. Die Daten während eben solange gespeichert bzw. solange es das Gesetz vorschreibt.
Persons concerned
All those who seek contact with us via the communication channels provided by us are affected by the aforementioned processes.
Phone
When you call us, the call data is stored pseudonymously on the respective terminal device and with the telecommunications provider used. In addition, data such as name and telephone number may subsequently be sent by e-mail and stored for the purpose of responding to inquiries. The data is deleted as soon as the business case has been terminated and legal requirements permit.
If you communicate with us by e-mail, data may be stored on the respective end device (computer, laptop, smartphone,…) and data is stored on the e-mail server. The data is deleted as soon as the business case has been terminated and legal requirements allow it.
Online forms
If you communicate with us using an online form, data is stored on our web server and, if necessary, forwarded to an e-mail address of ours. The data is deleted as soon as the business case has been terminated and legal requirements permit.
Legal basis
The processing of the data is based on the following legal bases:
- Art. 6 para. 1 lit. a DSGVO (consent): You give us your consent to store your data and to use it for purposes related to the business case;
- Art. 6 para. 1 lit. b DSGVO (contract): There is a need for the performance of a contract with you or a processor such as the telephone provider or we need to process the data for pre-contractual activities, such as the preparation of an offer;
- Art. 6 Abs. 1 lit. f DSGVO (Legitimate Interests): We want to operate customer inquiries and business communication in a professional framework. For this purpose, certain technical facilities such as e-mail programs, exchange servers and mobile network operators are necessary in order to be able to operate the communication efficiently.
Cookies
Cookies summary
👥 Data subjects: visitors to the website.
🤝 Purpose: depends on the cookie in question. More details can be found below or from the manufacturer of the software that sets the cookie.
📅 Storage duration: depending on the respective cookie, can vary from hours to years.
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (Consent), Art. 6 para. 1 lit.f DSGVO (Legitimate Interests).
What are cookies?
Our website uses HTTP cookies to store user-specific data.
Below we explain what cookies are and why they are used so that you can better understand the following privacy policy.
Whenever you browse the Internet, you use a browser. Popular browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing cannot be denied: Cookies are really useful little helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are other cookies for other applications. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, effectively the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data about you, such as language or personal page settings. When you return to our site, your browser transmits the “user-related” information back to our site. Thanks to cookies, our site knows who you are and offers you the setting you are used to. In some browsers, each cookie has its own file, in others, such as Firefox, all cookies are stored in a single file.
The following graphic shows a possible interaction between a web browser such as Chrome and the web server. Here, the web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. Also, the expiration time of a cookie varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans or other “pests”. Cookies also cannot access information on your PC.
For example, cookie data can look like this:
Name: _ga
Value: GA1.2.1326744211.152312099147-9
Intended use: differentiation of website visitors
Expiration date: after 2 years
A browser should be able to support these minimum sizes:
- At least 4096 bytes per cookie
- At least 50 cookies per domain
- At least 3000 cookies in total
What are the types of cookies?
The question of which cookies we use in particular depends on the services used and is clarified in the following sections of the privacy policy. At this point, we would like to briefly discuss the different types of HTTP cookies.
We can distinguish 4 types of cookies:
Essential cookies
These cookies are necessary to ensure basic website functionality. For example, these cookies are needed when a user adds a product to the shopping cart, then continues to browse other pages and later proceeds to checkout. These cookies do not delete the shopping cart even if the user closes his browser window.
Purposeful cookies
These cookies collect information about user behavior and whether the user receives any error messages. In addition, these cookies are also used to measure the loading time and the behavior of the website with different browsers.
Target-oriented cookies
These cookies provide a better user experience. For example, entered locations, font sizes or form data are stored.
Advertising cookies
These cookies are also called targeting cookies. They are used to deliver customized advertising to the user. This can be very convenient, but also very annoying.
Usually, when you visit a website for the first time, you are asked which of these cookie types you want to allow. And of course, this decision is also stored in a cookie.
If you want to know more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments from the Internet Engineering Task Force (IETF) called “HTTP State Management Mechanism”.
Purpose of processing via cookies
The purpose ultimately depends on the cookie in question. You can find more details below or from the manufacturer of the software that sets the cookie.
What data is processed?
Cookies are small helpers for many different tasks. Unfortunately, it is not possible to generalize what data is stored in cookies, but we will inform you about the processed or stored data in the following privacy policy.
Cookies storage duration
The storage period depends on the particular cookie and is specified further below. Some cookies are deleted after less than an hour, others can remain stored on a computer for several years.
You can also influence the storage period yourself. You can manually delete all cookies at any time via your browser (see also “Right of objection” below). Furthermore, cookies that are based on consent will be deleted at the latest after revocation of your consent, whereby the legality of the storage remains unaffected until then.
Right to object – how can I delete cookies?
How and whether you want to use cookies, you decide. Regardless of which service or website the cookies come from, you always have the option to delete, disable or only partially allow cookies. For example, you can block third-party cookies, but allow all other cookies.
If you want to determine which cookies have been stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings:
- Chrome: Delete, enable and manage cookies in Chrome
- Safari: Managing cookies and website data with Safari
- Firefox: Delete cookies to remove data that websites have placed on your computer
- Internet Explorer: Delete and manage cookies
- Microsoft Edge: Delete and manage cookies
If you do not want to have cookies in principle, you can set up your browser so that it always informs you when a cookie is to be set. In this way, you can decide for each individual cookie whether you allow the cookie or not. The procedure varies depending on the browser. It is best to search for the instructions in Google using the search term “delete cookies Chrome” or “disable cookies Chrome” in the case of a Chrome browser.
Legal basis
The so-called “Cookie Guidelines” have been in place since 2009. These state that the storage of cookies requires your consent (Article 6 (1) a DSGVO). Within the EU countries, however, there are still very different reactions to these directives. In Austria, however, this directive was implemented in Section 96 (3) of the Telecommunications Act (TKG). In Germany, the Cookie Directives were not implemented as national law. Instead, this directive was largely implemented in Section 15 (3) of the German Telemedia Act (TMG).
For absolutely necessary cookies, even in the absence of consent, there are legitimate interests (Article 6(1)(f) DSGVO), which in most cases are economic in nature. We want to provide visitors to the website with a pleasant user experience and for this purpose certain cookies are often absolutely necessary.
If cookies are used that are not absolutely necessary, this only happens in the case of your consent. The legal basis in this respect is Art. 6 para. 1 lit. a DSGVO.
In the following sections, you will be informed in more detail about the use of cookies, if used software uses cookies.
Application data
Application data summary
👥 Data subjects: users who apply for a job with us
🤝 Purpose: Processing of an application procedure.
📓 Processed data: Name, address, contact details, e-mail address, telephone number, proof of qualifications (certificates), possibly special category data.
📅 Storage period: in the event of a successful application, until the end of the employment relationship. Otherwise, the data will be deleted after the application process or stored for a certain period with your consent.
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (consent), legitimate interest (Art. 6 para. 1 lit. f DSGVO), Art. 6 para. 1 lit. b DSGVO (contract), Art. 9 para. 2 lit. a. DSGVO (processing of special categories)
What is application data?
You can apply to us by e-mail, online form or via a recruiting tool for a job in our company. All data that we receive and process from you as part of an application counts as application data. In doing so, you always disclose personal data such as name, date of birth, address and telephone number.
Why do we process application data?
We process your data so that we can operate a proper selection process in relation to the advertised position. In addition, we also like to keep your application documents in our application archive. Because it often happens that for the advertised positions a cooperation does not work out for various reasons, but we are impressed by you and your application and can imagine a future cooperation very well. Provided you give us your consent, we will archive your documents so that we can easily contact you for future tasks in our company.
We guarantee that we will handle your data with particular care and only ever process your data within the legal framework. Even within our company, your data will only be forwarded to persons who are directly involved with your application. In short: Your data is in safe hands with us!
What data is processed?
If you apply to us by e-mail, for example, we will of course also receive personal data, as mentioned above. Even the e-mail address already counts as personal data. However, in the course of an application process, we only process data that is relevant for our decision as to whether or not we want to welcome you to our team.
Exactly what data is processed depends primarily on the job posting. In most cases, however, it is a matter of name, date of birth, contact details and proof of qualifications. If you submit the application via an online form, the data is passed on to us in encrypted form. If you send us the application by e-mail, this encryption does not take place. Therefore, we cannot assume any responsibility for the way the data is transmitted. However, once the data is on our servers, we are responsible for the lawful handling of your data.
During an application process, in addition to the data mentioned above, information about your health or ethnic origin may also be requested so that we and you can exercise the rights related to labor law, social security and social protection and, at the same time, comply with the corresponding obligations. These data are special category data.
Here is a list of possible data we receive from you and process:
- Name
- Contact address
- E-mail address
- Phone number
- Date of birth
- Information that comes from the cover letter and resume
- Proof of qualification (e.g.) Certificates
- Special category data (e.g., ethnic origin, health data, religious beliefs).
- Usage data (websites visited, access data ect.)
- Metadata (IP address, device information)
How long will the data be stored?
If we accept you as a team member in our company, your data will be further processed for the purpose of the employment relationship and kept with us at least until the employment relationship ends. All application documents will then be placed in your employee file.
If we do not offer you the job, if you decline our offer or withdraw your application, we may retain your data for up to 6 months after the conclusion of the application process due to legitimate interest (Art. 6 (1) lit. f DSGVO). After that, both your electronic data and all data from physical application documents will be completely deleted or destroyed. We retain your data, for example, so that we can still answer any follow-up questions or so that we can provide evidence of the application in the event of a legal dispute. If a legal dispute arises and we may still need the data after the 6 months have expired, we will only delete the data when there is no longer any reason to retain it. If there are legal retention obligations to fulfill, we must generally store the data for longer than 6 months.
Furthermore, we can also keep your data longer if you have given special consent for this. We do this, for example, if we can well imagine a cooperation with you in the future. Then it is helpful to have your data archived so that we can contact you without any problems. In this case, the data will be added to our applicant pool. Of course, you can revoke your consent to the longer storage of your data at any time. If there is no revocation and you do not give a new consent, your data will be deleted after 2 years at the latest.
Legal basis
Legal bases for the processing of your data are Art. 6 para 1 lit. a DSGVO (consent), Art. 6 para 1 lit. b DSGVO (contract or pre-contractual measures), Art. 6 para 1 lit. f DSGVO (legitimate interests) and Art. 9 para 2 lit. a. DSGVO (processing of special categories).
If we include you in our application tool, this happens on the basis of your consent (Art. 6 para. 1 lit. a DSGVO). We would like to point out that your consent to our application pool is voluntary, has no influence on the application process and you have the option to revoke your consent at any time. The lawfulness of the processing until the time of the revocation remains unaffected.
In the case of the protection of vital interests, the data processing is carried out in accordance with Art. 9 para. 2 lit. c. DSGVO. For the purposes of health care, occupational medicine, medical diagnosis, health or social care or treatment, or for the management of health or social care systems and services, the processing of personal data is carried out in accordance with Art. 9 (2) lit. h. DSGVO. If you voluntarily provide special category data, the processing is based on Art. 9 (2) lit. a. DSGVO.
Web hosting introduction
Web hosting summary
👥 Affected parties: visitors of the website.
🤝 Purpose: professional hosting of the website and securing its operation.
📓 Processed data: IP address, time of website visit, browser used and other data. More details can be found below or with the respective web hosting provider used.
📅 Storage period: depending on the respective provider, but usually 2 weeks.
⚖️ Legal basis: Art. 6 para. 1 lit.f DSGVO (Legitimate Interests).
What is web hosting?
When you visit websites nowadays, certain information – including personal data – is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only with justification. By the way, by website we mean the entirety of all web pages on a domain, i.e. everything from the home page (homepage) to the very last subpage (like this one). By domain, we mean, for example, example.de or sampleexample.com.
When you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser to do so. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We say browser or web browser for short.
To display the website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complicated and costly task, which is why this is usually done by professional providers, the providers. These offer web hosting and thus ensure reliable and error-free storage of website data. A whole lot of technical terms, but please stay tuned, it gets better!
When the browser on your computer (desktop, laptop, tablet or smartphone) connects and during data transfer to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a while to ensure proper operation.
A picture is worth a thousand words, so the following graphic illustrates the interaction between the browser, the Internet and the hosting provider.
Why do we process personal data?
The purposes of data processing are:
- Professional hosting of the website and securing its operation
- to maintain operational and IT security
- Anonymous evaluation of access behavior to improve our offer and, if necessary, for criminal prosecution or the pursuit of claims
What data is processed?
Even while you are visiting our website right now, our web server, which is the computer on which this website is stored, usually automatically stores data such as
- the complete Internet address (URL) of the accessed web page
- Browser and browser version (e.g. Chrome 87)
- the operating system used (e.g. Windows 10)
- the address (URL) of the previously visited page (referrer URL) (e.g. https://www.beispielquellsite.de/vondabinichgekommen/)
- the hostname and IP address of the device being accessed from (e.g. COMPUTERNAME and 194.23.43.121)
- Date and time
- in files, the so-called web server log files
How long is data stored?
As a rule, the above data is stored for two weeks and then automatically deleted. We do not pass on this data, but we cannot exclude the possibility that this data may be viewed by authorities in the event of unlawful conduct.
In short, your visit is logged by our provider (company that runs our website on special computers (servers)), but we do not share your information without consent!
Legal basis
The lawfulness of the processing of personal data in the context of web hosting results from Art. 6 para. 1 lit. f DSGVO (protection of legitimate interests), because the use of professional hosting with a provider is necessary to present the company on the Internet in a secure and user-friendly manner and to be able to pursue attacks and claims from this if necessary.
As a rule, there is a contract between us and the hosting provider for commissioned processing pursuant to Art. 28 f. DSGVO, which ensures compliance with data protection and guarantees data security.
1&1 IONOS Webhosting Privacy Policy
We use IONOS by 1&1 to host our website. In Germany, 1&1 IONOS SE is located at Elgendorfer Str. 57, 56410 Montabaur, in Austria you can find 1&1 IONOS SE at Gumpendorfer Straße 142/PF 266, 1060 Vienna. IONOS offers the following web hosting services: Domain, Website & Shop, Hosting & WordPress, Marketing, Email & Office, IONOS Cloud and Server.
As explained in the “Automatic Data Storage” section, web servers, such as those of IONOS, store data of each website visit.
If you would like to learn more about the privacy policy for IONOS website, please visit the privacy policy on ionos.com.
Order processing agreement (AVV) IONOS
In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have entered into a Data Processing Agreement (DPA) with IONOS. What exactly is a GCU and especially what must be included in a GCU, you can read in our general section “Order Processing Agreement (GCU)”.
This contract is required by law because IONOS processes personal data on our behalf. It clarifies that IONOS may only process data they receive from us according to our instructions and must comply with the GDPR. You can find the link to the order processing agreement (AVV) at https://www.ionos.de/hilfe/datenschutz/allgemeine-informationen-zur-datenschutz-grundverordnung-dsgvo/auftragsverarbeitung/.
Web Analytics Introduction
Web Analytics Privacy Policy Summary
👥 Data subjects: Visitors to the website.
🤝 Purpose: Evaluation of visitor information to optimize the web offer.
📓 Data processed: Access statistics containing data such as access locations, device data, access duration and time, navigation behavior, click behavior, and IP addresses. More details can be found with the respective web analytics tool used.
📅 Storage period: depending on the web analytics tool used.
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (consent), Art. 6 para. 1 lit. f DSGVO (legitimate interests).
What is Web Analytics?
We use software on our website to evaluate the behavior of website visitors, known as web analytics for short. This involves collecting data that is stored, managed and processed by the respective analytic tool provider (also known as a tracking tool). The data is used to create analyses of user behavior on our website and made available to us as the website operator. In addition, most tools offer various testing options. For example, we can test which offers or content are best received by our visitors. To do this, we show you two different offers for a limited period of time. After the test (so-called A/B test), we know which product or content our website visitors find more interesting. For such test procedures, as for other analytics procedures, user profiles can also be created and the data stored in cookies.
Why do we run web analytics?
With our website we have a clear goal in mind: we want to deliver the best web offer on the market for our industry. To achieve this goal, we want to offer the best and most interesting offer on the one hand, and on the other hand make sure that you feel completely comfortable on our website. With the help of web analysis tools, we can take a closer look at the behavior of our website visitors and then improve our web offer for you and us accordingly. For example, we can see how old our visitors are on average, where they come from, when our website is most visited or which content or products are particularly popular. All this information helps us to optimize the website and thus best adapt it to your needs, interests and wishes.
What data is processed?
Exactly what data is stored depends, of course, on the analysis tools used. But as a rule, for example, which content you view on our website, which buttons or links you click on, when you access a page, which browser you use, which device (PC, tablet, smartphone, etc.) you use to visit the website or which computer system you use is stored. If you agreed that location data may also be collected, these may also be processed by the web analytics tool provider.
In addition, your IP address is also stored. According to the General Data Protection Regulation (DSGVO), IP addresses are personal data. However, your IP address is usually stored pseudonymously (i.e. in an unrecognizable and shortened form). For the purpose of testing, web analysis and web optimization, no direct data, such as your name, age, address or email address are stored as a matter of principle. All this data, if collected, is stored pseudonymously. Thus, you cannot be identified as a person.
The following example shows schematically how Google Analytics works as an example of client-based web tracking with Java Script code.
How long the respective data is stored always depends on the provider. Some cookies store data only for a few minutes or until you leave the website again, other cookies can store data for several years.
Duration of data processing
We will inform you about the duration of data processing below, provided we have further information on this. In general, we process personal data only as long as it is absolutely necessary for the provision of our services and products. If it is required by law, as for example in the case of accounting, this storage period may also be exceeded.
Right of objection
You also have the right and the possibility to revoke your consent to the use of cookies or third-party providers at any time. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection through cookies by managing, disabling or deleting cookies in your browser.
Legal basis
The use of web analytics requires your consent, which we have obtained with our cookie popup. According to Art. 6 para. 1 lit. a DSGVO (consent), this consent constitutes the legal basis for the processing of personal data as it may occur during the collection by web analytics tools.
In addition to consent, there is a legitimate interest on our part to analyze the behavior of website visitors and thus to improve our offer technically and economically. With the help of web analytics, we detect errors of the website, can identify attacks and improve the economic efficiency. The legal basis for this is Art. 6 para. 1 lit. f DSGVO (Legitimate Interests). Nevertheless, we use the tools only insofar as they have given consent.
Since web analytics tools use cookies, we also recommend that you read our general privacy policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy statements of the respective tools.
Information on specific web analytics tools, if any, is provided in the following sections.
Google Analytics Privacy Policy
Google Analytics Privacy Policy Summary
👥 Data subjects: Visitors to the website.
🤝 Purpose: Evaluation of visitor information to optimize the web offer.
📓 Data processed: Access statistics, which include data such as locations of accesses, device data, access duration and time, navigation behavior, click behavior, and IP addresses. More details can be found below in this privacy policy.
📅 Storage duration: depending on the properties used.
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (consent), Art. 6 para. 1 lit. f DSGVO (legitimate interests).
What is Google Analytics?
We use on our website the analysis tracking tool Google Analytics (GA) of the American company Google Inc. For the European area the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your actions on our website. For example, when you click on a link, this action is stored in a cookie and sent to Google Analytics. Using the reports we receive from Google Analytics, we can better tailor our website and service to your preferences. In the following, we will go into more detail about the tracking tool and, in particular, inform you about what data is stored and how you can prevent this.
Google Analytics is a tracking tool used for traffic analysis of our website. For Google Analytics to work, a tracking code is built into the code of our website. When you visit our website, this code records various actions you take on our website. Once you leave our website, this data is sent to the Google Analytics servers and stored there.
Google processes the data and we receive reports about your user behavior. These reports may include, but are not limited to, the following:
- Target group reports: Through target group reports, we get to know our users better and know more precisely who is interested in our service.
- Ad reports: Ad reports make it easier for us to analyze and improve our online advertising.
- Acquisition reports: Acquisition reports give us helpful information on how to get more people interested in our service.
- Behavior reports: This is where we learn how you interact with our website. We can track which path you take on our site and which links you click.
- Conversion reports: Conversion is the name given to a process in which you take a desired action as a result of a marketing message. For example, you go from being just a website visitor to a buyer or newsletter subscriber. These reports help us learn more about how our marketing efforts are working for you. This is how we aim to increase our conversion rate.
- Real-time reports: Here we always know immediately what is happening on our website. For example, we can see how many users are reading this text.
Why do we use Google Analytics on our website?
Our goal with this website is clear: we want to provide you with the best possible service. The statistics and data from Google Analytics help us achieve this goal.
The statistically evaluated data shows us a clear picture of the strengths and weaknesses of our website. On the one hand, we can optimize our site so that it is found more easily by interested people on Google. On the other hand, the data helps us to better understand you as a visitor. Thus, we know very well what we need to improve on our website in order to provide you with the best possible service. The data also helps us to carry out our advertising and marketing measures in a more individual and cost-effective way. After all, it only makes sense to show our products and services to people who are interested in them.
What data is stored by Google Analytics?
Google Analytics uses a tracking code to create a random, unique ID associated with your browser cookie. This is how Google Analytics recognizes you as a new user. The next time you visit our site, you will be recognized as a “returning” user. All collected data is stored together with this user ID. This is how it is possible to evaluate pseudonymous user profiles in the first place.
To be able to analyze our website with Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For each newly created property, the Google Analytics 4 property is default. Alternatively, you can also create the Universal Analytics property. Depending on the property used, data is stored for different lengths of time.
Identifiers such as cookies and app instance IDs measure your interactions on our website. Interactions are all types of actions you take on our website. If you also use other Google systems (such as a Google account), data generated through Google Analytics may be linked to third-party cookies. Google does not share Google Analytics data unless we, as the website operator, authorize it. Exceptions may occur if required by law.
The following cookies are used by Google Analytics:
Name: _ga
Value: 2.1326744211.152312099147-5
Purpose: By default, analytics.js uses the _ga cookie to store the user ID. Basically, it is used to distinguish website visitors.
Expiration date: after 2 years
Name: _gid
Value: 2.1687193234.152312099147-1
Purpose: the cookie is also used to distinguish website visitors
Expiration date: after 24 hours
Name: gat_gtag_UA
Value: 1
Purpose: Used to lower the request rate. If Google Analytics is deployed via Google Tag Manager, this cookie will be named dc_gtm .
Expiration date: after 1 minute
Name: AMP_TOKEN
Value: not specified
Purpose: The cookie has a token that can be used to retrieve a user ID from the AMP client ID service. Other possible values indicate a logout, a request, or an error.
Expiration date: after 30 seconds up to one year
Name: __utma
Value: 1564498958.1564498958.1564498958.1
Purpose: This cookie is used to track your behavior on the website and measure performance. The cookie is updated every time information is sent to Google Analytics.
Expiration date: after 2 years
Name: _utmt
Value: 1
Purpose: The cookie is used like _gat_gtag_UA to throttle the request rate.
Expiration date: after 10 minutes
Name: __utmb
Value: 3.10.1564498958
Purpose: This cookie is used to determine new sessions. It is updated every time new data or info is sent to Google Analytics.
Expiration date: after 30 minutes
Name: __utmc
Value: 167421564
Purpose: This cookie is used to set new sessions for returning visitors. This is a session cookie and is only stored until you close the browser again.
Expiration date: After you close the browser.
Name: __utmz
Value: m|utmccn=(referral)|utmcmd=referral|utmcct=/
Purpose: The cookie is used to identify the source of traffic to our website. That is, the cookie stores from where you came to our website. This may have been another page or an advertisement.
Expiration date: after 6 months
Name: __utmv
Value: not specified
Purpose: The cookie is used to store custom user data. It is updated whenever information is sent to Google Analytics.
Expiration date: after 2 years
Note: This list cannot claim to be complete, as Google also changes the choice of their cookies again and again.
Here we show you an overview of the most important data that is collected with Google Analytics:
Heatmaps: Google creates so-called heatmaps. Heatmaps allow you to see exactly those areas that you click on. This gives us information about where you are “on the move” on our site.
Session duration: Google defines session duration as the time you spend on our site without leaving. If you have been inactive for 20 minutes, the session ends automatically.
Bounce rate: A bounce is when you view only one page on our website and then leave our website again.
Account creation: When you create an account or place an order on our website, Google Analytics collects this data.
IP address: The IP address is only shown in abbreviated form so that no clear assignment is possible.
Location: The IP address can be used to determine the country and your approximate location. This process is also called IP location determination.
Technical information: Technical information may include your browser type, Internet service provider, or screen resolution.
Source of origin: Google Analytics or, of course, we are also interested in which website or which advertisement you came to our site from.
Other data include contact details, any ratings, playing media (e.g. when you play a video via our site), sharing content via social media or adding to your favorites. The enumeration does not claim to be complete and only serves as a general orientation of the data storage by Google Analytics.
How long and where is the data stored?
Google has their servers spread all over the world. Most servers are located in America and consequently your data is mostly stored on American servers. Here you can read exactly where Google data centers are located: https://www.google.com/about/datacenters/locations/?hl=de
Your data is distributed on different physical data carriers. This has the advantage that the data can be retrieved more quickly and is better protected against manipulation. In every Google data center, there are corresponding emergency programs for your data. If, for example, the hardware at Google fails or natural disasters paralyze servers, the risk of a service interruption at Google still remains low.
The data retention period depends on the properties used. When using the newer Google Analytics 4 properties, the retention period of your user data is set to 14 months. For other so-called event data, we have the option to choose a retention period of 2 months or 14 months.
For Universal Analytics properties, Google Analytics has a default retention period of 26 months for your user data. Then your user data is deleted. However, we have the option to choose the retention period of user data ourselves. We have five variants available for this purpose:
- Deletion after 14 months
- Deletion after 26 months
- Deletion after 38 months
- Deletion after 50 months
- No automatic deletion
In addition, there is also the option that data is only deleted when you no longer visit our website within the time period we have selected. In this case, the retention period is reset each time you visit our website again within the specified period.
Once the specified period has expired, the data is deleted once a month. This retention period applies to your data associated with cookies, user recognition and advertising IDs (e.g. DoubleClick domain cookies). Reporting results are based on aggregated data and are stored separately from user data. Aggregated data is a merging of individual data into a larger unit.
How can I delete my data or prevent data storage?
Under European Union data protection law, you have the right to access, update, delete, or restrict your data. Using the browser add-on to disable Google Analytics JavaScript (ga.js, analytics.js, dc.js), you can prevent Google Analytics from using your data. You can download and install the browser add-on at https://tools.google.com/dlpage/gaoptout?hl=de. Please note that this add-on only disables data collection by Google Analytics.
If you basically want to disable, delete or manage cookies, you can find the corresponding links to the respective instructions of the most popular browsers under the section “Cookies”.
Legal basis
The use of Google Analytics requires your consent, which we have obtained with our cookie popup. According to Art. 6 para. 1 lit. a DSGVO (consent), this consent constitutes the legal basis for the processing of personal data as it may occur during the collection by web analytics tools.
In addition to the consent, there is a legitimate interest on our part to analyze the behavior of website visitors and thus to improve our offer technically and economically. With the help of Google Analytics, we detect errors of the website, can identify attacks and improve the economic efficiency. The legal basis for this is Art. 6 para. 1 lit. f DSGVO (Legitimate Interests). Nevertheless, we only use Google Analytics if you have given your consent.
Google also processes data from you in the USA, among other places. We would like to point out that according to the opinion of the European Court of Justice, there is currently no adequate level of protection for the transfer of data to the USA. This may be associated with various risks for the legality and security of data processing.
Google uses so-called standard contractual clauses (= Art. 46. para. 2 and 3 DSGVO) as the basis for data processing for recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway, i.e. in particular in the USA) or a data transfer there. Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through these clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the US. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which reference the Standard Contractual Clauses, can be found at: https://business.safety.google/intl/de/adsprocessorterms/
We hope we have been able to provide you with the most important information about Google Analytics data processing. If you want to learn more about the tracking service, we recommend these two links: https://marketingplatform.google.com/about/analytics/terms/de/ and https://support.google.com/analytics/answer/6004245?hl=de.
Google Analytics order processing agreement (AVV)
In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have concluded an order processing agreement (OPA) with Google. What exactly is a GCU and especially what must be included in a GCU, you can read in our general section “Order processing agreement (GCU)”.
This contract is required by law because Google processes personal data on our behalf. It clarifies that Google may only process data they receive from us according to our instructions and must comply with the GDPR. You can find the link to the order data processing conditions at https://business.safety.google/intl/de/adsprocessorterms/.
Google Analytics reports on demographic characteristics and interests
We have turned on the advertising reports features in Google Analytics. The demographic and interest reports contain information on age, gender and interests. This allows us – without being able to assign this data to individual persons – to get a better picture of our users. You can learn more about the advertising functions at https://support.google.com/analytics/answer/3450482?hl=de_AT&utm_id=ad.
You can stop the use of the activities and information of your Google account under “Advertising settings” on https://adssettings.google.com/authenticated via checkbox.
Cookie Consent Management Platform Introduction
Cookie Consent Management Platform Summary
👥 Data subjects: website visitors
🤝 Purpose: To obtain and manage consent for certain cookies and thus the use of certain tools.
📓 Data processed: Data used to manage the cookie settings set, such as IP address, time of consent, type of consent, individual consents. More details can be found at the respective tool used.
📅 Storage period: Depends on the tool used, you have to be prepared for periods of several years.
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (consent), Art. 6 para. 1 lit.f DSGVO (legitimate interests).
What is a Cookie Consent Management Platform?
We use a Consent Management Platform (CMP) software on our website, which helps us and you to handle used scripts and cookies correctly and safely. The software automatically creates a cookie popup, scans and controls all scripts and cookies, provides cookie consent for you as required by data protection laws, and helps us and you keep track of all cookies. With most cookie consent management tools, all existing cookies are identified and categorized. You as a website visitor then decide for yourself whether and which scripts and cookies you allow or disallow. The following graphic illustrates the relationship between browser, web server and CMP.
Why do we use a cookie management tool?
Our goal is to offer you the best possible transparency in the area of data protection. In addition, we are also legally obligated to do so. We want to inform you as well as possible about all tools and all cookies that can store and process data from you. It is also your right to decide for yourself which cookies you accept and which you do not. In order to give you this right, we first need to know exactly which cookies ended up on our website in the first place. Thanks to a cookie management tool that regularly scans the website for all existing cookies, we know about all cookies and can provide you with DSGVO-compliant information about them. You can then accept or reject cookies via the consent system.
What data is processed?
Within the framework of our cookie management tool, you can manage each individual cookie yourself and have complete control over the storage and processing of your data. The declaration of your consent is stored so that we do not have to query you each time you visit our website again and we can also prove your consent if required by law. This is stored either in an opt-in cookie or on a server. Depending on the provider of the cookie management tool, the storage period of your cookie consent varies. In most cases, this data (e.g. pseudonymous user ID, time of consent, details of cookie categories or tools, browser, device information) is stored for up to two years.
Duration of data processing
We will inform you about the duration of data processing below, provided we have further information on this. In general, we process personal data only as long as it is absolutely necessary for the provision of our services and products. Data that is stored in cookies is stored for different lengths of time. Some cookies are already deleted after you leave the website, others may be stored in your browser for several years. The exact duration of data processing depends on the tool used; in most cases, you should be prepared for a storage period of several years. In the respective privacy statements of the individual providers, you will usually receive precise information about the duration of data processing.
Right of objection
You also have the right and the possibility to revoke your consent to the use of cookies at any time. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection through cookies by managing, disabling or deleting cookies in your browser.
Information on specific cookie management tools, if any, can be found in the following sections.
Legal basis
If you consent to cookies, personal data about you will be processed and stored via these cookies. If we are allowed to use cookies through your consent (Article 6 (1) lit. a DSGVO), this consent is also the legal basis for the use of cookies or the processing of your data. In order to be able to manage the consent to cookies and to enable you to give your consent, cookie consent management platform software is used. The use of this software enables us to operate the website in an efficient manner in compliance with the law, which constitutes a legitimate interest (Article 6 (1) (f) DSGVO).
Online map services introduction
Online map services privacy policy summary
👥 Data subjects: visitors to the website
🤝 Purpose: To improve the user experience.
📓 Data processed: Which data is processed depends largely on the services used. Mostly it is IP address, location data, search items and/or technical data. You can find more details about this in the respective tools used.
📅 Storage period: depending on the tools used.
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (Consent), Art. 6 para. 1 lit. f DSGVO (Legitimate Interests).
What are online map services?
We also use online map services for our website as an enhanced service. Google Maps is probably the service you are most familiar with, but there are other providers that specialize in creating digital maps. Such services allow you to view locations, route maps or other geographic information directly through our website. By using an embedded map service, you no longer have to leave our website to view the route to a location, for example. In order for the online map to work on our website, map sections are embedded using HTML code. The services can then display street maps, the earth’s surface or aerial or satellite images. If you use the built-in map service, data is also transmitted to the tool used and stored there. This data may also include personal data.
Why do we use online mapping services on our website?
Generally speaking, our aim is to provide you with a pleasant time on our website. And, of course, your time is pleasant only if you can easily find your way around our website and find all the information you need quickly and easily. That’s why we thought that an online map system could be another significant optimization of our service on the website. Without leaving our website, you can easily view route descriptions, locations or even points of interest with the help of the map system. Of course, it is also super convenient that you can see at a glance where we are located, so you can find us quickly and safely. As you can see, there are simply many advantages and we clearly consider online map services on our website as part of our customer service.
What data are stored by online map services?
When you open a page on our website that has an online map function built in, personal data may be transmitted to the respective service and stored there. In most cases, this is your IP address, through which your approximate position can also be determined. In addition to the IP address, data such as search terms entered and latitude and longitude coordinates are also stored. If you enter an address for route planning, for example, this data is also stored. The data is not stored by us, but on the servers of the integrated tools. You can imagine it like this: You are on our website, but when you interact with a map service, this interaction actually happens on their website. In order for the service to work properly, at least one cookie is usually set in your browser as well. Google Maps, for example, also uses cookies to record user behavior in order to optimize its own service and serve personalized advertising. You can learn more about cookies in our “Cookies” section.
How long and where is the data stored?
Each online map service processes different user data. If we have further information, we will inform you about the duration of data processing below in the corresponding sections on the individual tools. As a general rule, personal data is only ever retained for as long as is necessary for the provision of the service. Google Maps, for example, stores certain data for a fixed period of time, while you must delete other data yourself. With Mapbox, for example, the IP address is stored for 30 days and then deleted. As you can see, each tool stores data for different lengths of time. We therefore recommend that you take a close look at the privacy statements of the tools used.
The providers also use cookies to store data about your user behavior with the map service. You can find more general information about cookies in our “Cookies” section, but you can also find out which cookies may be used in the privacy texts of the individual providers. In most cases, however, this is only an exemplary list and is not complete.
Right of objection
You always have the possibility and also the right to access your personal data and also to object to the use and processing. You can also revoke the consent you have given us at any time. Usually, the easiest way to do this is via the cookie consent tool. However, there are also other opt-out tools that you can use. Possible cookies set by the providers used, you can also manage, delete or deactivate yourself with a few mouse clicks. It may then allergings happen that some functions of the service no longer work as usual. How you manage cookies in your browser also depends on the browser you use. In the section “Cookies” you will also find links to the instructions of the most important browsers.
Legal basis
If you have consented to the use of an online map service, the legal basis for the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a DSGVO (consent), this consent constitutes the legal basis for the processing of personal data as it may occur when collected by an online map service.
We also have a legitimate interest in using an online map service to optimize our service on our website. The corresponding legal basis for this is Art. 6 para. 1 lit. f DSGVO (Legitimate Interests). However, we only ever use an online map service if you have given your consent. We definitely want to have this stated again at this point. Information on special online map services – if available – is provided in the following sections.
Google Maps Privacy Policy
Google Maps Privacy Policy Summary
👥 Data subjects: Visitors to the website
🤝 Purpose: Optimization of our service performance
📓 Processed data: Data such as search terms entered, your IP address and also latitude or longitude coordinates.
More details can be found below in this privacy policy.
📅 Storage period: depending on the stored data
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (consent), Art. 6 para. 1 lit. f DSGVO (legitimate interests).
What is Google Maps?
We use Google Maps of the company Google Inc. on our website. For the European area the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. Google Maps allows us to better show you locations and thus adapt our service to your needs. By using Google Maps, data is transmitted to Google and stored on Google servers. Here we will now go into more detail about what Google Maps is, why we use this Google service, what data is stored and how you can prevent this.
Google Maps is an Internet mapping service from the Google company. With Google Maps, you can search for exact locations of cities, landmarks, accommodations, or businesses online using a PC, tablet, or app. If companies are represented on Google My Business, other information about the company is displayed in addition to the location. To show how to get there, map sections of a location can be embedded in a website using HTML code. Google Maps shows the earth’s surface as a street map or as an aerial or satellite image. Thanks to the Street View images and the high-quality satellite images, very accurate representations are possible.
Why do we use Google Maps on our website?
All our efforts on this site are aimed at providing you with a useful and meaningful time on our website. By integrating Google Maps we can provide you with the most important information about various locations. You can see at a glance where we are located. The directions always show you the best or fastest way to us. You can get the directions for routes by car, by public transport, on foot or by bike. For us, providing Google Maps is part of our customer service.
What data is stored by Google Maps?
In order for Google Maps to fully offer its service, the company must record and store data from you. This includes the search terms entered, your IP address and also the latitude and longitude coordinates. If you use the route planner function, the start address entered is also stored. However, this data storage happens on the websites of Google Maps. We can only inform you about this, but have no influence. Since we have integrated Google Maps into our website, Google sets at least one cookie (name: NID) in your browser. This cookie stores data about your user behavior. Google uses this data primarily to optimize its own services and to provide individual, personalized advertising for you.
The following cookie is set in your browser due to the integration of Google Maps:
Name: NID
Value: 188=h26c1Ktha7fCQTx8rXgLyATyITJ312099147-5
Purpose: NID is used by Google to customize ads to your Google searches. With the help of the cookie, Google “remembers” your most frequently entered search queries or your previous interaction with ads. This way, you will always get tailored ads. The cookie contains a unique ID that Google uses to collect your personal preferences for advertising purposes.
Expiration date: after 6 months
Note: We cannot guarantee the completeness of the stored data. Especially when using cookies, changes can never be ruled out. In order to identify the cookie NID, a separate test page was created, where only Google Maps was integrated.
How long and where is the data stored?
Google servers are located in data centers around the world. However, most servers are located in America. For this reason, your data is also increasingly stored in the USA. Here you can read exactly where the Google data centers are located: https://www.google.com/about/datacenters/locations/?hl=de
Google distributes the data on different data carriers. This means that the data can be retrieved more quickly and is better protected against any attempts at manipulation. Each data center also has special emergency programs. If, for example, there are problems with Google’s hardware or a natural disaster paralyzes the servers, the data will pretty much remain protected anyway.
Google stores some data for a set period of time. For other data, Google only offers the option to delete it manually. Furthermore, the company also anonymizes information (such as advertising data) in server logs by deleting part of the IP address and cookie information after 9 and 18 months, respectively.
How can I delete my data or prevent data storage?
With the automatic deletion of location and activity data introduced in 2019, location and web/app activity information will be stored for either 3 or 18 months – depending on your decision – and then deleted. In addition, you can also manually delete this data from your history at any time via your Google account. If you want to completely prevent your location tracking, you need to pause the “Web and App Activity” section in Google Account. Click “Data and personalization” and then click the “Activity setting” option. Here you can turn the activities on or off.
In your browser, you can also disable, delete or manage individual cookies. Depending on which browser you use, this always works slightly differently. Under the section “Cookies” you will find the corresponding links to the respective instructions of the most popular browsers.
If you do not want to have cookies in principle, you can set up your browser so that it always informs you when a cookie is to be set. This way, you can decide for each individual cookie whether you allow it or not.
Legal basis
If you have consented to Google Maps being used, the legal basis for the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a DSGVO (consent), this consent constitutes the legal basis for the processing of personal data as it may occur during the collection by Google Maps.
We also have a legitimate interest in using Google Maps to optimize our online service. The corresponding legal basis for this is Art. 6 para. 1 lit. f DSGVO (Legitimate Interests). Nevertheless, we only use Google Maps if you have given your consent.
Google also processes data from you in the USA, among other places. We would like to point out that according to the opinion of the European Court of Justice, there is currently no adequate level of protection for the transfer of data to the USA. This may be associated with various risks for the legality and security of data processing.
Google uses so-called standard contractual clauses (= Art. 46. para. 2 and 3 DSGVO) as the basis for data processing for recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway, i.e. in particular in the USA) or a data transfer there. Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through these clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the US. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which reference the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.
If you would like to learn more about Google’s data processing, we recommend that you read the company’s in-house privacy policy at https://policies.google.com/privacy?hl=de.
All texts are protected by copyright.