With the following Privacy Policy, we would like to inform about the types of personal data we process (hereinafter also referred to as “data”), the purposes for which we process them, and the extent of such processing.

This Privacy Policy applies to all processing of personal data by us, both in the course of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as “online services”).

The terms used in this Privacy Policy are intended to be gender-neutral and apply equally to all individuals.


Privacy Policy for SECOND OPINION CONSULT AG (in formation)

As of 23rd June 2026

Controller

SECOND OPINION CONSULT AG (in formation)

Representatives: John Korter (CEO),  Johannes Krüger (Authorised Signatory)

E-Mail: sparring@secondopconsult.com
Tel.: +49 (0) 2203 20299 28

Legal notice: https://second-opinion-consult.com/en/impressum

Overview of Processing Activities

The following overview summarizes the categories of data processed, the purposes for which they are processed, and identifies the categories of data subjects concerned.

Categories of Data Processed

  • Master Data (e.g., names, addresses)
  • Content Data (e.g., information entered into online forms)
  • Contact Data (e.g., email addresses, telephone numbers, postal codes)
  • Meta/Communication Data (e.g., device information, IP addresses)
  • Usage Data (e.g., websites visited, interest in content, access times)
  • Contract Data (e.g., subject matter of the contract, contract length, customer category)
  • Payment Data (e.g., bank account details, invoices, payment history)

Categories of Data Subjects

  • Business and Contract Partners
  • Prospective Customers
  • Communication Partners
  • Clients
  • Users (e.g., website visitors, users of online services)
  • Partners / Students / Participants

Purposes of Processing

  • Administrative and Organizational Procedures
  • Direct Marketing (e.g., by email or post)
  • Feedback (e.g., collecting feedback via online forms, surveys)
  • Marketing
  • Contact Requests and Communication
  • Profiles Containing User-Related Information (Creation of User Profiles)
  • Web analytics (e.g., access statistics, recognition of returning visitors)
  • Security Measures
  • Provision of Contractual Services and Customer Support
  • Management and Response to Inquiries

Applicable Legal Bases

The following section provides an overview of the legal bases under the General Data Protection Regulation (GDPR) on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in individual cases, we will inform you of these in this Privacy Policy.

  • Consent (Art. 6(1)(a) GDPR) - The person concerned has given consent to the processing of their personal data for one or more specific purposes.
  • Performance of a Contract and Pre-Contractual Requests (Art. 6(1)(b) GDPR) - Processing is necessary for the fulfillment of a contract to which the person concerned is a party or in order to take steps at the request of the person concerned prior to entering into a contract.
  • Compliance with a Legal Obligation (Art. 6(1)(c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate Interests (Art. 6(1)(f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

National Data Protection Regulations in Germany:

In addition to the data protection provisions of the General Data Protection Regulation (GDPR), national data protection laws apply in Germany. This includes, in particular, the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG), which contains specific provisions regarding the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers, and automated decision-making in individual cases, including profiling. Furthermore, the BDSG regulates the processing of personal data for employment-related purposes (Section 26 BDSG), particularly with regard to the establishment, performance, or termination of employment relationships and the consent of employees. In addition, data protection laws of the individual federal states (Länder) may also apply.

Technical and Organizational Measures

Taking into account the technological state, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection in accordance with applicable legal requirements.

These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to data, as well as access, input, disclosure, availability, and separation of data. Furthermore, we have established procedures to ensure the exercise of data subjects’ rights, the deletion of data, and appropriate responses to data protection incidents. In addition, we take the protection of personal data into account when developing or selecting hardware, software, and processing procedures, in accordance with the principles of data protection by design and data protection by default.

SSL/TLS Encryption (HTTPS): To protect the data transmitted via our online services, we use SSL/TLS encryption. You can recognize an encrypted connection by the https:// prefix in your browser’s address bar.

Transfer of Personal Data

As part of our processing of personal data, it may be necessary to transfer such data to, or disclose it to, other entities, companies, legally independent organizations, or individuals. Recipients of such data may include, for example, service providers engaged for IT-related services or providers of services and content integrated into our website.

In such cases, we comply with the applicable legal requirements and, in particular, conclude appropriate agreements with the recipients of your data to ensure an adequate level of protection for your personal data.

Use of Cookies

Cookies are text files containing data from visited websites or domains that are stored by a browser on the user's device. A cookie primarily serves to store information about a user during or after their visit to an online service. The information stored may include, for example, language preferences on a website, login status, a shopping cart, or the point at which a video was viewed. The term “cookies” also includes other technologies that perform the same functions as cookies (e.g., when user information is stored using pseudonymous online identifiers, also referred to as “user IDs”).

The following types of cookies and functions are distinguished:

Temporary Cookies (Session Cookies)

Temporary cookies are deleted at the latest when a user leaves an online service and closes their browser.

Permanent Cookies

Permanent cookies remain stored even after the browser has been closed. For example, the login status can be saved, or preferred content can be displayed directly when a user revisits a website. Likewise, user interests may be stored in such cookies for audience measurement or marketing purposes.

First-Party Cookies

First-party cookies are set directly by us.

Third-Party Cookies

Third-party cookies are primarily used by advertisers and other third parties to process user information.

Necessary Cookies

Cookies may be strictly necessary for the operation of a website (e.g., to store login information or other user inputs, or for security purposes).

Analytics, Marketing, and Personalization Cookies

Cookies are also commonly used for web analytics purposes and where a user's interests or behavior (e.g., viewing certain content, using functions, etc.) are stored within a user profile. Such profiles are used, for example, to display content that may be relevant to users' interests. This process is also referred to as “tracking”, i.e., monitoring users’ potential interests. Where we use cookies or tracking technologies, we will inform you separately in this Privacy Policy or when obtaining your consent.

Information on the Legal Basis

The legal basis on which we process your personal data using cookies depends on whether we request your consent. If you consent to the use of cookies, the legal basis for processing your data is your consent pursuant to Art. 6(1)(a) GDPR. Otherwise, data processed through cookies is processed on the basis of our legitimate interests (e.g., in the efficient operation and improvement of our online services) or, where the use of cookies is necessary, for the performance of our contractual obligations.

Storage Period

Unless we provide explicit information regarding the storage period of permanent cookies (e.g., as part of a cookie consent process), please assume that cookies may be stored for up to two years.

General Information on Withdrawal of Consent and Objection (Opt-Out)

Depending on whether processing is based on consent or a legal basis, you have the right at any time to withdraw your consent or object to the processing of your data through cookie technologies (collectively referred to as “opt-out”).

You may initially exercise your objection through your browser settings, for example by disabling the use of cookies (although this may also limit the functionality of our online services). An objection to the use of cookies for online marketing purposes may also be declared through the following websites, particularly in relation to tracking technologies:

In addition, further information on available opt-out options may be found in the descriptions of the service providers and cookies used.

Processing of Cookie Data Based on Consent

We use a cookie consent management system through which users can give, manage, and withdraw their consent to the use of cookies and the processing activities and service providers specified within the consent management system.

The consent declaration is stored in order to avoid repeated requests for consent and to demonstrate compliance with legal obligations. Storage may take place on the server and/or in a cookie (a so-called “opt-in cookie”) or by means of comparable technologies, enabling the consent to be associated with a specific user or device.

Unless specific information is provided by the respective consent management service provider, the following applies: Consent data may be stored for up to two years. A pseudonymous user identifier is created and stored together with the time of consent, details regarding the scope of consent (e.g., which categories of cookies and/or service providers were approved), as well as information about the browser, operating system, and device used.

Processed Data Types

  • Usage Data (e.g., websites visited, interest in content, access times)
  • Meta/Communication Data (e.g., device information, IP addresses)

Categories of Data Subjects

  • Users (e.g., website visitors, users of online services)

Legal Bases

  • Consent (Art. 6(1)(a) GDPR)
  • Legitimate Interests (Art. 6(1)(f) GDPR)

Business Services

We process the data of our contractual and business partners, such as customers and prospective customers (collectively referred to as “Contractual Partners”), within the framework of contractual and similar legal relationships and related measures, as well as in the course of communication with Contractual Partners (including pre-contractual communication), for example, to respond to inquiries.

We process this data to fulfill our contractual obligations, safeguard our rights, carry out the administrative tasks associated with these activities, and support our business organization. Within the scope of applicable law, we disclose Contractual Partners’ data to third parties only where necessary for the aforementioned purposes, to comply with legal obligations, or with the consent of the data subjects (e.g., to telecommunications providers, transportation and logistics providers, subcontractors, banks, tax advisors, legal advisors, payment service providers, or tax authorities).

Contractual Partners will be informed about any further forms of processing, such as processing for marketing purposes, within this Privacy Policy.

We inform Contractual Partners about which data are required for the above purposes before or during data collection, for example through online forms, special markings (e.g., colors or symbols such as asterisks), or direct communication.

We delete data after the expiration of statutory warranty obligations and similar retention periods, generally after four years, unless the data are stored in a customer account or must be retained for legal archiving purposes (e.g., typically ten years for tax-related records). Data disclosed to us by Contractual Partners in connection with an assignment will be deleted in accordance with the terms of the assignment, generally upon completion thereof.

Where we use third-party providers or platforms to deliver our services, the respective terms and conditions and privacy notices of those third-party providers or platforms shall apply in the relationship between users and such providers.

Consulting Services

We process the data of our clients, prospective clients, and other customers or contractual partners (collectively referred to as “Clients”) in order to provide consulting services. The categories of data processed, as well as the scope, purpose, and necessity of such processing, are determined by the underlying contractual relationship with the Client.

Where necessary for the performance of a contract, the protection of vital interests, compliance with legal obligations, or where the Client has provided consent, we may disclose or transfer Client data to third parties or service providers, such as public authorities, subcontractors, or providers of IT, office, or similar services, in compliance with applicable professional and legal requirements.

Publishing Activities

We process the data of our contacts, interview partners, and other individuals who are the subject of our publishing, editorial, journalistic, or related activities.

In this regard, we refer to the protections afforded by freedom of expression and freedom of the press pursuant to Art. 85 GDPR in conjunction with applicable national laws. Processing is carried out for the purpose of fulfilling our professional activities and, in particular, on the basis of the public interest in information and media services.

Business Consulting

We process the data of our customers, clients, prospective customers, and other contractual partners (collectively referred to as “Clients”) in order to provide contractual or pre-contractual services, particularly consulting services.

The categories of data processed, as well as the scope, purposes, and necessity of processing, are determined by the underlying contractual or business relationship.

Where necessary for the performance of a contract, compliance with legal obligations, or where consent has been provided, we may disclose or transfer Customer data to third parties or service providers, such as public authorities, courts, or providers of IT, office, or similar services, in accordance with applicable legal and professional requirements.

Events and Activities

We process the data of participants in events, conferences, seminars, and similar activities organized or hosted by us (collectively referred to as “Participants” and “Events”) in order to facilitate participation and the use of associated services or activities.

Where, in this context, we process health-related data, religious beliefs, political opinions, or other special categories of personal data, such processing takes place where the information has been manifestly made public by the data subject, where processing is necessary for health protection or safety purposes, or where the data subject has provided consent.

Required information is clearly indicated within registration forms, booking processes, or similar contractual arrangements and includes information necessary for the provision of services, invoicing, and communication regarding the Event. Where we gain access to information relating to end customers, employees, or other individuals, we process such information in accordance with applicable legal and contractual requirements.

  • Categories of Data Processed: Master Data (e.g., names, addresses, postal codes); Payment Data (e.g., bank account details, invoices, payment history); Contact Data (e.g., email addresses, telephone numbers); Contract Data (e.g., subject matter of the contract, contract term, customer category); Usage Data (e.g., websites visited, interest in content, access times); Meta/Communication Data (e.g., device information, IP addresses)
     
  • Categories of Data Subjects: Prospective Customers, Business and Contractual Partners, Customers, Clients
     
  • Purposes of Processing: Provision of Contractual Services and Customer Support, Contact Requests and Communication, Administrative and Organizational Procedures, Management and Response to Inquiries, Security Measures
     
  • Legal Base: Performance of a Contract and Pre-Contractual Requests (Art. 6(1)(b) GDPR), Compliance with a Legal Obligation (Art. 6(1)(c) GDPR), Legitimate Interests (Art. 6(1)(f) GDPR)

Blogs and online publishing media

We use blogs or similar means of online communication and publication (hereinafter referred to as the "publication medium"). Reader data is processed only to the extent necessary for the operation and presentation of the publication medium, communication between authors and readers, or for security purposes. For all other aspects, please refer to the information on the processing of visitors' data provided in this Privacy Policy.

Types of data processed:

  • Master data (e.g., names, addresses, postal codes)
  • Contact data (e.g., email addresses, telephone numbers)
  • Content data (e.g., entries in online forms)
  • Usage data (e.g., websites visited, interest in content, access times)
  • Metadata and communication data (e.g., device information, IP addresses)

Data subjects:

  • Users (e.g., website visitors, users of online services)

Purposes of processing:

  • Provision of contractual services and customer support
  • Feedback collection (e.g., gathering feedback through online forms)

Legal bases for processing:

  • Performance of a contract and pre-contractual requests (Article 6(1)(b) GDPR)
  • Legitimate interests (Article 6(1)(f) GDPR)

Registration and Participation (Events, Video Conferences, Online Meetings, Webinars, Livestreams, and Screen Sharing)

We use platforms and applications provided by third parties (hereinafter referred to as “conference platforms”) for the purpose of conducting video and audio conferences, webinars, and other types of video and audio meetings (collectively referred to as “conferences”). When selecting conference platforms and their services, we comply with applicable legal requirements.

Data Processed by Conference Platforms

In connection with participation in a conference, conference platforms process the personal data of participants listed below. The scope of processing depends on the specific conference and the data required for participation (e.g., access credentials or real names), as well as any optional information provided by participants. In addition to processing data for the purpose of conducting the conference, conference platforms may process participant data for security purposes or service improvements.

The processed data may include:

  • Personal information (first name, last name)
  • Contact information (email address, telephone number, postal code)
  • Access data (access codes or passwords)
  • Profile pictures
  • Information regarding professional position or role
  • IP address used to access the internet
  • Information about participants’ devices, operating systems, browsers, and related technical and language settings
  • Information relating to communication content, such as chat messages, audio and video data
  • Data relating to the use of additional functions (e.g., surveys or polls)

Communication content is encrypted to the extent technically provided by the respective conference provider. If participants are registered users of a conference platform, additional data may be processed in accordance with the agreement between the participant and the respective provider.

Sharing of Data with Event Partners

The data collected in connection with registration for or participation in events, webinars, livestreams, meetings, or other online events may be shared with partner companies involved in these events, either in aggregated form or, where applicable, including personal data.

The disclosure of data serves the following purposes:

  • Providing evidence of event performance and audience reach
  • Enabling partner companies to assess interest in event content, both on an aggregated basis and, where applicable, at the level of individual participants

Logging and Recordings

If text entries, participation results (e.g., poll responses), audio recordings, or video recordings are logged or recorded, participants will be informed transparently in advance. Where required by law, participants will be asked to provide their consent before such recordings take place.

Participant Privacy Measures

Please refer to the privacy policies of the respective conference platforms for details regarding the processing of your data. We recommend selecting the security and privacy settings that best meet your needs within the conference platform.

In addition, participants should take appropriate measures to protect personal data and privacy during video conferences, for example by:

  • Informing household members of ongoing recordings
  • Closing doors where appropriate
  • Using background blur or background replacement features where available

Links to conference rooms and access credentials must not be shared with unauthorized third parties.

Information on Legal Bases

Where we process user data in connection with conference platforms and request consent for the use of conference platforms or specific functions (e.g., recording of conferences), the legal basis for processing is the user's consent.

Processing may also be necessary for the performance of contractual obligations (e.g., documentation and follow-up of meeting results).

In all other cases, user data is processed based on our legitimate interests in efficient and secure communication with our business partners and other contacts.

Categories of Data Processed

  • Master data (e.g., names, addresses, postal codes)
  • Contact data (e.g., email addresses, telephone numbers)
  • Content data (e.g., entries in online forms)
  • Usage data (e.g., websites visited, interests, access times)
  • Metadata and communication data (e.g., device information, IP addresses)

Data Subjects

  • Communication partners
  • Users (e.g., website visitors and users of online services)
  • Clients

Purposes of Processing

  • Provision of contractual services and customer support
  • Contact requests and communication
  • Internal office and organizational processes

Legal Bases

  • Consent (Art. 6(1)(a) GDPR)
  • Performance of a contract and pre-contractual measures (Art. 6(1)(b) GDPR)
  • Legitimate interests (Art. 6(1)(f) GDPR)

 

Services and Service Providers Used

Microsoft Teams

Messaging and conferencing software.

Service Provider:
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399, USA

Website:https://products.office.com
Privacy Policy:https://privacy.microsoft.com/en-us/privacystatement
Security Information:https://www.microsoft.com/trust-center

Zoom

Video conferencing, web conferencing, and webinar platform.

Service Provider:
Zoom Video Communications, Inc.
55 Almaden Blvd., Suite 600
San Jose, CA 95113, USA

Website:https://zoom.us
Privacy Policy:https://explore.zoom.us/en/privacy/
Standard Contractual Clauses (SCCs): Available as part of Zoom's Global Data Processing Addendum.

Mailchimp

Email delivery and email marketing platform.

Service Provider:
The Rocket Science Group, LLC (Mailchimp)
675 Ponce De Leon Ave NE #5000
Atlanta, GA 30308, USA

Website:https://mailchimp.com
Privacy Policy:https://mailchimp.com/legal/privacy/
Data Processing Addendum:https://mailchimp.com/legal/data-processing-addendum/
Information on EU-U.S. Data Transfers:https://mailchimp.com/help/mailchimp-european-data-transfers/

Newsletters and Electronic Notifications

We send newsletters, emails, and other electronic notifications (hereinafter referred to collectively as “newsletters”) only with the consent of the recipients or where otherwise permitted by law. Where the content of a newsletter is specifically described during the registration process, such description is decisive for the user’s consent. Otherwise, our newsletters contain information about our company and our services.

To subscribe to our newsletters, it is generally sufficient to provide your E-Mail address. However, we may ask you to provide your name for personalized communication or additional information if required for the purposes of the newsletter.

Double Opt-In Procedure

Subscriptions to our newsletters are generally made using a double opt-in procedure. This means that after signing up, you will receive an E-Mail asking you to confirm your subscription. This confirmation is necessary to prevent unauthorized registrations using another person’s E-Mail address.

Newsletter subscriptions are logged to provide proof of the registration process in accordance with legal requirements. This includes storing the date and time of registration and confirmation, as well as the IP address used. Changes to subscriber data stored by the E-Mail service provider are also logged.

Deletion and Restriction of Processing

We may retain unsubscribed E-Mail addresses for up to three years based on our legitimate interests in demonstrating previously granted consent before deleting them. The processing of such data is limited to the purpose of defending against potential legal claims.

A data subject may request deletion at any time, provided that the previous existence of consent can be confirmed. Where we are legally required to permanently honor objections to processing, we reserve the right to store the E-Mail address solely for this purpose in a suppression list (also referred to as a “blocklist”).

The logging of the subscription process is carried out on the basis of our legitimate interests in documenting the proper and lawful conduct of the registration process. Where we engage a service provider for E-Mail distribution, this is based on our legitimate interests in operating an efficient and secure E-Mail delivery system.

Information on Legal Bases

Newsletters are sent on the basis of the recipient’s consent or, where consent is not required, on the basis of our legitimate interests in direct marketing, provided this is legally permissible (for example, in the case of advertising to existing customers).

If we engage a service provider to send E-Mails, this is done on the basis of our legitimate interests. The registration process is documented on the basis of our legitimate interests in proving compliance with applicable legal requirements.

Newsletter Content

Information about:

Our company, Our services, Promotions and campaigns, Offers and updates

Measurement of Open and Click Rates

Our newsletters contain a so-called “web beacon,” which is a pixel-sized file retrieved from our server, or from the server of our email service provider, when the newsletter is opened.

As part of this retrieval process, technical information is collected, including:

  • Browser information
  • System information
  • IP address
  • Date and time of access

This information is used to improve our newsletters based on technical data, target audiences, and user reading behavior, including information about access locations (which may be determined from the IP address) and access times.

The analysis also includes determining:

  • Whether newsletters are opened
  • When they are opened
  • Which links are clicked

This information is associated with individual newsletter recipients and stored in their profiles until deletion. The evaluations help us understand our users’ reading habits, tailor our content to their interests, and distribute different content according to user preferences.

The measurement of open and click rates, storage of measurement results in user profiles, and any further processing are carried out on the basis of the user’s consent.

Unfortunately, separate withdrawal of consent for performance measurement is not possible. To opt out of tracking, the entire newsletter subscription must be cancelled or objected to. In this case, stored profile information will be deleted.

Requirement for Free Services

Consent to receive newsletters may be required as a condition for the use of certain free services (e.g., access to specific content or participation in promotions).

If users wish to use a free service without subscribing to the newsletter, they may contact us directly.

Categories of Data Processed

  • Master data (e.g., names, addresses, postal codes)
  • Contact data (e.g., E-Mail addresses, telephone numbers)
  • Metadata and communication data (e.g., device information, IP addresses)
  • Usage data (e.g., websites visited, interests, access times)

Data Subjects

  • Communication partners
  • Users (e.g., website visitors and users of online services)

Purposes of Processing

  • Direct marketing (e.g., by E-Mail or postal mail)
  • Provision of contractual services and customer support

Legal Bases

  • Consent (Art. 6(1)(a) GDPR)
  • Legitimate interests (Art. 6(1)(f) GDPR)

Right to Object (Opt-Out)

You may unsubscribe from our newsletter at any time, withdraw your consent, or object to future communications.

An unsubscribe link is included at the End of every newsletter. Alternatively, you may contact us using any of the contact methods provided above, preferably by E-Mail.

Services and Service Providers Used

Mailchimp

E-Mail delivery and E-Mail marketing platform.

Service Provider:
The Rocket Science Group, LLC (“Mailchimp”)
675 Ponce De Leon Ave NE #5000
Atlanta, GA 30308, USA

Website:https://mailchimp.com

Privacy Policy:
https://mailchimp.com/legal/privacy/

Data Processing Addendum (Standard Contractual Clauses):
https://mailchimp.com/legal/data-processing-addendum/

Information on European Data Transfers:
https://mailchimp.com/help/mailchimp-european-data-transfers/

Liability for Content

The content of this newsletter has been prepared with the greatest care and is intended solely for general information purposes. Despite regular review, we do not guarantee the accuracy, completeness, or timeliness of the information provided. Errors, changes, and interim developments remain reserved.

No Legal or Tax Advice

The information contained in this newsletter does not constitute legal, tax, financial, or any other form of professional advice. It does not replace individual assessment and consultation. For binding advice, please contact your legal or tax advisor or our customer support team.

Liability for External Links

Where this newsletter contains links to third-party websites, please note that we have no influence over their content. Responsibility for the content of linked websites lies solely with their respective providers or operators. Continuous monitoring of external content is not reasonably possible. At the time the links were created, no unlawful content was apparent.

Copyright and Usage Rights

All content contained in this newsletter, including but not limited to texts, graphics, tables, and images, is protected by copyright law. No content may be reproduced, distributed, or made publicly available, in whole or in part, without the prior written consent of SECOND OPINION CONSULT AG.

Surveys and Questionnaires

The surveys and questionnaires we conduct (hereinafter referred to as “surveys”) are evaluated anonymously. Personal data is processed only to the extent necessary for the provision and technical operation of the surveys (e.g., processing the user's IP address to display the survey in the user's browser or using a temporary cookie (session cookie) to enable the survey to be resumed) or where users have provided their consent.

Information on Legal Bases

Where we request participants' consent to process their data, such consent serves as the legal basis for the processing. Otherwise, participant data is processed on the basis of our legitimate interests in conducting objective surveys and questionnaires.

Categories of Data Processed

  • Contact data (e.g., E-Mail addresses, telephone numbers, postal codes)
  • Content data (e.g., entries in online forms)
  • Usage data (e.g., websites visited, interests in content, access times)
  • Metadata and communication data (e.g., device information, IP addresses)

Data Subjects

  • Communication partners

Purposes of Processing

  • Handling contact requests and communications
  • Direct marketing (e.g., by E-Mail or postal mail)

Legal Bases

  • Consent (Art. 6(1)(a) GDPR)
  • Legitimate interests (Art. 6(1)(f) GDPR)

Web Analytics, Monitoring, and Optimisation

Web analytics (also referred to as “audience measurement”) is used to analyze visitor traffic to our online services and may include behavioral, interest-based, or demographic information about visitors, such as age or gender, in pseudonymized form. Through audience measurement, we can determine, for example, at what times our website, its functions, or its content are used most frequently or are particularly likely to be revisited. We can also identify areas that require optimization.

In addition to web analytics, we may use testing procedures, such as A/B testing, to test and optimize different versions of our online services or individual components thereof.

For these purposes, user profiles may be created and stored in a file (commonly referred to as a “cookie”), or similar technologies serving the same purpose may be used. Such information may include viewed content, visited websites, the elements used on those websites, and technical information such as the browser used, the computer system used, and information regarding usage times. Where users have consented to the collection of location data, such data may also be processed, depending on the service provider.

Users’ IP addresses are also stored. However, we use an IP masking procedure (i.e., pseudonymization through truncation of the IP address) to protect user privacy. In general, no directly identifiable data (such as names or E-Mail addresses) is stored in connection with web analytics, A/B testing, or optimization. Instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of users, but only the information stored in their profiles for the purposes of the respective procedures.

Information on Legal Bases

Where we request users’ consent to use third-party service providers, the legal basis for the processing of data is that consent.

Otherwise, user data is processed on the basis of our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services).

In this context, we also refer you to the information regarding the use of cookies contained in this Privacy Policy.

Categories of Data Processed

  • Usage data (e.g., websites visited, interest in content, access times)
  • Metadata and communication data (e.g., device information, IP addresses)

Data Subjects

  • Users (e.g., website visitors and users of online services)

Purposes of Processing

  • Audience measurement (e.g., access statistics and recognition of returning visitors)
  • Creation of profiles containing user-related information

Security Measures

  • IP masking (pseudonymization of IP addresses)

Legal Bases

  • Consent (Art. 6(1)(a) GDPR)
  • Legitimate interests (Art. 6(1)(f) GDPR)

Services and Service Providers Used

Matomo (Without Cookies)

Matomo is a privacy-friendly web analytics solution that operates without the use of cookies. Returning users are recognized through the use of a so-called “digital fingerprint”, which is stored anonymously and refreshed every 24 hours.

This digital fingerprint records user activity within our online services by combining pseudonymized IP addresses with browser settings on the user’s device in such a way that it is not possible to identify individual users.

Service Provider:
Self-hosted web analytics and audience measurement solution

Website:
https://matomo.org

Social Media Presence

We maintain online presences on social networking platforms and, in this context, process user data in order to communicate with users active on these platforms and to provide information about our company and services.

Please note that user data may be processed outside the European Union. This may result in risks for users, as the enforcement of their rights may become more difficult in certain jurisdictions.

Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, user profiles may be created based on users' behavior and resulting interests. These profiles can then be used to display advertisements within and outside the respective social network that are presumed to match users’ interests. For these purposes, cookies are generally stored on users’ devices, allowing user behavior and interests to be recorded. In addition, data may be stored in user profiles independently of the devices used by users, particularly if users are registered members of the respective platform and logged into their accounts.

For a detailed description of the respective processing activities and available options for objecting to such processing (opt-out), please refer to the privacy policies and information provided by the operators of the respective social networks.

In the event of requests for information or the exercise of data subject rights, we would also like to point out that these rights can most effectively be exercised directly with the respective providers. Only the platform providers have direct access to users' data and can take appropriate measures or provide information accordingly. Should you nevertheless require assistance, you are welcome to contact us.

Categories of Data Processed

  • Contact data (e.g., E-Mail addresses, telephone numbers, postal codes)
  • Content data (e.g., information entered in online forms)
  • Usage data (e.g., websites visited, interests, access times)
  • Metadata and communication data (e.g., device information, IP addresses)

Data Subjects

  • Users (e.g., website visitors and users of online services)

Purposes of Processing

  • Contact requests and communication
  • Feedback collection (e.g., through online forms)
  • Marketing

Legal Basis

  • Legitimate interests (Art. 6(1)(f) GDPR)

Services and Service Providers Used

Instagram

Social networking platform.

Service Provider:
Instagram, Inc.
1601 Willow Road
Menlo Park, CA 94025, USA

Parent Company:
Meta Platforms, Inc. (formerly Facebook)
1 Hacker Way
Menlo Park, CA 94025, USA

Website:https://www.instagram.com

Privacy Policy:
https://instagram.com/about/legal/privacy

 


 

LinkedIn

Professional social networking platform.

Service Provider:
LinkedIn Ireland Unlimited Company
Wilton Place
Dublin 2, Ireland

Website:https://www.linkedin.com

Privacy Policy:
https://www.linkedin.com/legal/privacy-policy

Opt-Out Settings:
https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out

 


 

X (formerly Twitter)

Social networking platform.

Service Provider:
Twitter International Unlimited Company
One Cumberland Place
Fenian Street
Dublin 2, D02 AX07, Ireland

Parent Company:
X Corp. (formerly Twitter, Inc.)
1355 Market Street, Suite 900
San Francisco, CA 94103, USA

Privacy Policy:
https://twitter.com/privacy

Personalization Settings:

https://twitter.com/settings/account/personalization

 


 

Vimeo

Video hosting and social media platform.

Service Provider:
Vimeo, Inc.
Attention: Legal Department
555 West 18th Street
New York, NY 10011, USA

Website:https://vimeo.com

Privacy Policy:
https://vimeo.com/privacy

Data Deletion

The data processed by us will be deleted in accordance with applicable legal requirements once the consent permitting such processing has been withdrawn or other legal grounds for processing no longer apply (e.g., where the purpose for processing the data no longer exists or the data is no longer required for that purpose).

If the data cannot be deleted because it is required for other lawful purposes, its processing will be restricted to those purposes. This means that the data will be blocked and will not be processed for any other purpose. This applies, for example, to data that must be retained for commercial or tax law reasons, or where storage is necessary for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person.

Within this Privacy Policy, we may provide users with additional information regarding the deletion and retention of data where such information specifically relates to particular processing activities.

Changes and Updates to the Privacy Policy

We encourage you to review the contents of our Privacy Policy on a regular basis. We will update this Privacy Policy whenever changes to our data processing activities make such revisions necessary. We will inform you whenever the changes require any action on your part (e.g., providing consent) or where any other individual notification is required by law.

Where we provide addresses and contact details of companies and organisations in this Privacy Policy, please note that such information may change over time. We therefore recommend that you verify the relevant contact details before making contact.

Rights of Data Subjects (persons concerned)

As a data subject under the General Data Protection Regulation (GDPR), you are entitled to various rights, in particular those arising from Articles 15 to 21 GDPR:

Right to Object

You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data where such processing is based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions.

Where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing. This also applies to profiling insofar as it is related to such direct marketing.

Right to Withdraw Consent

You have the right to withdraw any consent you have given at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Right of Access

You have the right to obtain confirmation as to whether personal data concerning you is being processed and, where that is the case, to request access to that data, as well as additional information and a copy of the data in accordance with applicable legal requirements.

Right to Rectification

You have the right to request the correction of inaccurate personal data concerning you and, taking into account the purposes of the processing, to request the completion of incomplete personal data, in accordance with applicable legal requirements.

Right to Erasure and Restriction of Processing

You have the right, in accordance with applicable legal requirements, to request the immediate deletion of personal data concerning you. Alternatively, you may request the restriction of processing of your personal data.

Right to Data Portability

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format and, where applicable, to request the transmission of that data to another controller, in accordance with legal requirements.

Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. In particular, you may lodge a complaint with the supervisory authority in the Member State of your habitual residence, your place of work, or the place of the alleged infringement.

Definitions

This section provides an overview of the terminology used in this Privacy Policy. Many of these terms are derived from applicable legislation and are primarily defined in Article 4 of the General Data Protection Regulation (GDPR). The statutory definitions are legally binding. The explanations below are intended solely to facilitate understanding.

  • IP MaskingIP masking refers to a method in which the last octet (i.e., the final segment) of an IP address is removed, preventing the IP address from being used to uniquely identify an individual. IP masking is therefore a means of pseudonymization used in data processing activities, particularly in online marketing and web analytics.
     
  • Personal DataPersonal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier (e.g., a cookie), or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
     
  • Profiles Containing User-Related Information: The processing of profiles containing user-related information (or simply “profiles”) refers to any type of automated processing of personal data consisting of the use of such data to evaluate, analyze, or predict certain personal aspects relating to a natural person. Depending on the type of profiling, this may include information concerning: Demographics, Behavior, Interests, Interactions with websites and their content, Preferences for specific products or services, Clicking behavior on websites, Geographic location. Cookies and web beacons are commonly used for profiling purposes.
     
  • Audience Measurement: Audience measurement (also known as web analytics) is used to evaluate visitor traffic on an online service and may include analyses of visitor behavior and interests relating to specific information, such as website content. Through audience measurement, website operators can determine, for example: When visitors access a website, which content generates the most interest, how users interact with different website features This enables website operators to improve and tailor content to better meet users’ needs. Audience measurement frequently relies on pseudonymous cookies and web beacons to recognize returning visitors and provide more accurate analyses of website usage.
     
  • Controller: A controller is the natural or legal person, public authority, agency, or other body that alone or jointly with others determines the purposes and means of the processing of personal data.
     
  • Processing: Processing means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of personal data, including: Collection, Recording, Organising, Structuring, Storing, Adaptation or modification, Retrieving, Consulting, Using, Disclosure by transmission, Dissemination, Restricting, Erasimng, Destructing In practice, almost any interaction with personal data constitutes processing under the GDPR.