authoriseme.eu ?

Introduction and overview

We have written this data protection notice (version 14.06.2023-322522634) to explain to you, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we as the controller – and the processors (e.g. providers) commissioned by us – process, will process in the future and what lawful options you have. The terms used are to be understood as gender-neutral.
In short: We inform you comprehensively about data that we process about you.

Privacy notices usually sound very technical and use legal terminology. This privacy notice, on the other hand, is intended to describe the most important things to you as simply and transparently as possible. To the extent that it is conducive to transparency, technical terms are explained in a reader-friendly manner, links to further information are provided and graphics are used. In this way, we inform you in clear and simple language that we only process personal data in the course of our business activities if there is a corresponding legal basis. This is certainly not possible by providing the most concise, unclear and legalistic explanations possible, as is often standard practice on the Internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is one or two pieces of information that you did not yet know.
If you still have questions, we would like to ask you to contact the responsible party named in the imprint, to follow the available links and to look at further information on third-party sites. Our contact details can of course also be found in the imprint.

Scope

This data protection notice applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (order processors). By personal data, we mean information within the meaning of Art. 4 No. 1 DSGVO, such as a person’s name, e-mail address and postal address. The processing of personal data ensures that we can offer and invoice our services and products, whether online or offline. The scope of this privacy notice includes:

  • all online presences (websites, online stores) that we operate
  • Social media appearances and e-mail communication
  • mobile apps for smartphones and other devices

In short, the data protection information applies to all areas in which personal data is processed in a structured manner within the company via the aforementioned channels. If we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.

Contact details of the responsible person

Responsible for this website is AuthoriseMe GmbH, Austraße 34, 35745 Herborn, info(at)authoriseme.eu

You can reach our designated data protection officer by e-mail at data.de(at)raan-group.com

Storage duration

The fact that we only store personal data for as long as is absolutely necessary for the provision of our services and products applies as a general criterion at our company. This means that we delete personal data as soon as the reason for processing the data no longer exists. In some cases, we are required by law to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.

Should you wish your data to be deleted or revoke your consent to data processing, the data will be deleted as soon as possible and insofar as there is no obligation to store it.

Rights under the General Data Protection Regulation

In accordance with Articles 13, 14 of the GDPR, we inform you about the following rights you have to ensure that data processing is fair and transparent:

  • According to Article 15 of the GDPR, you have the right to know whether we are processing data about you. If this is the case, you have the right to receive a copy of the data and the following information: 
    • the purpose for which we carry out the processing;
    • the categories, i.e. the types of data that are processed;
    • who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
    • how long the data will be stored;
    • the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
    • that you can complain to a supervisory authority;
    • the origin of the data if we have not collected it from you;
    • whether profiling is carried out, i.e. whether data is automatically evaluated to arrive at a personal profile of you.
  • You have a right to rectify data according to Article 16 of the GDPR, which means that we must correct data if you find errors.
  • According to Article 17 of the GDPR, you have the right to erasure („right to be forgotten“), which specifically means that you may request the deletion of your data.
  • According to Article 18 of the GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it further.
  • According to Article 20 DSGVO, you have the right to data portability, which means that we will provide you with your data in a common format upon request.
  • According to Article 21 of the GDPR, you have a right to object, which, once enforced, entails a change in processing. 
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then check as soon as possible whether we can legally comply with this objection.
    • If data is used to conduct direct marketing, you may object to this type of data processing at any time. We may not use your data for direct marketing thereafter.
    • If data is used to perform profiling, you can object to this type of data processing at any time. We may not use your data for profiling thereafter.
  • According to Article 22 of the GDPR, you may have the right not to be subject to a decision based solely on automated processing (for example, profiling).
  • According to Article 77 of the GDPR, you have the right to lodge a complaint. This means that you can complain to the data protection authority at any time if you believe that the data processing of personal data violates the GDPR.

In short, you have rights – do not hesitate to contact the responsible party listed above with us!

If you believe that the processing of your data violates data protection law or your data protection rights have been violated in any other way, you can complain to the supervisory authority.

NEWSLETTER

If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. Further data is not collected or only on a voluntary basis. For the handling of the newsletter, we use newsletter service providers, which are described below.

Double opt-in procedure: The registration to our newsletter takes place in general in a so-called Double-Opt-In procedure. This means that you will receive an e-mail after registration asking you to confirm your registration. This confirmation is necessary so that no one can register with external e-mail addresses.

The registrations for the newsletter are logged in order to be able to prove the registration process according to the legal requirements. This includes storing the login and confirmation times as well as the IP address. Likewise the changes of your data stored with the dispatch service provider are logged.

Deletion and restriction of processing: We may store the unsubscribed email addresses for up to three years based on our legitimate interests before deleting them to provide evidence of prior consent. The processing of these data is limited to the purpose of a possible defense against claims. An individual deletion request is possible at any time, provided that the former existence of a consent is confirmed at the same time. In the case of an obligation to permanently observe an objection, we reserve the right to store the e-mail address solely for this purpose in a blacklist. You may object to the storage if your interests outweigh our legitimate interest.

The logging of the registration process takes place on the basis of our legitimate interests for the purpose of proving its proper course. If we commission a service provider to send e-mails, this is done on the basis of our legitimate interests in an efficient and secure sending system.

Brevo

This website uses Brevo for the sending of newsletters. The provider is the Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany.

Brevo services can, among other things, be used to organize and analyze the sending of newsletters. The data you enter for the purpose of subscribing to the newsletter are archived on servers of Sendinblue GmbH in Germany.

  • Processed data types: Inventory data (e.g. names, addresses); Contact data (e.g. e-mail, telephone numbers); Meta, communication and process data (e.g. IP addresses, time information, identification numbers, consent status); Usage data (e.g. websites visited, interest in content, access times).
  • Data subjects: Communication partner (Recipients of e-mails, letters, etc.).
  • Purposes of Processing: Direct marketing (e.g. by e-mail or postal); Web Analytics (e.g. access statistics, recognition of returning visitors).

Data analysis by Brevo 

Brevo enables us to analyze our newsletter campaigns. For instance, it allows us to see whether a newsletter message has been opened and, if so, which links may have been clicked. This enables us to determine, which links drew an extraordinary number of clicks.

Moreover, we are also able to see whether once the e-mail was opened or a link was clicked, any previously defined actions were taken (conversion rate). This allows us to determine whether you have made a purchase after clicking on the newsletter.

Brevo also enables us to divide the subscribers to our newsletter into various categories (i.e., to “cluster” recipients). For instance, newsletter recipients can be categorized based on age, gender, or place of residence. This enables us to tailor our newsletter more effectively to the needs of the respective target groups.

If you do not want to permit an analysis by Brevo, you must unsubscribe from the newsletter. We provide a link for you to do this in every newsletter message. Moreover, you can also unsubscribe from the newsletter right on the website.

Legal basis 

The data is processed based on your consent (Art. 6(1)(a) GDPR). You may revoke any consent you have given at any time by unsubscribing from the newsletter. This shall be without prejudice to the lawfulness of any data processing transactions that have taken place prior to your revocation.

Storage period 

The data deposited with us for the purpose of subscribing to the newsletter will be stored by us until you unsubscribe from the newsletter or the newsletter service provider and deleted from the newsletter distribution list after you unsubscribe from the newsletter. Data stored for other purposes with us remain unaffected.

After you unsubscribe from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist, if such action is necessary to prevent future mailings. The data from the blacklist is used only for this purpose and not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). The storage in the blacklist is indefinite. You may object to the storage if your interests outweigh our legitimate interest.

For more details, please consult the Data Protection Regulations of Brevo at: https://www.brevo.com/de/datenschutz-uebersicht/ and https://www.brevo.com/de/legal/privacypolicy/.

Data processing 

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.

Cookies

The following cookies and plugins are used on this website:

 

  1. Borelabs Cookie Consent (user consent management for cookies), with 1 year storage time: https://borlabs.io/
  2. Contact 7 (contact forms), unlimited storage period: https://wordpress.org/plugins/contact-form-7/
  3. Flamingo (contact management in WordPress backend, storage of messages)  unlimited storage period: https://wordpress.org/plugins/flamingo/ 
  4. Rankmath (SEO): https://wordpress.org/plugins/seo-by-rank-math/
  5. Google Analytics 4 (user analyses) with 2 months storage time
  6. Google reCaptcha (spam/bot protection on contact forms), storage time not influenceable

 

Cookies summary
👥 Data subjects: visitors to the website.
🤝 Purpose: depends on the cookie in question. More details can be found below or from the manufacturer of the software that sets the cookie.
📓 Data processed: Depending on the cookie used in each case. More details can be found below or from the manufacturer of the software that sets the cookie.
📅 Storage duration: Depending on the respective cookie, can vary from hours to years.
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (Consent), Art. 6 para. 1 lit.f DSGVO (Legitimate Interests).

 

What are cookies?

Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used so that you can better understand
the following privacy notice.

Whenever you browse the Internet, you use a browser. Popular browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small files in your browser. These files are called cookies.

One thing cannot be denied: Cookies are really useful little helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, as there are other cookies for other applications. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, effectively the „brain“ of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.

Cookies store certain user data about you, such as language or personal page settings. When you return to our site, your browser transmits the „user-related“ information back to our site. Thanks to cookies, our site knows who you are and offers you the setting you are used to. In some browsers, each cookie has its own file, in others, such as Firefox, all cookies are stored in a single file.

The following graphic shows a possible interaction between a web browser such as Chrome and the web server. Here, the web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. Also, the expiration time of a cookie varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans or other „pests“. Cookies also cannot access information on your PC.

For example, cookie data can look like this:

Name: _ga
Wert: GA1.2.1326744211.152322522634-9
Intended use: differentiation of website visitors
Expiration date: after 2 years

A browser should be able to support these minimum sizes:

  • At least 4096 bytes per cookie
  • At least 50 cookies per domain
  • At least 3000 cookies in total

What are the types of cookies?

The question of which cookies we use in particular depends on the services used and is clarified in the following sections of the privacy notice. At this point, we would like to briefly discuss the different types of HTTP cookies.

We can distinguish 4 types of cookies:

Essential cookies
These cookies are necessary to ensure basic website functionality. For example, these cookies are needed when a user adds a product to the shopping cart, then continues to browse other pages and later proceeds to checkout. These cookies do not delete the shopping cart even if the user closes his browser window.

Purpose cookies
These cookies collect information about user behavior and whether the user receives any error messages. In addition, these cookies are also used to measure the loading time and the behavior of the website with different browsers.

Target-oriented cookies
These cookies provide a better user experience. For example, entered locations, font sizes or form data are stored.

Advertising cookies
These cookies are also called targeting cookies. They are used to deliver customized advertising to the user. This can be very convenient, but also very annoying.

Usually, when you visit a website for the first time, you are asked which of these cookie types you want to allow. And, of course, this decision is also stored in a cookie.

If you want to know more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments called „HTTP State Management Mechanism“.

Purpose of processing via cookies

The purpose ultimately depends on the cookie in question. 

What data is processed?

Cookies are small helpers for many different tasks. Unfortunately, it is not possible to generalize what data is stored in cookies, but we will inform you about the processed or stored data in the following privacy notice.

Cookies storage duration

The storage period depends on the particular cookie and is specified further below. Some cookies are deleted after less than an hour, others can remain stored on a computer for several years.

You can also influence the storage period yourself. You can manually delete all cookies at any time via your browser (see also „Right of objection“ below). Furthermore, cookies that are based on consent will be deleted at the latest after revocation of your consent, whereby the legality of the storage remains unaffected until then.

Right to object – how can I delete cookies?

How and whether you want to use cookies, you decide. Regardless of which service or website the cookies come from, you always have the option to delete, disable or only partially allow cookies. For example, you can block third-party cookies, but allow all other cookies.

If you want to determine which cookies have been stored in your browser, if you want to change or delete cookie settings, you can find this in your browser settings:

Chrome: Delete, enable and manage cookies in Chrome

Safari: Managing cookies and website data with Safari

Firefox: Delete cookies to remove data that websites have placed on your computer

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete and manage cookies

If you do not want to have cookies in principle, you can set up your browser so that it always informs you when a cookie is to be set. In this way, you can decide for each individual cookie whether you allow the cookie or not. The procedure varies depending on the browser. It is best to search for the instructions in Google using the search term „delete cookies Chrome“ or „disable cookies Chrome“ in the case of a Chrome browser.

Web Analytics Introduction

Web Analytics Privacy Notice Summary
👥 Data subjects: Visitors to the website.
🤝 Purpose: Evaluation of visitor information to optimize the web offer.
📓 Data processed: Access statistics containing data such as access locations, device data, access duration and time, navigation behavior, click behavior, and IP addresses. More details on this can be found with the respective web analytics tool used.
📅 Storage period: depending on the web analytics tool used.
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (consent), Art. 6 para. 1 lit. f DSGVO (legitimate interests).

What is Web Analytics?

We use software on our website to evaluate the behavior of website visitors, known as web analytics for short. This involves collecting data that is stored, managed and processed by the respective analytic tool provider (also known as a tracking tool). The data is used to create analyses of user behavior on our website and made available to us as the website operator. In addition, most tools offer various testing options. For example, we can test which offers or content are best received by our visitors. To do this, we show you two different offers for a limited period of time. After the test (so-called A/B test), we know which product or content our website visitors find more interesting. For such test procedures, as for other analytics procedures, user profiles can also be created and the data stored in cookies.

Why do we run web analytics?

With our website we have a clear goal in mind: we want to deliver the best web offer on the market for our industry. To achieve this goal, we want to offer the best and most interesting offer on the one hand, and on the other hand make sure that you feel completely comfortable on our website. With the help of web analysis tools, we can take a closer look at the behavior of our website visitors and then improve our web offer for you and us accordingly. For example, we can see how old our visitors are on average, where they come from, when our website is most visited or which content or products are particularly popular. All this information helps us to optimize the website and thus best adapt it to your needs, interests and wishes.

What data is processed?

Exactly what data is stored depends, of course, on the analysis tools used. But as a rule, for example, which content you view on our website, which buttons or links you click on, when you access a page, which browser you use, which device (PC, tablet, smartphone, etc.) you use to visit the website or which computer system you use is stored. If you agreed that location data may also be collected, these may also be processed by the web analytics tool provider.

In addition, your IP address is also stored. According to the General Data Protection Regulation (DSGVO), IP addresses are personal data. However, your IP address is usually stored pseudonymously (i.e. in an unrecognizable and shortened form). For the purpose of testing, web analysis and web optimization, no direct data, such as your name, age, address or email address are stored as a matter of principle. All this data, if collected, is stored pseudonymously. Thus, you cannot be identified as a person.

The following example schematically shows how Google Analytics works as an example of client-based web tracking with Java Script code.

How long the respective data is stored always depends on the provider. Some cookies store data only for a few minutes or until you leave the website again, other cookies can store data for several years.

Duration of data processing

We will inform you about the duration of data processing below, provided we have further information on this. In general, we process personal data only as long as it is absolutely necessary for the provision of our services and products. If it is required by law, as for example in the case of accounting, this storage period may also be exceeded.

Right of objection

You also have the right and the possibility to revoke your consent to the use of cookies or third-party providers at any time. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection through cookies by managing, disabling or deleting cookies in your browser.

Legal basis

The use of web analytics requires your consent, which we have obtained with our cookie popup. According to Art. 6 para. 1 lit. a DSGVO (consent), this consent constitutes the legal basis for the processing of personal data as it may occur during the collection by web analytics tools.

In addition to consent, there is a legitimate interest on our part to analyze the behavior of website visitors and thus to improve our offer technically and economically. With the help of web analytics, we detect errors of the website, can identify attacks and improve the economic efficiency. The legal basis for this is Art. 6 para. 1 lit. f DSGVO (Legitimate Interests). Nevertheless, we use the tools only insofar as they have given consent.

Since cookies are used with web analytics tools, we recommend that you also read our general data protection information on cookies. To find out exactly which of your data is stored and processed, you should read the privacy notices of the respective tools.

Information on specific web analytics tools, if any, is provided in the following sections.

Google Analytics

Google Analytics Privacy Notice Summary Data
subjects: visitors to the website
Purpose: evaluation of visitor information to optimize the web offer.
Data processed: Access statistics, which include data such as locations of accesses, device data, access duration and time, navigation behavior, click behavior and IP addresses. More details can be found below in this privacy notice.
Storage period: depending on the properties used
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (consent), Art. 6 para. 1 lit. f DSGVO (legitimate interests).

What is Google Analytics?

We use on our website the analysis tracking tool Google Analytics (GA) of the American company Google Inc. For the European area the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. Google Analytics collects data about your actions on our website. For example, when you click on a link, this action is stored in a cookie and sent to Google Analytics. Using the reports we receive from Google Analytics, we can better tailor our website and service to your preferences. In the following, we will go into more detail about the tracking tool and, in particular, inform you about what data is stored and how you can prevent this.

Google Analytics is a tracking tool used for traffic analysis of our website. For Google Analytics to work, a tracking code is built into the code of our website. When you visit our website, this code records various actions you take on our website. Once you leave our website, this data is sent to the Google Analytics servers and stored there.

Google processes the data and we receive reports about your user behavior. These reports may include, but are not limited to, the following:

  • Target group reports: Through target group reports, we get to know our users better and know more precisely who is interested in our service.
  • Ad reports: Ad reports make it easier for us to analyze and improve our online advertising.
  • Acquisition reports: Acquisition reports give us helpful information on how to get more people interested in our service.
  • Behavior reports: This is where we learn how you interact with our website. We can track which path you take on our site and which links you click.
  • Conversion reports: Conversion is the name given to a process in which you perform a desired action as a result of a marketing message. For example, when you go from being just a website visitor to a buyer or newsletter subscriber. These reports help us learn more about how our marketing efforts are working for you. This is how we aim to increase our conversion rate.
  • Real-time reports: Here we always know immediately what is happening on our website. For example, we can see how many users are reading this text.

Why do we use Google Analytics on our website?

Our goal with this website is clear: we want to provide you with the best possible service. The statistics and data from Google Analytics help us achieve this goal.

The statistically evaluated data shows us a clear picture of the strengths and weaknesses of our website. On the one hand, we can optimize our site so that it is found more easily by interested people on Google. On the other hand, the data helps us to better understand you as a visitor. Thus, we know very well what we need to improve on our website in order to provide you with the best possible service. The data also helps us to carry out our advertising and marketing measures in a more individual and cost-effective way. After all, it only makes sense to show our products and services to people who are interested in them.

What data is stored by Google Analytics?

Google Analytics uses a tracking code to create a random, unique ID associated with your browser cookie. This is how Google Analytics recognizes you as a new user. The next time you visit our site, you will be recognized as a „returning“ user. All collected data is stored together with this user ID. This is how it is possible to evaluate pseudonymous user profiles in the first place.

To be able to analyze our website with Google Analytics, a property ID must be inserted into the tracking code. The data is then stored in the corresponding property. For each newly created property, the Google Analytics 4 property is default. 

Identifiers such as cookies and app instance IDs measure your interactions on our website. Interactions are all types of actions you take on our website. If you also use other Google systems (such as a Google account), data generated through Google Analytics may be linked to third-party cookies. Google does not share Google Analytics data unless we, as the website operator, authorize it. Exceptions may occur if required by law.

The following cookies are used by Google Analytics:

Name: _ga
Wert: 2.1326744211.152322522634-5
Purpose: By default, analytics.js uses the _ga cookie to store the user ID. Basically, it is used to distinguish website visitors.
Expiration date: after 2 years

Name: _gid
Wert: 2.1687193234.152322522634-1
Purpose: the cookie is also used to distinguish website visitors
Expiration date: after 24 hours

Name: _gat_gtag_UA_<property-id>
Value: 1
Purpose: Used to lower the request rate. If Google Analytics is deployed via Google Tag Manager, this cookie will be named _dc_gtm_ <property-id>.
Expiration date: after 1 minute

Name: AMP_TOKEN
Value: not specified
Purpose: The cookie has a token that can be used to retrieve a user ID from the AMP client ID service. Other possible values indicate a logout, a request, or an error.
Expiration date: after 30 seconds up to one year

Name: __utma
Wert: 1564498958.1564498958.1564498958.1
Purpose: This cookie is used to track your behavior on the website and measure performance. The cookie is updated every time information is sent to Google Analytics.
Expiration date: after 2 years

Name: __utmt
Value: 1
Purpose: The cookie is used like _gat_gtag_UA_<property-id> to throttle the request rate.
Expiration date: after 10 minutes

Name: __utmb
Value: 3.10.1564498958
Purpose: This cookie is used to determine new sessions. It is updated every time new data or info is sent to Google Analytics.
Expiration date: after 30 minutes

Name: __utmc
Value: 167421564
Purpose: This cookie is used to set new sessions for returning visitors. This is a session cookie and is only stored until you close the browser again.
Expiration date: After you close the browser.

Name: __utmz
Value: m|utmccn=(referral)|utmcmd=referral|utmcct=/
Purpose: The cookie is used to identify the source of traffic to our website. That is, the cookie stores from where you came to our website. This may have been another page or an advertisement.
Expiration date: after 6 months

Name: __utmv
Value: not specified
Purpose: The cookie is used to store custom user data. It is updated whenever information is sent to Google Analytics.
Expiration date: after 2 years

 

Here we show you an overview of the most important data collected with Google Analytics:

Heatmaps: Google creates so-called heatmaps. Heatmaps allow you to see exactly those areas that you click on. This gives us information about where you are „on the move“ on our site.

Session duration: Google defines session duration as the time you spend on our site without leaving. If you have been inactive for 20 minutes, the session ends automatically.

Bounce rate: A bounce rate is when you view only one page on our website and then leave our website again.

Account creation: When you create an account or place an order on our website, Google Analytics collects this data.

IP address: The IP address is only shown in abbreviated form so that no clear assignment is possible.

Location: The IP address can be used to determine the country and your approximate location. This process is also called IP location determination.

Technical information: Technical information may include your browser type, Internet service provider, or screen resolution.

Source of origin: Google Analytics or, of course, we are also interested in which website or which advertisement you came to our site from.

Other data include contact details, any ratings, playing media (e.g. when you play a video via our site), sharing content via social media or adding to your favorites. The enumeration does not claim to be complete and only serves as a general orientation of the data storage by Google Analytics.

How long and where is the data stored?

Google has their servers spread all over the world. Most servers are located in America and consequently your data is mostly stored on American servers. Here you can read exactly where Google’s data centers are located: https://www.google.com/about/datacenters/locations/?hl=de 

Your data is distributed on different physical data carriers. This has the advantage that the data can be retrieved more quickly and is better protected against manipulation. In every Google data center, there are corresponding emergency programs for your data. If, for example, the hardware at Google fails or natural disasters paralyze servers, the risk of a service interruption at Google still remains low.

The data retention period depends on the properties used. When using the newer Google Analytics 4 properties, the retention period of your user data is set to 14 months. For other so-called event data, we have the option to choose a retention period of 2 months or 14 months.

In addition, there is also the option that data will only be deleted if you no longer visit our website within the period we have selected. In this case, the retention period is reset each time you visit our website again within the specified period.

Once the specified period has expired, the data is deleted once a month. This retention period applies to your data associated with cookies, user recognition and advertising IDs (e.g. DoubleClick domain cookies). Reporting results are based on aggregated data and are stored separately from user data. Aggregated data is a merging of individual data into a larger unit.

How can I delete my data or prevent data storage?

Under European Union data protection law, you have the right to access, update, delete, or restrict your data. Using the browser add-on to disable Google Analytics JavaScript (ga.js, analytics.js, dc.js), you can prevent Google Analytics from using your data. You can download and install the browser add-on at https://tools.google.com/dlpage/gaoptout?hl=de. Please note that this add-on only disables data collection by Google Analytics.

If you basically want to disable, delete or manage cookies, you can find the corresponding links to the respective instructions of the most popular browsers under the section „Cookies“.

Legal basis

The use of Google Analytics requires your consent, which we have obtained with our cookie popup. According to Art. 6 para. 1 lit. a DSGVO (consent), this consent constitutes the legal basis for the processing of personal data as it may occur during the collection by web analytics tools.

In addition to the consent, there is a legitimate interest on our part to analyze the behavior of website visitors and thus to improve our offer technically and economically. With the help of Google Analytics, we detect website errors, can identify attacks and improve the economic efficiency. The legal basis for this is Art. 6 para. 1 lit. f DSGVO (Legitimate Interests). Nevertheless, we only use Google Analytics if you have given your consent.

Google also processes data from you in the USA, among other places. We would like to point out that according to the opinion of the European Court of Justice, there is currently no adequate level of protection for the transfer of data to the USA. This may be associated with various risks for the legality and security of data processing.

Google uses so-called standard contractual clauses (= Art. 46. para. 2 and 3 DSGVO) as the basis for data processing for recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway, i.e. in particular in the USA) or a data transfer there. Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through these clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the US. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which reference the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

We hope we have been able to provide you with the most important information about Google Analytics data processing. If you want to learn more about the tracking service, we recommend these two links: https://marketingplatform.google.com/about/analytics/terms/de/ and https://support.google.com/analytics/answer/6004245?hl=de.

Borlabs Cookie Privacy Notice

We use BorlabsCookie on our website, which is, among other things, a tool for storing your cookie consent. The service provider is the German company Borlabs – Benjamin A. Bornschein, Rübenkamp 32, 22305 Hamburg, Germany. You can learn more about the data processed through the use of BorlabsCookie in the Privacy Policy at https://de.borlabs.io/datenschutz/.

Adobe Font

This website uses web fonts from Adobe for the uniform display of certain fonts. The provider is Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA (Adobe). When you call up this website, your browser loads the required fonts directly from Adobe in order to be able to display them correctly on your end device. In doing so, your browser establishes a connection to Adobe’s servers in the USA. This enables Adobe to know that your IP address has been used to access this website. According to Adobe, no cookies are stored when providing the fonts. The storage and analysis of the data is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in the uniform presentation of the typeface on its website. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user’s terminal device (e.g. device fingerprinting) as defined by the TTDSG. The consent can be revoked at any time. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.adobe.com/de/privacy/eudatatransfers.html For more information on Adobe Fonts, please visit: https://www.adobe.com/de/privacy/policies/adobe-fonts.html

Google reCAPTCHA Privacy Notice

Google reCAPTCHA Privacy Notice Summary
👥 Data subject: Visitors to the website
🤝 Purpose: Optimization of our service performance and protection against cyber attacks.
📓 Data processed: Data such as IP address, browser information, your operating system, limited location and usage data
More details can be found below in this privacy notice.
📅 Storage period: depending on the stored data.
⚖️ Legal basis: Art. 6 para. 1 lit. a DSGVO (Consent), Art. 6 para. 1 lit. f DSGVO (Legitimate Interests).

 

What is reCAPTCHA?

Our primary goal is to secure and protect our website for you and for us in the best possible way. To ensure this, we use Google reCAPTCHA from the company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services. With reCAPTCHA we can determine whether you are really a flesh and blood human being and not a robot or other spam software. By spam we mean any unsolicited information sent to us electronically. With the classic CAPTCHAS, you usually had to solve text or image puzzles to verify the information. With reCAPTCHA from Google, we usually don’t have to bother you with such puzzles. Here, in most cases, it is enough to simply check a box to confirm that you are not a bot. With the new Invisible reCAPTCHA version, you don’t even have to set a checkmark anymore. How this works exactly and especially which data is used for this, you will learn in the course of this privacy notice.

reCAPTCHA is a free captcha service from Google that protects websites from spam software and abuse by non-human visitors. The most common use of this service is when you fill out forms on the Internet. A captcha service is a kind of automatic Turing test, designed to ensure that an action on the Internet is performed by a human and not by a bot. In the classic Turing test (named after computer scientist Alan Turing), a human determines the distinction between a bot and a human. In captchas, the computer or a software program also does this. Classic captchas work with small tasks that are easy for humans to solve, but present significant difficulties for machines. With reCAPTCHA, you no longer have to actively solve puzzles. The tool uses modern risk techniques to distinguish humans from bots. Here, you only need to check the „I am not a robot“ text box, or with Invisible reCAPTCHA, even that is no longer necessary. With reCAPTCHA, a JavaScript element is included in the source code and then the tool runs in the background and analyzes your user behavior. From these user actions, the software calculates a so-called captcha score. Google uses this score to calculate even before the captcha is entered how likely you are to be a human. reCAPTCHA or captchas in general are always used when bots could manipulate or abuse certain actions (such as registrations, surveys, etc.).

Why do we use reCAPTCHA on our website?

We only want to welcome flesh and blood people on our site. Bots or spam software of any kind can safely stay at home. That’s why we pull out all the stops to protect ourselves and offer the best possible user experience for you. For this reason we use Google reCAPTCHA from Google. This way we can be pretty sure that we remain a „bot-free“ website. By using reCAPTCHA, data is sent to Google to determine whether you are actually human. reCAPTCHA therefore serves the security of our website and, by extension, your security. For example, without reCAPTCHA, it could happen that a bot registers as many e-mail addresses as possible during registration in order to „spam“ forums or blogs with unwanted advertising content. With reCAPTCHA we can avoid such bot attacks.

What data is stored by reCAPTCHA?

reCAPTCHA collects personal data from users to determine whether the actions on our website really come from people. Thus, the IP address and other data required by Google for the reCAPTCHA service may be sent to Google. IP addresses are almost always shortened beforehand within the member states of the EU or other contracting states to the Agreement on the European Economic Area before the data ends up on a server in the USA. The IP address is not combined with other data from Google unless you are logged in with your Google account while using reCAPTCHA. First, the reCAPTCHA algorithm checks whether Google cookies from other Google services (YouTube. Gmail, etc.) are already placed on your browser. Then, reCAPTCHA places an additional cookie on your browser and captures a snapshot of your browser window.

The following list of collected browser and user data does not claim to be complete. Rather, they are examples of data that, to our knowledge, are processed by Google.

  • Referrer URL (the address of the page from which the visitor comes)
  • IP address (e.g. 256.123.123.1)
  • Info about the operating system (the software that allows your computer to run. Known operating systems are Windows, Mac OS X or Linux).
  • Cookies (small text files that store data in your browser)
  • Mouse and keyboard behavior (every action you perform with the mouse or keyboard is saved)
  • Date and language settings (which language or date you have preset on your PC will be saved)
  • All JavaScript objects (JavaScript is a programming language that allows websites to adapt to the user. JavaScript objects can collect all kinds of data under one name).
  • Screen resolution (shows how many pixels the image display consists of)

It is undisputed that Google uses and analyzes this data even before you click the „I am not a robot“ checkbox. With the Invisible reCAPTCHA version, even the ticking is omitted and the entire recognition process runs in the background. How much and which data Google stores exactly, Google does not tell you in detail.

The following cookies are used by reCAPTCHA: Here we refer to the reCAPTCHA demo version from Google at https://www.google.com/recaptcha/api2/demo. All of these cookies require a unique identifier for tracking purposes. Here is a list of cookies that Google reCAPTCHA has set on the demo version:

Name: IDE
Value: WqTUmlnmv_qXyi_DGNPLESKnRNrpgXoy1K-pAZtAkMbHI-322522634-8
Purpose: This cookie is set by the DoubleClick company (also owned by Google) to register and report a user’s actions on the website in dealing with advertisements. In this way, advertising effectiveness can be measured and appropriate optimization measures can be taken. IDE is stored in browsers under the domain doubleclick.net.
Expiration date: after one year

Name: 1P_JAR
Value: 2019-5-14-12
Purpose: This cookie collects statistics about website usage and measures conversions. For example, a conversion occurs when a user becomes a buyer. The cookie is also used to display relevant advertisements to users. Furthermore, the cookie can be used to prevent a user from seeing the same ad more than once.
Expiration date: after one month

Name: ANID
Wert: U7j1v3dZa3225226340xgZFmiqWppRWKOr
Purpose: We could not find out much info about this cookie. In Google’s privacy notice, the cookie is mentioned in connection with „advertising cookies“ such as „DSID“, „FLC“, „AID“, „TAID“. ANID is stored under domain google.com.
Expiration date: after 9 months

Name: CONSENT
Value: YES+AT.en+20150628-20-0
Purpose: The cookie stores the status of a user’s consent to use various services from Google. CONSENT is also used for security purposes to verify users, prevent credential fraud, and protect user data from unauthorized attacks.
Expiration date: after 19 years

Name: NID
Wert: 0WmuWqy322522634zILzqV_nmt3sDXwPeM5Q
Purpose: NID is used by Google to customize ads to your Google searches. With the help of the cookie, Google „remembers“ your most typed search queries or your previous interaction with ads. This way, you always get tailored ads. The cookie contains a unique ID to collect personal settings of the user for advertising purposes.
Expiration date: after 6 months

Name: DV
Wert: gEAABBCjJMXcI0dSAAAANbqc322522634-4
Purpose: Once you have checked the „I am not a robot“ box, this cookie will be set. The cookie is used by Google Analytics for personalized advertising. DV collects information in anonymous form and is further used to make user distinctions.
Expiration date: after 10 minutes

Note: This list cannot claim to be exhaustive, as Google’s experience shows that it changes its choice of cookies time and again.

How long and where is the data stored?

By inserting reCAPTCHA, data is transferred from you to the Google server. Where exactly this data is stored, Google does not make clear, even after repeated inquiries. Without having received confirmation from Google, it can be assumed that data such as mouse interaction, time spent on the website or language settings are stored on Google’s European or American servers. The IP address that your browser transmits to Google is generally not merged with other Google data from other Google services. However, if you are logged into your Google account while using the reCAPTCHA plug-in, the data will be merged. The deviating data protection provisions of the Google company apply to this.

How can I delete my data or prevent data storage?

If you do not want any data about you and your behavior to be transmitted to Google, you must log out of Google completely and delete all Google cookies before you visit our website or use the reCAPTCHA software. Basically, as soon as you visit our site, the data is automatically transmitted to Google. To delete this data again, you must contact Google support at https://support.google.com/?hl=de&tid=322522634.

Thus, by using our website, you consent to the automatic collection, processing and use of data by Google LLC and its agents.

Please note that when using this tool, data from you may also be stored and processed outside the EU. Most third countries (including the USA) are not considered secure under current European data protection law. Data to insecure third countries may therefore not simply be transferred, stored and processed there unless there are suitable safeguards (such as EU standard contractual clauses) between us and the non-European service provider.

Legal basis

If you have consented to Google reCAPTCHA being used, the legal basis for the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a DSGVO (consent), this consent constitutes the legal basis for the processing of personal data as it may occur during the collection by Google reCAPTCHA.

We also have a legitimate interest in using Google reCAPTCHA to optimize our online service and make it more secure. The corresponding legal basis for this is Art. 6 para. 1 lit. f DSGVO (Legitimate Interests). Nevertheless, we only use Google reCAPTCHA if you have given your consent.

Google also processes data from you in the USA, among other places. We would like to point out that according to the opinion of the European Court of Justice, there is currently no adequate level of protection for the transfer of data to the USA. This may be associated with various risks for the legality and security of data processing.

Google uses so-called standard contractual clauses (= Art. 46. para. 2 and 3 DSGVO) as the basis for data processing for recipients located in third countries (outside the European Union, Iceland, Liechtenstein, Norway, i.e. in particular in the USA) or a data transfer there. Standard Contractual Clauses (SCC) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through these clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the US. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which reference the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

You can learn a bit more about reCAPTCHA on Google’s web developer page at https://developers.google.com/recaptcha/. Google does go into more detail here about the technical development of reCAPTCHA, but you will search in vain for precise information about data storage and privacy-related topics there as well. A good overview of the basic use of data at Google can be found in the in-house privacy notice at https://www.google.com/intl/de/policies/privacy/.

WordPress Static Files

Google reCAPTCHA Privacy Notice Summary
👥 Data subject: Visitors to the website
🤝 Purpose: To ensure website´s functionality
📓 Data processed: Non-personal data such as code, scripts, and media files necessary for displaying and functioning of our website
📅 Storage period: for limited time, depending on browser settings, cache-control headers, and caching mechanisms
⚖️ Legal basis: Art. 6 para. 1 lit. f DSGVO (Legitimate Interests).

 

What is WordPress Static Files?

WordPress Static Files are essential components of our website’s functionality. They include files such as JavaScript, CSS, images, and other static resources that are served to visitors‘ browsers to ensure proper rendering and functionality of our website. 

Why do we use WordPress Static Files on our website?

These files help enhance user experience, improve website performance, and facilitate seamless navigation.

What data is stored by reCAPTCHA?

WordPress Static Files are typically stored on our web server and cached in visitors‘ browsers for a limited period. The storage duration may vary depending on browser settings, cache-control headers, and caching mechanisms implemented on our website. However, no personal data is stored within these static files, and they are not used for tracking or profiling visitors.

How long and where is the data stored?

WordPress Static Files are typically stored on our web server and cached in visitors‘ browsers for a limited period. The storage duration may vary depending on browser settings, cache-control headers, and caching mechanisms implemented on our website. However, no personal data is stored within these static files, and they are not used for tracking or profiling visitors.

Legal basis

The use of WordPress Static Files is essential for the legitimate interests pursued by our website, including ensuring website functionality, performance optimization, and enhancing user experience. As these files do not involve the processing of personal data or infringe upon visitors‘ privacy rights, the legal basis for their use aligns with the legitimate interests provision under applicable data protection regulations.

Closing Words

Congratulations! If you are reading these lines, you have really „fought“ your way through our entire privacy policy, or at least scrolled this far. As you can see from the scope of our privacy policy, we do not take the protection of your personal data lightly.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. However, we do not only want to tell you which data is processed, but also to explain the reasons for the use of various software programs. As
a rule, data protection notices
sound very technical and legalistic. However, since most of you are not web developers or lawyers, we also wanted to take a different approach linguistically and explain the facts in simple and clear language. Of course, this is not always possible due to the subject matter. Therefore, the most important terms are explained in more detail at the end of the data protection information.
If you have any questions about data protection on our website, please do not hesitate to contact us or the responsible office. We wish you a pleasant time and hope to welcome you on our website again soon.

No profiling or automated decision making is carried out.

All texts are protected by copyright.

Status 09.08.2023