Information in accordance with Section 5 of the German Telemedia Act (TMG):
nD-enerserve GmbH
Max-von-Laue-Str. 19
30966 Hemmingen
Commercial Register: HRB 213079
Registering court: Hanover Local Court
Represented by:
Jens Ramhorst
Clemens Koebe
Contact:
Phone: +49 511 47 30 81 45
Mail: info@enerserve.eu
Register entry:
Entry in the Commercial Register.
Registering court: Hanover Local Court
Registration number: HRB 213079
VAT number:
VAT registration number in accordance with Section 27a of the Value Added Tax Act:
DE303591409
Dispute resolution
The European Commission provides an online dispute resolution (ODR) platform: https://ec.europa.eu/consumers/odr
You can find our email address at the top of the legal notice.
We participate in dispute resolution proceedings before a consumer arbitration board. The competent body is
the Universal Arbitration Board of the Centre for Arbitration e.V., Straßburger Straße 8, 77694 Kehl am
Rhein (https://www.verbraucher-schlichter.de).
Single point of contact under the Digital Services Act (DSA)
(Regulation (EU) 2022/2065)
You can contact our central point of contact for users and public authorities under Sections 11 and 12 of the DSA as follows:
Email: info@enerserve.eu
Telephone: 0511-47308145
The languages available for contact are: German, English.
Liability for content
As a service provider, we are responsible for our own content on these pages in accordance with Section 7(1) of the German Telemedia Act (TMG) and general legislation. However, pursuant to Sections 8 to 10 of the TMG, we are not obliged, as a service provider, to monitor third-party information that is transmitted or stored, or to investigate circumstances that might indicate illegal activity.
This does not affect any obligations to remove or block access to information under general law. However, liability in this regard only arises from the moment we become aware of a specific infringement. Should we become aware of any such infringements, we will remove the content in question immediately.
Liability for links
Our website contains links to external third-party websites over whose content we have no control. We therefore cannot accept any liability for this external content. The respective provider or operator of the linked sites is always responsible for their content. The linked sites were checked for any potential legal violations at the time the links were created. No illegal content was apparent at the time the links were created.
However, it is not reasonable to expect us to monitor the content of linked websites on an ongoing basis without specific evidence of a legal infringement. Should we become aware of any such infringements, we will remove the relevant links immediately.
Copyright
The content and works on these pages created by the website operators are subject to German copyright law. The reproduction, adaptation, distribution and any form of use beyond the scope of copyright law require the written consent of the respective author or creator. Downloads and copies of this website are permitted for private, non-commercial use only.
Where the content on this site has not been created by the operator, the copyright of third parties is respected. In particular, third-party content is identified as such. Should you nevertheless become aware of any copyright infringement, please notify us accordingly. Upon becoming aware of any infringements, we will remove such content immediately.
Source: e-recht24.de
Privacy Policy
We are delighted that you are interested in our organisation. The protection of your personal data is of particular importance to our management. You can use our websites without disclosing any personal data to us. However, if you wish to make use of more specific services via our websites, other online platforms, applications and social media pages, we may need to process your personal data. If we wish to process data about you and cannot rely on any other legal basis, we will always ask for your consent first (e.g. via a cookie banner).
We always comply with the applicable data protection laws when processing your personal data (such as your name, address, email address or telephone number). This privacy policy explains what data we process. It also sets out the rights you have as a data subject.
We have implemented a range of technical and organisational measures to protect your data on our websites as effectively as possible. Nevertheless, there are always risks associated with the internet, and it is not possible to provide complete protection. Therefore, if you prefer, you can also provide us with your personal data by other means, such as by telephone.
This privacy policy is not only intended to fulfil the obligations under the GDPR and to comply with the laws of the Member States of the European Union (EU) and the European Economic Area (EEA). This privacy policy is also intended to ensure compliance with legislation such as the UK GDPR, the Swiss Federal Act on Data Protection and the Swiss Data Protection Ordinance (DSG, DSV), the California Consumer Privacy Act (CCPA/CPRA), China’s Personal Information Protection Law (PIPL), the Delaware Personal Data Privacy Act (DPDPA), the Tennessee Information Protection Act (TIPA), the Minnesota Consumer Data Privacy Act (MCDPA), the Iowa Act Relating to Consumer Data Protection (ICDPA), the Maryland Online Data Privacy Act (MODPA), the Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations, and shall be interpreted accordingly. The following privacy policy shall be interpreted for each country, state or province in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or province.
To improve readability, we have chosen not to use gender-specific terms (male, female, diverse and other gender identities) on our website, in our publications, in our communications and in our privacy policy. All wording used applies equally to all genders.
If you have any suggestions for improving the text of this privacy policy, or if you require an external data protection officer, please contact the author of the text: Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. (mult.), M.L.E..
1. Definitions
In our privacy policy, we use specific terms from various data protection laws. We want our policy to be easy to understand, so we have provided definitions of these terms below.
The following definitions are based, where applicable, on the case law of the General Court of the European Union (GCEU), the Court of Justice of the European Union (CJEU), the Swiss Federal Supreme Court (BGE), the Supreme Court of the United Kingdom (UKSC), or in accordance with national data protection laws or the case law of a state or federal state, including but not limited to California, including judicial precedent, including under common law, if this is necessary for the application of the law in a specific case.
In this privacy policy, we use the following terms, amongst others:
a) personal data
Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the ‘data subject’ where applicable). A natural person is considered to be identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more special characteristics that express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection laws or the national case law of a state or federal state, including judicial precedent, including under common law.
b) data subject
A data subject is any identified or identifiable natural person whose personal data is processed by the controller, a processor, an international organisation or another recipient of the data, and any person who must be regarded as such under national data protection laws or the national case law of a state or federal state, including judicial precedent, including under common law.
c) Processing
Processing means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution or any other form of making available, alignment or combination, restriction, erasure or destruction.
d) Restriction of processing
Restriction of processing refers to the marking of stored personal data with the aim of limiting its future processing.
e) Profiling
Profiling means any form of automated processing of personal data consisting of the use of such data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
f) Pseudonymisation
Pseudonymisation is the processing of personal data in such a way that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.
g) Responsible person
The controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of processing are determined by Union law or the law of the Member States, the controller or the specific criteria for its designation may be provided for by Union law or the law of the Member States.
h) Data processor
A data processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the data controller.
i) Empfänger
A recipient is a natural or legal person, public authority, agency or other body to whom personal data are disclosed, regardless of whether or not they are a third party. However, public authorities which may receive personal data in the course of a specific investigation mandate under Union law or the law of the Member States are not considered to be recipients.
j) Third party
A third party is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or the processor, are authorised to process the personal data.
k) Consent
Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, expressed in the form of a statement or by a clear affirmative action, by which the data subject indicates that they agree to the processing of their personal data.
2. Name and address of the data controller
The data controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, UK data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection laws (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and other provisions relating to data protection, is:
nD-enerserve GmbH
Max-von-Laue-Str. 19
30966 Hemmingen
Tel.: 051147308145
Mail: info@enerserve.eu
Website: www.enerserve.eu
3. Collection of general data and information
Whenever a data subject or an automated system accesses our websites, our websites collect a range of general data and information. This general data and information is stored in the log files of the relevant server. The data collected may include, amongst other things, (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our websites (so-called referrer), (4) the sub-websites accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an Internet Protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems.
We do not use this general data and information to draw any conclusions about the data subject. Rather, this information is required in order to (1) deliver the content of our websites correctly, (2) optimise the content of our websites and the advertising on them, (3) ensure the ongoing functionality of our IT systems and the technology of our websites, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber attack. We therefore evaluate this anonymously collected data and information both statistically and with the aim of enhancing data protection and data security within our company, ultimately to ensure an optimal level of protection for the personal data we process. The data from the server log files is stored separately from any personal data provided by a data subject.
The purpose of the processing is to prevent threats and ensure IT security, as well as the purposes mentioned above. The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest is, in particular, the protection of our IT systems. The log files are deleted once the stated purposes have been achieved.
4. Contacting us via the website and other data transfers, and your consent
Our websites contain information that enables you to contact our company quickly by electronic means and to communicate with us directly; this includes a general email address and, where applicable, a telephone number. If a data subject contacts us by email, via a contact form, via an input form or by other means, the personal data transmitted by the data subject is automatically stored. Such personal data, transmitted to us by a data subject on a voluntary basis, is processed for the purposes of processing the enquiry or contacting the data subject.
We seek your consent for the transmission, storage and processing of your contact details and enquiries, and for contacting you, in accordance with Article 6(1)(a) of the GDPR and Article 49(1)(a) of the GDPR, as follows:
By submitting your personal data, you voluntarily consent to the processing of the personal data you have entered or submitted for the purposes of handling your enquiry and contacting you. By submitting your data to us, you also voluntarily give your explicit consent in accordance with Article 49(1) (1)(a) of the GDPR to data transfers to third countries to and by the companies and for the purposes specified in this privacy policy, in particular for such transfers to third countries for which an EU/EEA adequacy decision exists or does not exist, as well as to companies or other bodies that are not covered by an existing adequacy decision on the basis of self-certification or other accession criteria, and where or for which there are significant risks and no suitable safeguards for the protection of your personal data (e.g. due to Section 702 of the FISA, Executive Order EO12333 and the Cloud Act in the USA).
When you gave your voluntary and explicit consent, you were aware that third countries may not provide an adequate level of data protection and that your data subject rights may not be enforceable in such cases. You may withdraw your consent under data protection law at any time with effect for the future. Withdrawing your consent does not affect the lawfulness of any processing carried out on the basis of that consent prior to its withdrawal. By a single action (entering and submitting), you are giving several consents. These include consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and Telemedia Act, and other international legislation, which are required, amongst other things, as a legal basis for any planned further processing of your personal data. By your action, you also confirm that you have read and taken note of this privacy policy.
5. Routine erasure and restriction of personal data
We process and store personal data for the period necessary to fulfil the purpose of the processing, or where this is required by European legislation or regulations, or by other legislation or regulations to which we are subject, or for as long as there is a legal basis for the processing.
If the purpose of the processing ceases to apply, or if a retention period prescribed by European legislation or regulations or by another competent legislative body expires, or if the legal basis for the processing ceases to apply, the personal data will be restricted or erased as a matter of routine and in accordance with the statutory provisions.
6. Rights of the data subject under the GDPR
a) Right to confirmation
Every data subject has the right to request confirmation from the controller as to whether personal data concerning them is being processed.
Möchte eine betroffene Person dieses Recht in Anspruch nehmen, kann sie sich hierzu jederzeit an uns wenden.
b) Right of access
Every data subject has the right to obtain, at any time and free of charge, information from the controller regarding the personal data held about them, as well as a copy of that data. Furthermore, the European legislator has granted data subjects the right to access the following information:
• the purposes of processing,
• the categories of personal data that are processed,
• the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular where recipients are in third countries or are international organisations,
• where possible, the envisaged period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period,
• the existence of a right to have personal data concerning them rectified or erased, or to have the processing restricted by the controller, or a right to object to such processing,
• the existence of a right to lodge a complaint with a supervisory authority,
• where the personal data are not collected from the data subject: all available information regarding the origin of the data,
• the existence of automated decision-making, including profiling, in accordance with Article 22(1) and (4) of the GDPR and — at least in such cases — meaningful information about the logic involved, as well as the significance and the intended consequences of such processing for the data subject.
Furthermore, the data subject has the right to be informed as to whether personal data has been transferred to a third country or to an international organisation. If this is the case, the data subject is also entitled to be informed of the appropriate safeguards relating to the transfer.
Möchte eine betroffene Person dieses Recht in Anspruch nehmen, kann sie sich hierzu jederzeit an uns wenden.
c) Right to rectification
Every data subject has the right to request the immediate rectification of inaccurate personal data concerning them. Furthermore, the data subject has the right to request that incomplete personal data be completed, taking into account the purposes of the processing, including by means of a supplementary statement.
Möchte eine betroffene Person dieses Recht in Anspruch nehmen, kann sie sich hierzu jederzeit an uns wenden.
d) Right to erasure (right to be forgotten)
Every data subject has the right to request that the controller erases personal data relating to them without delay, provided that one of the following grounds applies and provided that the processing is not necessary:
• The personal data was collected or otherwise processed for purposes for which it is no longer necessary.
• The data subject withdraws their consent on which the processing was based pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, and there is no other legal basis for the processing.
• The data subject objects to the processing in accordance with Article 21(1) of the GDPR, and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing in accordance with Article 21(2) of the GDPR.
• The personal data was processed unlawfully.
• The erasure of personal data is necessary for compliance with a legal obligation under Union law or the law of the Member States to which the controller is subject.
• The personal data was collected in connection with the information society services offered, in accordance with Article 8(1) of the GDPR.
If any of the above reasons apply and a data subject wishes to request the erasure of personal data held by us, they may contact us at any time.
Where we have made the personal data public and our organisation, as the controller, is obliged under Article 17(1) of the GDPR to erase the personal data, we shall take reasonable steps, including technical measures, taking into account the available technology and the cost of implementation, to inform other controllers processing the published personal data that the data subject has requested those other controllers to delete all links to that personal data, or copies or replicas of that personal data, insofar as the processing is not necessary.
e) Right to restriction of processing
Every data subject has the right to request that the controller restrict processing if any of the following conditions apply:
• The data subject disputes the accuracy of the personal data, for a period sufficient to enable the controller to verify the accuracy of the personal data.
• The processing is unlawful; the data subject objects to the erasure of the personal data and requests, instead, that the use of the personal data be restricted.
• The controller no longer requires the personal data for the purposes of processing, but the data subject requires it for the establishment, exercise or defence of legal claims.
• The data subject has objected to the processing in accordance with Article 21(1) of the GDPR, and it has not yet been determined whether the controller’s legitimate grounds override those of the data subject.
If any of the above conditions apply and a data subject wishes to request the restriction of personal data held by us, they may contact us at any time.
f) Right to data portability
Every data subject has the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format. They also have the right to transmit this data to another controller without hindrance from the controller to whom the personal data was provided, provided that the processing is based on consent pursuant to Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR or on a contract pursuant to Article 6(1)(b) of the GDPR, and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
Furthermore, when exercising their right to data portability under Article 20(1) of the GDPR, the data subject has the right to have their personal data transmitted directly from one controller to another, provided that this is technically feasible and does not adversely affect the rights and freedoms of others.
Möchte eine betroffene Person dieses Recht in Anspruch nehmen, kann sie sich hierzu jederzeit an uns wenden.
g) Right to object
Every data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them carried out on the basis of Article 6(1)(e) or (f) of the GDPR. This also applies to profiling based on these provisions.
In the event of an objection, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing is necessary for the establishment, exercise or defence of legal claims.
Where we process personal data for the purposes of direct marketing, the data subject has the right to object at any time to the processing of their personal data for such marketing purposes. This also applies to profiling insofar as it is related to such direct marketing. If the data subject objects to us processing their data for direct marketing purposes, we will no longer process their personal data for those purposes.
Furthermore, the data subject has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them that is carried out by us for scientific or historical research purposes or for statistical purposes in accordance with Article 89(1) of the GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.
If a data subject wishes to exercise this right, they may contact us at any time. Furthermore, in connection with the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject is free to exercise their right to object by means of automated procedures using technical specifications.
h) Automated decisions in individual cases, including profiling
Every data subject has the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning them or similarly significantly affects them, unless the decision (1) is necessary for entering into or performing a contract between the data subject and the controller, or (2) is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or (3) is based on the data subject’s explicit consent.
If the decision (1) is necessary for the conclusion or performance of a contract between the data subject and the controller, or (2) is it made with the data subject’s explicit consent, we shall take appropriate measures to safeguard the data subject’s rights and freedoms as well as their legitimate interests, including at least the right to obtain human intervention on the part of the controller, to express their point of view and to contest the decision. (2) is authorised by Union or Member State law to which the controller is subject, and that law provides for appropriate measures to safeguard the data subject’s rights and freedoms and legitimate interests; or (3) is based on the data subject’s explicit consent.
Möchte eine betroffene Person dieses Recht in Anspruch nehmen, kann sie sich hierzu jederzeit an uns wenden.
i) Right to withdraw consent under data protection law
Every data subject has the right to withdraw their consent to the processing of personal data at any time.
Möchte eine betroffene Person dieses Recht in Anspruch nehmen, kann sie sich hierzu jederzeit an uns wenden.
7. General purpose of the processing, categories of data processed and categories of recipients
The general purpose of processing personal data is to handle all matters relating to the data controller, customers, prospective customers, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense), or the data controller’s legal obligations. This general purpose applies unless more specific purposes are stated for a particular processing operation.
The categories of personal data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of personal data are public authorities, external bodies, internal processing, intra-group processing and other bodies.
A list of our data processors and recipients of data in third countries, as well as any international organisations, is either published on our website or can be requested from us free of charge.
8. Legal basis for processing
Article 6(1)(a) of the GDPR serves as the legal basis for processing operations where we obtain consent for a specific purpose of processing. Where the processing of personal data is necessary for the performance of a contract to which the data subject is a party, as is the case, for example, with processing operations necessary for the delivery of goods or the provision of other services or consideration, the processing is based on Article 6(1)(b) of the GDPR. The same applies to processing operations necessary for the implementation of pre-contractual measures, such as in cases of enquiries regarding our products or services. Where we are subject to a legal obligation requiring the processing of personal data, such as for the fulfilment of tax obligations, the processing is based on Article 6(1)(c) of the GDPR.
In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were to be injured on our premises and their name, age, health insurance details or other vital information subsequently had to be disclosed to a doctor, a hospital or other third parties. In such cases, the processing would be based on Article 6(1)(d) of the GDPR.
Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, the legal basis is Article 6(1)(e) of the GDPR.
Ultimately, processing operations may be based on Article 6(1)(f) of the GDPR. This legal basis applies to processing operations not covered by any of the aforementioned legal bases, provided that the processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, unless the interests, fundamental rights and freedoms of the data subject override those interests. We are permitted to carry out such processing operations in particular because they have been specifically mentioned by the European legislator. In this regard, the legislator took the view that a legitimate interest could, for example, be assumed if the data subject is a customer of the controller (Recital 47, second sentence, of the GDPR).
9. Legitimate interests in processing pursued by the controller or a third party, and direct marketing
Where the processing of personal data is based on Article 6(1)(f) of the GDPR, and no more specific legitimate interests are specified, our legitimate interest is the conduct of our business activities for the benefit of our staff and shareholders.
We may send you direct marketing material relating to our own goods or services that are similar to those you have enquired about, ordered or purchased. You may object to receiving direct marketing at any time (e.g. by email). You will not incur any costs other than the standard transmission charges. The processing of personal data for the purposes of direct marketing is based on Article 6(1)(f) of the GDPR. The legitimate interest is direct marketing.
Our news updates and newsletters may also constitute communications for the purposes of direct marketing within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from that Directive, provided that we have obtained your electronic and other contact details in connection with the sale of a service or product, which includes the creation of a free user account, through which you are permitted, amongst other things, to access free content on our websites and publications (newsletters, etc.), provided that we use direct marketing to promote similar products or services, so that direct marketing is also permissible without consent (see ECJ, judgment of 13 November 2025, Case C-654/23). In such cases, you may object to the use of your contact information at any time, free of charge.
10. The period for which personal data is stored
The criterion for the duration of the storage of personal data is the relevant statutory retention period. Where no statutory retention period applies, the criterion is the contractual or internal retention period. Once the period has expired, the relevant data is routinely deleted, provided it is no longer required for the performance or initiation of a contract. This applies in particular to all processing operations for which no more specific criteria have been established.
11. Legal or contractual requirements regarding the provision of personal data; necessity for the conclusion of the contract; the data subject’s obligation to provide personal data; possible consequences of failure to provide such data
We would like to inform you that the provision of personal data is in some cases required by law (e.g. tax regulations) or may also arise from contractual provisions (e.g. details of the contracting party). In some cases, it may be necessary for a data subject to provide us with personal data in order to conclude a contract, which we must then process. For example, the data subject is obliged to provide us with personal data if our organisation enters into a contract with them. Failure to provide the personal data would mean that the contract with the data subject could not be concluded. Before providing personal data, the data subject must contact us. We inform the data subject on a case-by-case basis as to whether the provision of personal data is required by law or contract, or is necessary for the conclusion of the contract; whether there is an obligation to provide the personal data; and what the consequences of not providing the personal data would be.
12. Existence of automated decision-making
As a responsible company, we do not normally use automated decision-making or profiling. Should we, in exceptional cases, use automated decision-making or profiling, we will inform the data subject either separately or via a section in our privacy policy (available here on our website). In such cases, the following applies:
Automated decision-making, including profiling, may take place if this (1) is necessary for the conclusion or performance of a contract between the data subject and us, or (2) is permitted under Union or Member State law to which we are subject, and that law provides for appropriate measures to safeguard the rights and freedoms and legitimate interests of the data subject, or (3) this is done with the data subject’s explicit consent.
In the cases referred to in Article 22(2)(a) and (c) of the GDPR, we will take appropriate measures to safeguard the rights and freedoms as well as the legitimate interests of the data subject. In such cases, you have the right to request that the controller take action, to state your own point of view, and to challenge the decision.
Where applicable, this privacy policy sets out relevant information regarding the logic involved, as well as the scope and intended consequences of such processing for the data subject.
13. Recipients in a third country and appropriate or adequate safeguards, and how to obtain a copy of these or where they are available.
In accordance with Article 46(1) of the GDPR, the controller or a processor may transfer personal data to a third country only if the controller or processor has provided appropriate safeguards and provided that the data subjects have enforceable rights and effective legal remedies. Appropriate safeguards may be provided by standard data protection clauses without the need for specific authorisation from a supervisory authority, Article 46(2)(c) of the GDPR.
Before any personal data is transferred, EU Standard Data Protection Clauses or other appropriate safeguards are agreed with all recipients in third countries, or the transfers are based on adequacy decisions. This ensures that appropriate safeguards, enforceable rights and effective remedies are in place for all processing of personal data. Any data subject may obtain a copy of the standard data protection clauses or adequacy decisions from us. Furthermore, the standard data protection clauses and adequacy decisions are available in the Official Journal of the European Union.
Article 45(3) of the GDPR empowers the European Commission to adopt an implementing act determining that a non-EU country ensures an adequate level of protection. This means a level of protection for personal data that is essentially equivalent to that within the EU. Adequacy decisions mean that personal data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar rules apply to the United Kingdom, Switzerland and a number of other countries.
In all cases where the European Commission, or a government or competent authority of another country, has determined that a third country ensures an adequate level of protection and/or that a valid framework exists (e.g. the EU-U. S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to members of such frameworks (e.g. self-certified organisations) are based exclusively on that organisation’s membership of the relevant framework or on the relevant adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the respective company’s membership of that framework. If we or one of our group companies is established in a third country with an adequate level of protection, all transfers to us or our group company are based exclusively on the relevant adequacy decisions.
Any data subject may obtain a copy of the frameworks from us. The frameworks are also available in the Official Journal of the European Union, in published legislative materials, or on the websites of data protection supervisory authorities or other authorities or institutions.
14. Right to lodge a complaint with a data protection supervisory authority
As the controller, we are obliged to inform the data subject of their right to lodge a complaint with a supervisory authority. This right to lodge a complaint is set out in Article 77(1) of the GDPR. Under this provision, every data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement, without prejudice to any other administrative or judicial remedy, if the data subject considers that the processing of personal data relating to them infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator solely in that it may only be exercised with a single supervisory authority (Recital 141, first sentence, of the GDPR). This provision is intended to prevent duplicate complaints on the same matter by the same data subject. If a data subject wishes to lodge a complaint against us, they are therefore requested to contact only a single supervisory authority.
15. Registration or filling in forms on our website and your consent
You have the option to register on our website by providing personal data and/or filling in forms. The personal data transmitted to us in this process is determined by the specific form used for registration or data entry. The personal data you provide will be processed exclusively for our internal use and for our own purposes. However, we may pass on your personal data to one or more processors, for example to parcel delivery services, who will also use your personal data exclusively for purposes attributable to us as the controller. A transfer may also take place if you have instructed us to do so; the legal basis in this case is Article 6(1)(b) of the GDPR.
When you register or enter data on our website, the IP address assigned by your Internet Service Provider (ISP), as well as the date and time of registration or data entry, may also be stored. This data is stored because it is the only way to prevent misuse of our services, and because, if necessary, this data enables us to investigate criminal offences that have been committed. In this respect, the storage of this data is necessary for our protection. The purpose of this processing is to avert danger, detect misuse and investigate criminal offences, as well as the aforementioned purposes. The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in particular in the protection of our information technology systems and the investigation of criminal offences. This data is not, as a rule, disclosed to third parties, unless there is a legal obligation to do so or the disclosure serves the purposes of criminal prosecution.
The registration, entry and transmission of your personal data also enable us to offer you content or services which, by their very nature, can only be provided to registered users or individuals known to us. You are free to amend the personal data provided during registration at any time or to have it completely deleted from our database. The purposes of processing are the receipt of data by us and the use of your data for further processing, for communication with you, and for the representation or implementation of the registration or the purposes for which the data was entered. The legal basis is your consent pursuant to Article 6(1)(a) of the GDPR and/or Article 49(1)(1)(a) of the GDPR.
By entering and submitting your data, you voluntarily consent to the processing of the personal data you have provided. By entering and submitting your data to us, you also voluntarily give your explicit consent in accordance with Article 49(1) (1)(a) of the GDPR to data transfers to third countries to and by the companies and for the purposes specified in this privacy policy, in particular for such transfers to third countries for which an EU/EEA adequacy decision exists or does not exist, as well as to companies or other bodies that are not covered by an existing adequacy decision on the basis of self-certification or other accession criteria, and where or for which there are significant risks and no suitable safeguards for the protection of your personal data (e.g. due to Section 702 of the FISA, Executive Order EO12333 and the Cloud Act in the USA).
When you gave your voluntary and explicit consent, you were aware that third countries may not provide an adequate level of data protection and that your data subject rights may not be enforceable in such cases. You may withdraw your consent under data protection law at any time with effect for the future. Withdrawing your consent does not affect the lawfulness of any processing carried out on the basis of that consent prior to its withdrawal. By a single action (entering and submitting), you are giving several consents. These include consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and Telemedia Act, and other international legislation, which are required, amongst other things, as a legal basis for any planned further processing of your personal data. By your action, you also confirm that you have read and taken note of this privacy policy.
We will provide any data subject, upon request, with information at any time regarding the personal data we hold about them. Furthermore, we will rectify or erase personal data at the request or upon notification by the data subject, provided that this does not conflict with any statutory retention obligations or other grounds justifying the processing. All our staff are happy to assist you in this regard.
16. Blog and comments section
A blog is a publicly accessible platform where one or more people, known as bloggers or web bloggers, post articles or share their thoughts in what are known as blog posts. On our blog, you can leave individual comments on blog posts where appropriate.
If you post comments on our blog, details of the time the comment was posted and your username (or pseudonym, where applicable) will be stored, published and disseminated alongside the comments. By submitting comments, you enter into a publication agreement with us which grants us, free of charge and irrevocably, all copyright usage rights to which you are entitled and which are valid worldwide. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the processing is therefore Article 6(1)(b) of the GDPR.
The purposes of the processing are to provide a blog with a comments function and to enable users to post comments.
Furthermore, when you submit a comment, the IP address assigned to your internet connection by your internet service provider (ISP) is logged. The IP address is stored for security reasons and in the event that you infringe the rights of third parties or post unlawful content through a comment you have submitted. This personal data is therefore stored in our own interest so that we may, if necessary, exonerate ourselves in the event of a legal infringement. The above purposes constitute the legitimate interests pursued by the controller (Art. 6(1)(f) GDPR). This data is not generally disclosed to third parties, unless there is a legal obligation to do so or the disclosure serves the purposes of criminal prosecution or exculpation.
17. Subscribe to comments
In principle, anyone can subscribe to the comments posted on our blog. In particular, commenters have the option of subscribing to comments posted in response to their own comment on a specific blog post.
For legal reasons, a confirmation email is sent via the double opt-in procedure to the email address initially provided by the data subject when subscribing to comments. This confirmation email serves to verify whether the holder of the email address, as the data subject, has authorised the subscription to comments. The legal basis for sending this double opt-in confirmation email is Article 6(1)(c) of the GDPR, as there is a legal obligation to send comment subscriptions only to recipients who have reconfirmed their consent. The option to subscribe to comments can be cancelled at any time.
The purposes of the processing are to provide a blog with a comments function and to enable users to subscribe to comments. The legal basis for sending these comments is Article 6(1)(b) of the GDPR, on the basis of the contract concluded with us for the transmission of comments.
18. Privacy Policy regarding the use of Google APIs
We use Google APIs to integrate features such as geodata, calendar integration, cloud storage and database access into our applications and services. These application programming interfaces allow us to access user data, device information and system-related services, enabling us, for example, to synchronise appointments, display locations or retrieve cloud content. Personal data may be processed in the course of this processing – in particular when users link Google accounts or data requests are triggered. The data processed includes, amongst other things, name, email address, calendar data or document information, location data, IP address, device type, browser information, times of use, API requests and associated metadata.
Data processing is automated via Google's cloud infrastructure. When API calls are made, our application sends requests to Google servers, which return or update user information. Google processes this data to verify access rights, provide content, and enable features such as synchronization and analytics.
The operator of the service and, therefore, the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is the use of Google APIs. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in the efficient implementation of processes using APIs.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
Further information and the applicable privacy policy are available at https://support.google.com.
19. Privacy Policy Regarding the Use of Google Site Verification
We use the Google Site Verification service to verify our website with Google. This verification is a prerequisite for using other Google services such as Google Search Console, Google Analytics, or Google Ads. As part of the site verification process, a verification token is integrated using various methods (e.g., HTML file, meta tag, DNS record, or Google Tag Manager) to prove ownership of the domain. When using this service, personal data may be processed, particularly in the form of IP addresses, technical access data, and information about the domain, the website, or the Google account used.
Processing is carried out automatically via Google servers. Once verification is complete, ownership of the website is recorded in the verifying user’s Google Account.
The operator of the service and, therefore, the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to provide technical proof of domain ownership in order to activate Google services such as Search Console or Analytics. The processing is based on Article 6(1)(f) of the GDPR. The legitimate interest lies in the use of Google tools, the proper assignment of services to the domain, and the technical protection of accounts against misuse.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Google's current privacy policy, please visit https://policies.google.com/privacy.
20. Privacy Policy Regarding the Use of JavaScript and JavaScript Frameworks
On our website, we use JavaScript or JavaScript frameworks as a client-side programming language or JS framework to dynamically display content and enable interaction within the browser. Among other things, JavaScript enables the display of pop-ups, the loading of dynamic content, the tracking of user behavior, the submission of forms, and communication with third-party providers via APIs. JavaScript is not a standalone software product with an external operating company, but rather a scripting language integrated by default into web browsers that is executed on our websites.
The JavaScript-based source code is hosted on our own IT infrastructure and executed by the web browser. We are the operator of the service.
In addition, as part of our web development, we may use various open-source JavaScript libraries or frameworks, such as Vue.js, Angular.js, or similar projects. These are used to expand the functionality of our website in a structured, modular way, particularly for client-side validation, optimizing user navigation, reducing load times, and asynchronous data processing. To the extent technically possible, we host these components locally on our own IT infrastructure so that no data is transferred to third parties. In certain cases, however, individual components may be integrated via external sources such as Content Delivery Networks (CDNs). This may result in connections being established with third-party servers, during which, in particular, the IP address, technical metadata, or usage parameters are processed.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to enable interactive features, dynamic content, simplified development, client-side validation, and improved user guidance. The processing is based on Article 6(1)(f) of the GDPR. The legitimate interest lies in simplifying the development and provision of a functional and user-friendly website.
Die Kriterien für die Festlegung der Dauer, für die personenbezogene Daten verarbeitet werden, richten sich nach dem jeweiligen Zweck der Interaktion, insbesondere der Dauer der jeweiligen Sitzung oder der Speicherung clientseitiger Informationen (z. B. in Verbindung mit Cookies oder Local Storage). Die Bereitstellung personenbezogener Daten ist für die Nutzung interaktiver Websitefunktionen erforderlich.
21. Privacy Policy Regarding the Use of MySQL
We use MySQL as a relational database management system for the structured storage, organization, and processing of data within our web applications and IT systems. MySQL enables us to manage personal data efficiently by providing the foundation for dynamic website features, user accounts, form processing, database queries, and back-end operations. During operation, personal data may be processed—particularly when users, for example, fill out forms, register or log in, place orders, or interact with database-supported functions. In these cases, information such as name, email address, login credentials, IP address, times of use, or transmitted content is stored within MySQL.
MySQL is not directly responsible for data processing; rather, it provides the infrastructure on which we, as the data controller, store and retrieve data. The actual processing is carried out by our systems, while MySQL is operated as a software solution on our own servers or within hosting services. The application itself does not contain any built-in analytics or tracking features. Access to the database is protected by authentication mechanisms, access restrictions, and encryption techniques to prevent unauthorized access.
The application is installed on our own IT infrastructure or in our hosting environment. We are the operator of the service.
Purposes for which personal data is to be processed, as well as the legal basis for processing: The purpose of processing is the systematic management, storage, and protection of user data, as well as the provision of dynamic features within our web services. The processing is based on Article 6(1)(b) of the GDPR for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures, as well as on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the reliable, secure, and efficient management of data within the scope of our business operations.
The criteria for determining the period for which personal data is processed are statutory or contractual retention periods. The provision of personal data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obligated to provide us with personal data. However, if you do not provide such data, you may not be able to use our services.
For more information and MySQL's current privacy policy, please visit https://www.mysql.com.
22. Privacy Policy Regarding the Use of BootstrapCDN
We use BootstrapCDN to optimize the loading times of our websites and ensure a consistent design. By delivering Bootstrap, a widely used front-end library, via a content delivery network, we can ensure that our websites load quickly and efficiently, leading to an improved user experience. BootstrapCDN also allows us to access the latest versions of Bootstrap without having to manually update them on our servers.
When using BootstrapCDN, data such as the IP addresses of our website users is collected in order to process requests for Bootstrap resources. This information is used to optimize the service and ensure that content is delivered efficiently to end users.
The operator of the service and, therefore, the recipient of the personal data is: Volentio JSD Limited, Northside House, Mount Pleasant, Barnet, EN4 9EB, United Kingdom.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to optimize loading times and improve the user experience on our website. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in the efficient and secure provision of web content.
The company may have entered into one of the EU Standard Contractual Clauses with us. You may request a copy of the applicable safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and BootstrapCDN’s privacy policy, please visit https://www.bootstrapcdn.com.
23. Privacy Policy Regarding the Use of Cloudflare
Cloudflare offers a wide range of services designed to enhance the security, performance, and reliability of websites and web applications. Key features include DDoS protection, a web application firewall, content delivery network services, secure DNS services, and more. By using Cloudflare, we can protect our online presence from cyberattacks, improve our website’s loading speed, and ensure the overall availability of our services.
When using Cloudflare services, data such as IP addresses, system configurations, and network traffic information is processed. This information is necessary to defend against threats, optimize traffic, and provide insights into website usage.
The operator of the service and, therefore, the recipient of the personal data is: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. For data subjects in the EU and the EEA, Cloudflare Netherlands B.V., Keizersgracht 62, 1015CS Amsterdam, Netherlands, acts as the contact person and representative within the meaning of Art. 27 of the GDPR. The representative under UK national law is: Cloudflare, Ltd., County Hall/The Riverside Building, Belvedere Road, London, SE1 7PB, United Kingdom.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to use services to secure and optimize websites and web applications. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in ensuring the security, performance, and reliability of our online presence.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Cloudflare, Inc.'s privacy policy, please visit https://www.cloudflare.com.
24. Privacy Policy Regarding the Use of Google Gstatic
We use content provided by Google via the domain www.gstatic.com to ensure the technical efficiency of our website. Gstatic is a static content delivery domain through which Google loads various files, such as JavaScript libraries, stylesheets, framework components, and media content. The purpose of this service is to reduce loading times, increase stability, and deliver recurring content via a high-performance infrastructure. When accessing resources integrated via Gstatic, personal data may be processed—in particular, technical connection data. Among other things, IP addresses, device type, browser information, operating system, requested file, language settings, timestamps, and, if applicable, referrer URLs are processed.
Data processing is performed automatically via Google's servers as soon as a user visits our website and an element (e.g., a script or a library) is retrieved from Gstatic.
The operator of the service and, therefore, the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data is to be processed, as well as the legal basis for processing: The purpose of processing is the efficient delivery of static content on our website via a global content delivery network. The processing is based on Article 6(1)(f) of the GDPR. The legitimate interest lies in reducing server load, improving loading speed, ensuring the error-free technical display of website content, and ensuring a stable user experience.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law nor by contract, nor is it necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Google's current privacy policy, please visit https://policies.google.com/privacy.
25. Privacy Policy Regarding the Use of Font Awesome
Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome allows for easy integration of icons via CSS, JavaScript, or web fonts. The platform offers both free and Pro versions, which provide access to a wider variety of icons and additional features.
When using Font Awesome, personal data such as IP addresses and usage data may be processed, particularly when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, handle support requests, and ensure the security of the platform.
The operator of the service and, therefore, the recipient of the personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to use the Icon Toolkit and the associated services. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in optimizing the user experience and efficiently providing an appealing website.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and Font Awesome’s privacy policy, please visit https://fontawesome.com.
26. Privacy Policy Regarding the Use of Google Fonts
Google Fonts is a free service provided by Google LLC that offers web developers a wide range of fonts to enhance the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that text on their websites is displayed consistently and as intended across different devices and browsers. Google Fonts is hosted on Google’s servers, ensuring high availability and fast loading times.
When using Google Fonts, personal data such as IP addresses and browser information may be processed, as a request is sent to Google's servers when the fonts are loaded. This data is used to provide the service, optimize performance, and prevent misuse.
The operator of the service and, therefore, the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to use and optimize the font service for web developers and end users. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in improving the user experience on websites by providing a wide variety of fonts and ensuring fast loading times.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Google Fonts' privacy policy, please visit https://policies.google.com/privacy.
27. Privacy Policy Regarding the Use of Google Maps
Google Maps is a comprehensive mapping and navigation service provided by Google LLC that allows users to view maps, plan routes, and find local businesses and services. By providing detailed geographic information, Google Maps helps people around the world find their way and navigate their daily lives. The service offers features such as satellite imagery, street views, real-time traffic conditions, and the ability to rate and review places.
When using Google Maps, personal data such as location data, search queries, and usage statistics are processed. This information is necessary to provide and use the service, offer personalized recommendations, and improve the user experience.
The operator of the service and, therefore, the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to use and optimize the mapping and navigation service. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in the provision and use of an efficient, user-friendly, and accurate navigation service.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Google Maps' privacy policy, please visit https://policies.google.com/privacy.
28. Privacy Policy Regarding the Use of jQuery
jQuery is a widely used JavaScript library that web developers use to simplify and speed up HTML document management, event handling, animation, and Ajax interactions. We use jQuery on our website to create a smoother and more interactive user experience. When you visit our website, jQuery may be used to collect certain data, such as information about user behavior and interactions on the page.
This data processing is indirect and is primarily aimed at improving website performance and user-friendliness. jQuery itself, as a client-side library, does not store or process personal data on its own servers. jQuery runs in the user’s browser and can be used for dynamic content updates, which may involve transmitting data to external servers. The use of jQuery on our website is intended to create a smoother and more interactive user experience. When you visit our website, jQuery may be used to collect certain data, such as information about user behavior and interactions on the site.
The operator of the service and, therefore, the recipient of the personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of using jQuery is to improve the user experience on our website by providing an efficient interactive experience. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in the provision and use of a functional, user-friendly, and visually appealing website.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
The jQuery Privacy Policy is available at https://jquery.com/.
29. Privacy Policy Regarding the Use of Google Analytics
Google Analytics is a tool provided by Google LLC that offers website and app operators detailed statistics on traffic and user behavior. It enables the collection and analysis of data on website visits, user interactions, and conversion rates, helping operators understand and optimize their online presence. Google Analytics uses cookies to collect information about user behavior, including page views, time spent on the site, and the paths users take on the website.
When using Google Analytics, personal data such as IP addresses, browser information, and interaction data is processed. This data helps website operators measure their website’s performance, improve the user experience, and develop targeted marketing strategies.
The operator of the service and, therefore, the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to analyze and optimize websites and apps, as well as for advertising. The processing is based on Article 6(1)(f) of the GDPR, where the legitimate interest lies in improving the website, enhancing user-friendliness, and increasing the effectiveness of online marketing.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Google Analytics' privacy policy, please visit https://policies.google.com/privacy.
30. Privacy Policy Regarding the Use of Google Ads
Google Ads, früher bekannt als Google AdWords, ist ein Online-Werbeprogramm der Google LLC, das Unternehmen ermöglicht, gezielte Werbeanzeigen zu schalten, um ihre Sichtbarkeit im Internet zu erhöhen. Google Ads bietet verschiedene Werbeformate, einschließlich Suchanzeigen, Displayanzeigen, YouTube-Videoanzeigen und mehr, die es Unternehmen erlauben, potenzielle Kunden auf Google-Suchergebnisseiten, Partnerwebsites und anderen Plattformen im Google-Netzwerk zu erreichen.
When using Google Ads, personal data such as IP addresses, cookies, and other identifiers derived from interactions with ads are processed. This data helps measure the effectiveness of advertising campaigns, precisely target audiences, and personalize ads based on users’ interests and behavior.
The operator of the service and, therefore, the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the personal data is to be processed, as well as the legal basis for the processing: The purpose of the processing is to analyze and optimize online advertising campaigns. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in the effective design and delivery of advertising campaigns that are relevant to both advertisers and users.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Google Ads' current privacy policy, please visit https://policies.google.com/privacy.
31. Privacy Policy Regarding the Use of the Fonts Plugin | Google Fonts Typography
Fonts Plugin | Google Fonts Typography is a WordPress plugin that gives users access to an extensive library of Google Fonts and makes it easy to integrate these fonts into their websites. With this plugin, users can customize the appearance of their website by choosing from a wide variety of fonts that are directly integrated into their site. While the plugin does not store any personal data, the use of the Google Fonts API may result in the transmission of data such as IP addresses to Google.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of using the Fonts Plugin | Google Fonts Typography is to utilize a wide selection of fonts to enhance the visual design of websites. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in improving the aesthetic quality and user-friendliness of the website.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, functionality, or the plugin.
For more information about the Fonts Plugin | Google Fonts Typography, visit WordPress.org.
32. Privacy Policy Regarding the Use of Advanced Google reCAPTCHA
Advanced Google reCAPTCHA is a WordPress plugin that provides an additional layer of security for websites by integrating Google's reCAPTCHA technology. The tool protects websites from spam and abuse by automating the process of verifying that a human user—not a bot—is interacting with the site. It is commonly used in forms, comment sections, and during registration processes.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of using Advanced Google reCAPTCHA is to protect websites from automated abuse and to improve overall security. The processing is based on Article 6(1)(f) of the GDPR, where the legitimate interest lies in securing the website and ensuring the integrity of user interactions.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, functionality, or the plugin.
Further information about Advanced Google reCAPTCHA is available on WordPress.org.
33. Privacy Policy Regarding the Use of Akismet Anti-Spam
Akismet Anti-Spam is a WordPress plugin designed to detect and filter spam in comments and contact forms. The tool compares submitted comments and form data against a global database of known spam characteristics to identify and block unwanted or malicious content. Akismet processes data such as IP addresses, user agents, the URL of the page being commented on, the commenter’s name, the email address, and the actual text content of the comment.
The operator of the service and, therefore, the recipient of the personal data is: Automattic Inc., 60 29th Street 343, San Francisco, CA 94110, USA. For data subjects in the EU and the EEA, Aut O’Mattic A8C Ireland Ltd., Grand Canal Dock, 25 Herbert Pl, Dublin, D02 AY86, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of using Akismet Anti-Spam is to prevent and reduce spam on WordPress-based websites. The processing is based on Article 6(1)(f) of the GDPR. The legitimate interest lies in protecting the website and its users from spam and abuse, as well as in maintaining the quality of the content published on the website.
Die Betreibergesellschaft des Dienstes sitzt in einem Drittland, nämlich in den USA. Übermittlungen in Drittländer können auf dem Abschluss von Standardvertragsklauseln oder auf sonstigen geeigneten oder angemessenen Garantien die in Art. 46 (2) DS-GVO genannt sind, beruhen. Die Betreibergesellschaft des Dienstes hat gegebenenfalls einen der EU-Standardverträge mit uns abgeschlossen. Eine Kopie der geeigneten oder angemessenen Garantien können Sie bei uns anfordern.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, functionality, or the plugin.
For more information and to view Akismet’s privacy policy, please visit https://akismet.com.
34. Privacy Policy Regarding the Use of All-in-One WP Migration
All-in-One WP Migration is a WordPress plugin designed to simplify website migration. It allows users to export and import their WordPress database, media, plugins, and themes from one website to another. The plugin handles all website content, including personal data stored in posts, pages, user profiles, and other areas of WordPress.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of using All-in-One WP Migration is to assist with website migration in order to ensure a seamless transition and efficient data restoration. The processing is based on Article 6(1)(f) of the GDPR. The legitimate interest lies in facilitating the technical management of web content and ensuring the continuity of digital presences.
For more information about All-in-One WP Migration, visit https://servmask.com/.
35. Privacy Policy Regarding the Use of SpeedyCache – Cache, Optimization, Performance
SpeedyCache is a WordPress plugin that improves website performance using caching techniques and optimization features. It helps reduce page load times by storing a static copy of the content and delivering it quickly to visitors. The plugin does not collect or store any personal data from website visitors. However, the static content may contain personal data.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of using SpeedyCache is to improve website performance through efficient caching and optimization of loading times. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in enhancing user-friendliness and the efficient use of website content.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, functionality, or the plugin.
For more information about SpeedyCache, visit WordPress.org.
36. Privacy Policy Regarding the Use of WP Fastest Cache
WP Fastest Cache is a caching plugin for WordPress designed to improve website loading times by generating static HTML pages from dynamic WordPress content. The plugin reduces the need for PHP requests and database queries on the server by providing pre-built pages, which speeds up the website’s overall performance. WP Fastest Cache does not store any personal user data, but it may collect IP addresses and other technical information for cache management and performance optimization purposes.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of using WP Fastest Cache is to optimize website speed through efficient caching. The processing is based on Article 6(1)(f) of the GDPR. The legitimate interest lies in improving the user experience and the efficiency of the website through faster loading times and reduced server load.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, functionality, or the plugin.
For more information about WP Fastest Cache, visit the WordPress plugin repository at WordPress.org.
37. Privacy Policy Regarding the Use of Yoast SEO
Yoast SEO is an SEO plugin for WordPress that helps website owners optimize their content for search engines. It offers a wide range of features, including analyzing content for SEO friendliness, generating XML sitemaps, managing meta tags, and providing recommendations to improve visibility in search engines. Yoast SEO aims to improve website rankings and strengthen users’ online presence.
When using Yoast SEO, the plugin does not directly collect any personal data from website visitors. Instead, the plugin focuses on optimizing website content and technical settings to improve search engine optimization. However, website operators who use Yoast SEO may choose to enable certain features that may collect user data, such as Google Analytics integrations or social media sharing options.
The developer of the application is: Yoast BV, Don Emanuelstraat 3, 6602 GX Wijchen, Netherlands.
The application is installed on our own IT infrastructure. We are the operator of the service.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of data processing is the use of SEO optimization tools. The processing of personal data that may occur through the use of the plugin and related services is based on the user’s consent (Art. 6(1)(a) GDPR) or on our legitimate interest in optimizing our online presence (Art. 6(1)(f) GDPR).
The criteria for determining the period for which personal data is processed are the statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. However, if you do not provide such data, you may not be able to use the services.
For more information and to view Yoast SEO’s privacy policy, visit https://yoast.com.
38. Privacy Policy Regarding the Use of Contact Form 7
Contact Form 7 is a WordPress plugin that allows us to create and manage flexible contact forms. The plugin collects data that users enter into forms, such as names, email addresses, messages, and other specific information needed for communication or to process inquiries. This data is used to process inquiries and respond to user communications.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of using Contact Form 7 is to provide online contact forms through which you can get in touch with us. Processing is based on Article 6(1)(f) of the GDPR. The legitimate interest lies in ensuring efficient and secure communication between users and us.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, functionality, or the plugin.
For more information about Contact Form 7, visit https://contactform7.com.
39. Privacy Policy Regarding the Use of Contact Form 7 Captcha
Contact Form 7 Captcha is an extension plugin for the WordPress plugin Contact Form 7 that provides additional security by integrating a CAPTCHA system. This CAPTCHA feature helps reduce spam submissions and improve the security of form submissions on websites. The plugin processes user interactions with the CAPTCHA but does not store any personal data of website visitors. It serves to confirm that the form submitter is a human and not an automated bot.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which personal data is to be processed, as well as the legal basis for processing: The purpose of using Contact Form 7 Captcha is to ensure that form submissions are made by real users and not by automated systems. The processing is based on Article 6(1)(f) of the GDPR, where the legitimate interest lies in preventing spam and securing the form processes. The plugin processes users’ interactions with the CAPTCHA but does not store any personal data of website visitors. It serves to confirm that the form submitter is a human and not an automated bot.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, functionality, or the plugin.
For more information about Contact Form 7 Captcha, visit WordPress.org.
40. Privacy Policy Regarding the Use of Contact Form 7 – Dynamic Text Extension
Contact Form 7 – Dynamic Text Extension is an extension plugin for the WordPress plugin Contact Form 7. It enables the dynamic insertion of text into form fields based on other values within the page, user input, or external sources. This functionality makes it easier to automatically populate forms with specific data, which is particularly useful for personalized requests and automated processes.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of using Contact Form 7 – Dynamic Text Extension is to enhance the functionality of contact forms by enabling dynamic content. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in improving the user-friendliness and efficiency of online forms.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, functionality, or the plugin.
For more information about Contact Form 7 – Dynamic Text Extension, visit WordPress.org.
41. Privacy Policy Regarding the Use of Duplicate Page
Duplicate Page is a WordPress plugin that allows users to quickly and easily duplicate pages, posts, or custom post types. The duplicated content may contain personal data.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to utilize content management and increase productivity for website administrators and content creators. The processing is based on Article 6(1)(f) of the GDPR. The legitimate interest lies in improving efficiency in the creation and management of web content.
For more information about Duplicate Page, visit the WordPress plugin repository at WordPress.org.
42. Privacy Policy Regarding the Use of Easy Google Fonts
Easy Google Fonts is a WordPress plugin that allows for easy integration of Google Fonts into WordPress themes without the need to edit code. The plugin adds a selection of custom fonts that can be managed via the WordPress Customizer tool, allowing users to easily customize their website’s fonts. While the plugin does not store any personal data, the fonts selected by users may transmit usage data to Google, as the fonts are loaded from Google servers.
The application is installed on our own IT infrastructure. We are the company that operates the service.
Purposes for which personal data will be processed, as well as the legal basis for processing: The purpose of using Easy Google Fonts is to provide website operators with an expanded and user-friendly selection of fonts. The processing is based on Article 6(1)(f) of the GDPR, whereby the legitimate interest lies in improving the aesthetics and user experience of the website through a variety of typography options.
Since the plugin loads fonts from Google servers, IP addresses and font usage data may be transmitted to Google, a company based in the United States. These transfers are based on the data protection mechanisms and standard contractual clauses provided by Google, or other appropriate safeguards, as required by the General Data Protection Regulation.
The criteria for determining the period for which personal data is processed are internal, statutory, or contractual retention periods. The use of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide us with personal data. If you do not provide such data, you may not be able to access or use our services, functionality, or the plugin.
For more information about Easy Google Fonts, visit WordPress.org.
43. Privacy Policy Regarding the Use of Facebook
Facebook is a social network that allows people to connect online, share content, and communicate. Users can create profiles, post photos and videos, exchange messages, and organize themselves into groups. Facebook also provides businesses and organizations with a platform for advertising and interacting with their target audience.
When using Facebook, personal data such as names, email addresses, phone numbers, usage data, location information, and information about shared content is processed. This data is necessary to provide the platform, offer personalized content and advertising, ensure user safety, and develop new services.
The operator of the service and, therefore, the recipient of the personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and the EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent’s Place, London, NW1 3FG, United Kingdom.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to use and improve social networking features and network services. The processing is based on Article 6(1)(b) of the GDPR for the performance of a contract to which the data subject is a party, as well as on Article 6(1)(f) of the GDPR, where the legitimate interest lies in improving the user experience, providing personalized content and advertising, and ensuring the security of the network.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Facebook's current privacy policy, please visit https://facebook.com.
44. Privacy Policy Regarding the Use of Instagram
Instagram is a widely used social media platform that allows users to share photos and videos, post Stories, and interact with followers and friends. Instagram offers a variety of features, including direct messaging, IGTV for longer videos, Instagram Live for real-time broadcasts, and an Explore page for discovering new content and users.
When using Instagram, personal data such as names, email addresses, phone numbers, user-generated content (photos, videos, comments, etc.), location data, usage information, and, in some cases, payment information is processed. This data helps provide the service, ensure the security of the platform, deliver personalized advertising, and improve the user experience.
The operator of the service and, therefore, the recipient of the personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and the EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as the contact point and representative within the meaning of Article 27 of the GDPR. The representative under UK national law is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent’s Place, London, NW1 3FG, United Kingdom.
Purposes for which the personal data is to be processed, as well as the legal basis for the processing: The purpose of the processing is to use and optimize social networking features. The processing is based on Article 6(1)(b) of the GDPR for the performance of a contract to which the data subject is a party, as well as on Article 6 (1)(f) of the GDPR, whereby the legitimate interest lies in improving and personalizing the user experience, providing customer support, and ensuring the security and integrity of the platform, as well as in the use of the platform and marketing.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other appropriate or adequate safeguards as referred to in Article 46(2) of the GDPR. The service provider may be a certified member of one or more data privacy frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obligated to provide personal data to us or to the service provider. However, if you do not provide such data, you may not be able to use our services or those of the service provider.
For more information and to view Instagram's privacy policy, please visit https://instagram.com.
45. Privacy Policy Regarding the Use of DHL
DHL is a logistics and express delivery provider that offers a wide range of services for international and domestic parcel delivery, freight transport, e-commerce solutions, and supply chain management. By using DHL’s services, we can reliably and efficiently ship our products and shipments to customers worldwide, while benefiting from advanced tracking options and utilizing customized logistics solutions.
In providing its services, DHL processes personal data such as names, addresses, contact information for senders and recipients, shipment information, and shipment histories. This data is necessary to provide shipping services, track shipments, handle customs clearance, and ensure an efficient supply chain.
The operator of the service and, therefore, the recipient of the personal data is: DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn, Germany.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is the use of shipping and logistics services. The processing is based on Article 6(1)(b) of the GDPR for the performance of a contract to which the data subject is a party or for the implementation of pre-contractual measures. Additionally, the processing may be based on Article 6(1)(c) of the GDPR with regard to the fulfillment of legal obligations arising from customs and trade law.
The criteria for determining the period for which personal data is processed are the statutory or contractual retention periods. The provision of personal data is required by law or contract, or is necessary for the conclusion of a contract. You are required to provide us with personal data for this processing.
Further information and DHL’s current privacy policy are available at https://www.dhl.de.
46. Privacy Policy Regarding the Use of PayPal
PayPal is a payment service provider that enables us to process payments for our products and services securely and efficiently online. When you use PayPal, personal data such as your name, address, email address, payment information, and transaction data are processed. This data is necessary to authorize payments, verify the buyer’s identity, prevent fraud, and ensure the payment is processed securely. PayPal also uses this information to analyze transactions and improve security measures. Additionally, PayPal helps us optimize the payment process and offer users a convenient payment option.
The operator of the service and, therefore, the recipient of the personal data is: PayPal, Inc., 2211 N. First Street, San Jose, CA 95131, USA. For data subjects in the EU and the EEA, PayPal (Europe) S.à r.l. et Cie., S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg, acts as the contact person and representative within the meaning of Art. 27 of the GDPR. The representative under UK national law is: Bird & Bird GDPR Representative UK, 12 New Fetter Lane, Holborn, London, EC4A 1JP, United Kingdom.
Purposes for which the personal data will be processed, as well as the legal basis for the processing: The purpose of the processing is to process online payments and ensure a secure payment process. The processing is based on Article 6(1)(b) of the GDPR, as it is necessary for the performance of a contract to which the data subject is a party.
The service provider is based in a third country, namely the United States. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards referred to in Article 46(2) of the GDPR. The service provider may have entered into one of the EU standard contractual clauses with us. You may request a copy of the appropriate or adequate safeguards from us.
The criteria for determining the period for which personal data is processed are the contractual relationship between us and the service provider, or statutory or contractual retention periods. The provision of personal data is required by law or contract, or is necessary for the conclusion of a contract. You are required to provide us with personal data for this processing.
For more information and PayPal, Inc.'s current privacy policy, please visit https://www.paypal.com/am/home.
This privacy policy was created using a generator developed through a collaboration between online legal experts, data protection consultants, and the ISO 42001 certification body.