Nested Lasers

Privacy Policy

Get in touch

Privacy Policy

Introduction


With the following Privacy Policy, we would like to inform you about the types of personal data (hereinafter also referred to as “Data”) we process, the purposes for which we process it, and the scope of such processing. This Privacy Policy applies to all processing of personal data carried out by us, both in connection with the provision of our services and, in particular, on our websites, in mobile applications, and on external online platforms, such as our social media profiles (hereinafter collectively referred to as the “online offerings”).

The terms used are gender-neutral.

Effective as of: May 21, 2021


Table of Contents

  • Introduction
  • Data Controller
  • Overview of Data Processing Activities
  • Applicable Legal Bases
  • Security Measures
  • Data Processing in Third Countries
  • Use of Cookies
  • Provision of the Online Service and Web Hosting
  • Contacting Us
  • Video Conferences, Online Meetings, Webinars, and Screen Sharing
  • Job Application Process
  • Cloud Services
  • Newsletters and electronic notifications
  • Marketing communications via email, mail, fax, or phone
  • Web analytics, monitoring, and optimization
  • Online marketing
  • Social media presence
  • Plugins, embedded features, and content
  • Management, organization, and support tools
  • Data Deletion

Data Controller

sigma3D GmbH
Marie-Curie-Str. 248712 Gescher
Email address: info(at)sigma3D.de.
Phone: +49 2542 91898-0.

Legal Notice: https://www.sigma3d.de/impressum/.

Overview of Data Processing

The following overview summarizes the types of data processed and the purposes of such processing, and identifies the data subjects.


Types of Data Processed

  • Event Data (Facebook) (“Event Data” refers to data that may be transmitted by us to Facebook—for example, via Facebook Pixel (through apps or other means)—and relates to individuals or their actions; The data includes, for example, information about website visits, interactions with content and features, app installations, product purchases, etc.; the event data is processed for the purpose of creating target audiences for content and advertising (Custom Audiences); Event Data does not include the actual content (such as comments posted), login information, or contact information (i.e., no names, email addresses, or phone numbers). Event data is deleted by Facebook after a maximum of two years; the target audiences created from this data are deleted when our Facebook account is deleted.
  • Master data (e.g., names, addresses).
  • Applicant data (e.g., personal details, mailing and contact addresses, documents submitted as part of the application, and the information contained therein, such as cover letters, resumes, certificates, as well as other information regarding a specific position or voluntarily provided by applicants about their personal details or qualifications).
  • Content data (e.g., entries in online forms).
  • Contact data (e.g., email, phone numbers).
  • Meta/communication data (e.g., device information, IP addresses).
  • Usage data (e.g., websites visited, interest in content, access times).

Categories of Data Subjects

  • Employees (e.g., staff members, job applicants, former employees).
  • Job applicants.
  • Prospective clients.
  • Communication partners.
  • Customers.
  • Users (e.g., website visitors, users of online services).

Purposes of Processing

  • Provision of our online services and user-friendliness.
  • Conversion tracking (measuring the effectiveness of marketing measures).
  • Hiring process (establishment and any subsequent implementation, as well as possible subsequent termination of the employment relationship).
  • Administrative and organizational procedures.
  • Direct marketing (e.g., via email or mail).
  • Feedback (e.g., collecting feedback via an online form).
  • Marketing.
  • Contact requests and communication.
  • Profiles containing user-related information (creation of user profiles).
  • Remarketing.
  • Audience measurement (e.g., traffic statistics, identification of returning visitors).
  • Surveys and questionnaires (e.g., surveys with text fields, multiple-choice questions).
  • Provision of contractual services and customer service.
  • Management and response to inquiries.
  • Target group segmentation (identifying target groups relevant for marketing purposes or other content delivery).

Applicable Legal Bases

Below is an overview of the legal bases under the GDPR on which we rely for the processing of personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations of your or our country of residence or registered office may apply. Furthermore, should more specific legal bases apply in individual cases, we will inform you of these in the Privacy Policy.

  • Consent (Art. 6(1), sentence 1, lit. a GDPR) – The data subject has given consent to the processing of personal data concerning him or her for a specific purpose or for several specific purposes.
  • Performance of a Contract and Pre-Contractual Inquiries (Art. 6(1), first sentence, lit. b GDPR) — Processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
  • Legitimate Interests (Art. 6(1), first sentence, lit. f of the GDPR) - Processing is necessary to safeguard the legitimate interests of the controller or a third party, unless the interests or fundamental rights and freedoms of the data subject that require the protection of personal data take precedence.
  • Job Application Process as a Pre-Contractual or Contractual Relationship (Art. 9(2)(b) GDPR) - To the extent that, as part of the application process, special categories of personal data within the meaning of Article 9(1) of the GDPR (e.g., health data, such as severe disability status or ethnic origin) are requested from applicants, so that the controller or the data subject can exercise the rights arising from labor law and the law on social security and social protection and fulfill their respective obligations in this regard, such processing is carried out pursuant to Article 9(2)(b) GDPR; in the case of protecting the vital interests of applicants or other individuals pursuant to Article 9(2)(c) of the GDPR; or for the purposes of preventive healthcare or occupational medicine, for assessing an employee’s fitness for work, for medical diagnosis, care or treatment in the health or social sector, or for the administration of systems and services in the health or social sector pursuant to Article 9(2)(h) of the GDPR. In the case of the disclosure of special categories of data based on voluntary consent, such data is processed pursuant to Article 9(2)(a) of the GDPR.

National Data Protection Regulations in Germany: In addition to the data protection provisions of the General Data Protection Regulation, national data protection regulations apply in Germany. These include, in particular, the Act on the Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act—BDSG). The BDSG contains, in particular, special provisions regarding the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, it governs data processing for the purposes of the employment relationship (Section 26 BDSG), particularly with regard to the establishment, performance, or termination of employment relationships, as well as the consent of employees. In addition, state data protection laws of the individual federal states may apply.

Security Measures

In accordance with legal requirements, and taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability, and maintaining data segregation. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the erasure of data, and responses to data breaches. Furthermore, we take the protection of personal data into account from the very beginning of the development or selection of hardware, software, and procedures in accordance with the principle of data protection by design and through privacy-friendly default settings.

IP Address Truncation: If IP addresses are processed by us or by the service providers and technologies we use, and the processing of a full IP address is not necessary, the IP address is truncated (also referred to as “IP masking”). In this process, the last two digits or the last part of the IP address after a period are removed or replaced with placeholders. The purpose of truncating the IP address is to prevent or significantly hinder the identification of an individual based on their IP address.

SSL Encryption (https): To protect the data you transmit via our online services, we use SSL encryption. You can recognize such encrypted connections by the prefix https:// in your browser’s address bar.

Data Processing in Third Countries

If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if processing takes place in connection with the use of third-party services or the disclosure or transfer of data to other entities or individuals, entities, or companies, this is done only in accordance with legal requirements. 

Subject to express consent or a transfer required by contract or law, we process or have data processed only in third countries with a recognized level of data protection, contractual obligations through so-called standard data protection clauses of the European Commission, or where certifications or binding internal data protection policies are in place (Articles 44–49 of the GDPR; EU Commission information page: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection_de).

Use of Cookies

Cookies are text files that contain data from visited websites or domains and are stored by a browser on the user’s computer. A cookie is primarily used to store information about a user during or after their visit to an online service. The stored information may include, for example, language settings on a website, login status, a shopping cart, or the point at which a video was viewed. We also include other technologies that perform the same functions as cookies under the term “cookies” (e.g., when user information is stored using pseudonymous online identifiers, also known as “user IDs”).

We distinguish between the following types and functions of cookies:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest after a user leaves an online service and closes their browser.
  • Persistent cookies: Persistent cookies remain stored even after the browser is closed. For example, this allows the login status to be saved or preferred content to be displayed immediately when the user visits a website again. Similarly, users’ interests—which are used for audience measurement or marketing purposes—can be stored in such a cookie.
  • First-party cookies: First-party cookies are set by us.
  • Third-party cookies (also known as third-party cookies): Third-party cookies are primarily used by advertisers (so-called third parties) to process user information.
  • Necessary (also: essential or strictly necessary) cookies: Cookies may be strictly necessary for the operation of a website (e.g., to store logins or other user inputs, or for security reasons).
  • Statistics, Marketing, and Personalization Cookies: Furthermore, cookies are generally also used for audience measurement and when a user’s interests or behavior (e.g., viewing certain content, using features, etc.) on individual web pages are stored in a user profile. Such profiles are used, for example, to display content to users that corresponds to their potential interests. This process is also referred to as “tracking,” i.e., tracking users’ potential interests. To the extent that we use cookies or “tracking” technologies, we will inform you separately in our Privacy Policy or when obtaining your consent.

Notes on Legal Bases: The legal basis on which we process your personal data using cookies depends on whether we ask for your consent. If this is the case and you consent to the use of cookies, the legal basis for processing your data is your explicit consent. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (e.g., in the business operation of our online service and its improvement) or, if the use of cookies is necessary to fulfill our contractual obligations.

Retention Period: Unless we provide you with explicit information regarding the retention period of persistent cookies (e.g., as part of a so-called cookie opt-in), please assume that the retention period may be up to two years.

General Information on Withdrawal and Objection (Opt-Out):  Depending on whether the processing is based on consent or legal authorization, you have the option at any time to withdraw your consent or object to the processing of your data via cookie technologies (collectively referred to as “opt-out”). You can initially exercise your right to object through your browser settings, e.g., by disabling cookies (although this may also limit the functionality of our online services). You can also object to the use of cookies for online marketing purposes through a variety of services—particularly in the case of tracking—via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/. In addition, you can find further information on how to object in the details provided about the service providers and cookies used.

Processing of Cookie Data Based on Consent: We use a cookie consent management process through which users’ consent to the use of cookies—or to the processing activities and providers specified within the cookie consent management process—is obtained, managed, and revoked by the users. In this process, the declaration of consent is stored so that users do not have to be asked for consent repeatedly and so that we can provide proof of consent in accordance with legal requirements. Storage may occur on the server and/or in a cookie (a so-called opt-in cookie, or using comparable technologies) to enable the consent to be associated with a user or their device. Subject to specific information provided by the providers of cookie management services, the following applies: Consent may be stored for up to two years. In this process, a pseudonymous user identifier is generated and stored along with the time of consent, details regarding the scope of consent (e.g., which categories of cookies and/or service providers), as well as the browser, operating system, and device used.

  • Types of data processed: Usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Legal bases: Consent (Art. 6(1), sentence 1, lit. a GDPR), Legitimate Interests (Art. 6(1), sentence 1, lit. f GDPR).

Services and service providers used:

Cookiefirst: Cookie consent management; Service provider: Digital Data Solutions B.V., Plantage Middenlaan 42a, 1018 DH Amsterdam, Netherlands; Website: cookiefirst.com/de/; Privacy Policy: cookiefirst.com/legal/privacy-policy/; Stored data (on the service provider’s server): The user’s IP address, date and time of consent, browser information, the URL from which consent was submitted, an anonymous, random, and encrypted key value; the user’s consent status.

Provision of the Online Service and Web Hosting

In order to provide our online service securely and efficiently, we use the services of one or more web hosting providers, from whose servers (or servers managed by them) the online service can be accessed. For these purposes, we may use infrastructure and platform services, computing capacity, storage space, and database services, as well as security and technical maintenance services.

The data processed in connection with the provision of hosting services may include all information relating to users of our online services that is generated during their use of the services and their communications. This regularly includes the IP address, which is necessary to deliver the content of online services to browsers, and all entries made within our online service or on websites.

Email Sending and Hosting: The web hosting services we use also include the sending, receiving, and storage of emails. For these purposes, the addresses of the recipients and senders, as well as other information regarding email transmission (e.g., the providers involved) and the content of the respective emails, are processed. The aforementioned data may also be processed for the purpose of detecting spam. Please note that emails are generally not sent in encrypted form over the Internet. Although emails are typically encrypted during transmission, they are not encrypted on the servers from which they are sent and received (unless a so-called end-to-end encryption method is used). We therefore cannot assume any responsibility for the transmission of emails between the sender and our server.

  • Types of data processed: Content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user-friendliness, fulfillment of contractual obligations, and customer service.
  • Legal basis: Legitimate interests (Art. 6(1), sentence 1, lit. f of the GDPR).

Services and service providers used:
1&1 IONOS: Hosting platform for e-commerce / websites; Service provider: 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany; Website: https://www.ionos.de; Privacy Policy: https://www.ionos.de/terms-gtc/terms-privacy.

Contacting Us

When you contact us (e.g., via the contact form, email, phone, or social media), the information provided by the person making the inquiry is processed to the extent necessary to respond to the contact requests and any requested actions.

Responding to contact inquiries within the context of contractual or pre-contractual relationships is carried out to fulfill our contractual obligations or to respond to (pre-)contractual inquiries, and otherwise on the basis of our legitimate interests in responding to the inquiries.

  • Types of data processed: Master data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), Meta/communication data (e.g., device information, IP addresses).
  • Data subjects: Communication partners.
  • Purposes of processing: Contact requests and communication.
  • Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1), sentence 1, lit. b of the GDPR), legitimate interests (Art. 6(1), sentence 1, lit. f of the GDPR).

Video Conferences, Online Meetings, Webinars, and Screen Sharing

We use platforms and applications from third-party providers (hereinafter referred to as “conference platforms”) for the purpose of conducting video and audio conferences, webinars, and other types of video and audio meetings (hereinafter collectively referred to as “conferences”). When selecting conference platforms and their services, we comply with legal requirements. 

Data processed by conference platforms: When participants join a conference, the conference platforms process the participants’ personal data listed below. The scope of processing depends, on the one hand, on what data is required for a specific conference (e.g., login credentials or real names) and, on the other hand, on what optional information participants provide. In addition to processing for the purpose of conducting the conference, participants’ data may also be processed by the conference platforms for security purposes or to optimize service. The data processed includes personal information (first name, last name), contact information (email address, phone number), login credentials (access codes or passwords), profile pictures, details regarding professional position/role, the IP address of the internet connection, information about participants’ devices, their operating systems, browsers, and technical and language settings; information regarding the content of communications—i.e., chat entries as well as audio and video data; and the use of other available features (e.g., polls). Communication content is encrypted to the extent technically provided by the conference providers. If participants are registered as users on the conference platforms, additional data may be processed in accordance with the agreement with the respective conference provider.

Logging and Recordings: If text entries, participation results (e.g., from polls), or video and audio recordings are logged, participants will be informed of this transparently in advance and—where necessary—asked for their consent.

Participants’ Data Protection Measures: Please refer to the conference platforms’ privacy policies for details on how your data is processed, and select the security and privacy settings that best suit your needs within the conference platform’s settings. Please also ensure the protection of personal data and privacy in the background of your recording for the duration of a video conference (e.g., by informing roommates, locking doors, and, where technically possible, using the background blurring feature). Links to the conference rooms and access credentials must not be shared with unauthorized third parties.

Notes on Legal Bases: If, in addition to the conference platforms, we also process user data and ask users for their consent to the use of the conference platforms or certain features (e.g., consent to the recording of conferences), the legal basis for the processing is this consent. Furthermore, our processing may be necessary to fulfill our contractual obligations (e.g., in participant lists, when compiling meeting outcomes, etc.). In all other cases, user data is processed based on our legitimate interests in efficient and secure communication with our communication partners.

  • Types of data processed: Master data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), Meta/communication data (e.g., device information, IP addresses).
  • Data subjects: Communication partners, users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and customer service, contact requests and communication, office and organizational procedures.
  • Legal bases: Consent (Art. 6(1), first sentence, lit. a GDPR), performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, lit. b GDPR), legitimate interests (Art. 6(1), first sentence, lit. f of the GDPR).

Services and service providers used:

Microsoft Teams: messaging and conferencing software; service provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; website: products.office.com; Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement, Security Information: https://www.microsoft.com/de-de/trustcenter.

Application Process

The application process requires applicants to provide us with the data necessary for their evaluation and selection. The information required is specified in the job description or, in the case of online forms, in the details provided there. 

Generally, the required information includes personal details such as name, address, contact information, and proof of the qualifications necessary for the position. Upon request, we are also happy to provide additional details regarding what information is needed.

If available, applicants may submit their applications to us via an online form. The data is transmitted to us in encrypted form using state-of-the-art technology. Applicants may also submit their applications to us via email. However, please note that emails are generally not sent in encrypted form over the Internet. As a rule, emails are encrypted during transmission but not on the servers from which they are sent and received. We therefore cannot assume any responsibility for the transmission of the application between the sender and our server. 

For the purposes of candidate sourcing, application submission, and candidate selection, we may use applicant tracking systems, recruitment software, and third-party platforms and services in compliance with legal requirements.

Applicants are welcome to contact us regarding the method of submitting their application or to send their application by mail.

Processing of Special Categories of Data: To the extent that, as part of the application process, special categories of personal data within the meaning of Article 9(1) of the GDPR (e.g., health data, such as severe disability status or ethnic origin) are requested from applicants, so that the controller or the data subject can exercise the rights arising from labor law and the law on social security and social protection and fulfill their respective obligations in this regard, such processing is carried out in accordance with Article 9(2)(b) GDPR; in the case of protecting the vital interests of applicants or other individuals pursuant to Article 9(2)(c) of the GDPR; or for the purposes of preventive healthcare or occupational medicine, for assessing an employee’s fitness for work, for medical diagnosis, for the provision of care or treatment in the health or social sector, or for the administration of systems and services in the health or social sector pursuant to Article 9(2)(h) of the GDPR. If special categories of data are provided on the basis of voluntary consent, their processing is based on Article 9(2)(a) of the GDPR.

Deletion of Data: The data provided by applicants may be further processed by us for the purposes of the employment relationship in the event of a successful application. Otherwise, if the application for a job opening is unsuccessful, the applicants’ data will be deleted. Applicants’ data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time. Subject to a valid revocation by the applicant, the data will be deleted no later than six months after the application is submitted, so that we can answer any follow-up questions regarding the application and fulfill our obligations to provide evidence under the regulations on equal treatment of applicants. Invoices for any travel expense reimbursements are archived in accordance with tax regulations.

Inclusion in a Candidate Pool: Inclusion in a candidate pool, if offered, is based on consent. Applicants are informed that their consent to be included in the talent pool is voluntary, has no impact on the ongoing application process, and that they may withdraw their consent at any time with future effect.

  • Types of Data Processed: Applicant data (e.g., personal information, mailing and contact addresses, documents submitted as part of the application and the information contained therein, such as cover letters, resumes, certificates, as well as other information regarding a specific position or voluntarily provided by applicants about their personal background or qualifications).
  • Data subjects: Applicants.
  • Purposes of processing: Job application process (establishment and any subsequent implementation, as well as possible subsequent termination of the employment relationship).
  • Legal basis: Job application process as a pre-contractual or contractual relationship (Art. 9(2)(b) GDPR).

Services and service providers used:

Cloud Services

We use software services accessible via the Internet and run on their providers’ servers (so-called “cloud services,” also referred to as “Software as a Service”) for the following purposes: document storage and management, calendar management, sending emails, spreadsheets and presentations, sharing documents, content, and information with specific recipients, or publishing websites, forms, or other content and information, as well as participating in chats and audio and video conferences.

In this context, personal data may be processed and stored on the providers’ servers to the extent that such data is part of communications with us or is otherwise processed by us as set forth in this Privacy Policy. This data may include, in particular, users’ master data and contact information, as well as data relating to transactions, contracts, other processes, and their content. The cloud service providers also process usage data and metadata, which they use for security purposes and to optimize their services.

If we use the cloud services to provide forms or similar documents and content for other users or on publicly accessible websites, the providers may store cookies on users’ devices for web analytics purposes or to remember users’ settings (e.g., in the case of media controls).

Notes on Legal Bases: If we request consent for the use of cloud services, the legal basis for the processing is consent. Furthermore, their use may be part of our (pre)contractual services, provided that the use of cloud services has been agreed upon in this context. Otherwise, user data is processed on the basis of our legitimate interests (i.e., interest in efficient and secure administrative and collaboration processes).

  • Types of Data Processed: Master data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), Meta/communication data (e.g., device information, IP addresses).
  • Data subjects: Customers, employees (e.g., staff members, applicants, former employees), prospective customers, communication partners.
  • Purposes of processing: Office and organizational procedures.
  • Legal bases: Consent (Art. 6(1), sentence 1, letter a of the GDPR), performance of a contract and pre-contractual inquiries (Art. 6(1), sentence 1, letter b of the GDPR), legitimate interests (Art. 6(1), first sentence, lit. f of the GDPR).

Services and service providers used:

Microsoft cloud services: Cloud storage services; Service provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA; Website: https://microsoft.com/de-de; Privacy Policy: https://privacy.microsoft.com/de-de/privacystatement, Security Information: https://www.microsoft.com/de-de/trustcenter.

Newsletters and Electronic Notifications

We send newsletters, emails, and other electronic notifications (hereinafter “newsletters”) only with the recipients’ consent or when permitted by law. If the content of a newsletter is specifically described during the subscription process, that description is decisive for the user’s consent. In addition, our newsletters contain information about our services and our company.

To subscribe to our newsletters, it is generally sufficient to provide your email address. However, we may ask you to provide a name—so we can address you personally in the newsletter—or additional information, if such information is necessary for the purposes of the newsletter.

Double-opt-in procedure: Subscription to our newsletter generally takes place via a so-called double-opt-in procedure. This means that after signing up, you will receive an email asking you to confirm your subscription. This confirmation is necessary to ensure that no one can sign up using someone else’s email address. Newsletter subscriptions are logged to provide proof of the subscription process in accordance with legal requirements. This includes storing the time of subscription and confirmation, as well as the IP address. Changes to your data stored with the email service provider are also logged.

Deletion and Restriction of Processing: We may store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them, in order to be able to prove that consent was previously given. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for deletion may be made at any time, provided that the prior existence of consent is confirmed at the same time. In the event of obligations to permanently honor objections, we reserve the right to store the email address solely for this purpose in a blocklist.

The registration process is logged based on our legitimate interests for the purpose of verifying that it was carried out properly. To the extent that we engage a service provider to send emails, this is done based on our legitimate interests in an efficient and secure mailing system.

Notes on Legal Bases: Newsletters are sent based on the recipients’ consent or, if consent is not required, based on our legitimate interests in direct marketing, provided and to the extent that this is permitted by law, e.g., in the case of marketing to existing customers. To the extent that we engage a service provider to send emails, this is done on the basis of our legitimate interests. The registration process is recorded on the basis of our legitimate interests to demonstrate that it was carried out in accordance with the law.

Content: Information about us, our services, promotions, and offers.

  • Types of data processed: Master data (e.g., names, addresses), contact data (e.g., email, phone numbers), meta/communication data (e.g., device information, IP addresses).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g., via email or mail).
  • Legal basis: Consent (Art. 6(1)(a) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
  • Option to opt out: You may unsubscribe from our newsletter at any time, i.e., withdraw your consent or object to receiving further newsletters. You will find a link to unsubscribe from the newsletter either at the end of each newsletter or you can use one of the contact options listed above—preferably email—to do so.

Marketing Communications via Email, Mail, Fax, or Phone

We process personal data for the purpose of sending promotional communications, which may be sent via various channels, such as email, telephone, mail, or fax, in accordance with legal requirements.

Recipients have the right to revoke their consent at any time or to object to promotional communications at any time.

Following revocation or objection, we may store the data necessary to prove consent for up to three years based on our legitimate interests before deleting it. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for deletion may be submitted at any time, provided that the prior existence of consent is confirmed at the same time.

  • Types of data processed: Master data (e.g., names, addresses), contact information (e.g., email, phone numbers).
  • Data subjects: Communication partners.
  • Purposes of processing: Direct marketing (e.g., via email or mail).
  • Legal bases: Consent (Art. 6(1), first sentence, lit. a of the GDPR), legitimate interests (Art. 6(1), first sentence, lit. f of the GDPR).

Web Analytics, Monitoring, and Optimization

Web analytics (also referred to as “reach measurement”) is used to evaluate visitor traffic to our online offering and may include pseudonymized data regarding visitors’ behavior, interests, or demographic information, such as age or gender. With the help of reach analysis, we can, for example, determine at what times our online offering or its features and content are used most frequently, or encourage repeat visits. We can also identify which areas require optimization. 

In addition to web analytics, we may also use testing methods to, for example, test and optimize different versions of our online offering or its components.

For these purposes, so-called user profiles may be created and stored in a file (a so-called “cookie”), or similar methods serving the same purpose may be used. This information may include, for example, content viewed, webpages visited, and elements used on those pages, as well as technical details such as the browser and computer system used, and information regarding usage times. If users have consented to the collection of their location data, this data may also be processed, depending on the provider.

Users’ IP addresses are also stored. However, we use an IP masking procedure (i.e., pseudonymization by truncating the IP address) to protect users. In general, no personally identifiable user data (such as email addresses or names) is stored in the context of web analytics, A/B testing, and optimization; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.

Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.

  • Types of Data Processed: Usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Audience measurement (e.g., access statistics, identification of returning visitors), profiles containing user-related information (creation of user profiles).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6(1)(a) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).

Online Marketing

We process personal data for online marketing purposes, which may include, in particular, the marketing of advertising space or the display of promotional and other content (collectively referred to as “content”) based on users’ potential interests, as well as the measurement of their effectiveness. 

For these purposes, so-called user profiles are created and stored in a file (a so-called “cookie”) or similar methods are used to store information about the user that is relevant for displaying the aforementioned content. This information may include, for example, content viewed, websites visited, online networks used, as well as communication partners and technical details such as the browser and computer system used, and information regarding usage times. If users have consented to the collection of their location data, this data may also be processed.

Users’ IP addresses are also stored. However, we use available IP masking methods (i.e., pseudonymization by truncating the IP address) to protect users. In general, no personally identifiable information (such as email addresses or names) is stored as part of online marketing procedures; instead, pseudonyms are used. This means that neither we nor the providers of the online marketing services know the actual identity of the users, but only the information stored in their profiles.

The information in the profiles is typically stored in cookies or using similar methods. These cookies can generally be read later on other websites that use the same online marketing process, analyzed for the purpose of displaying content, supplemented with additional data, and stored on the server of the online marketing service provider.

In exceptional cases, personal data may be associated with the profiles. This is the case, for example, when users are members of a social network whose online marketing methods we use and the network links users’ profiles to the aforementioned information. Please note that users may enter into additional agreements with the providers, e.g., by giving consent during registration.

We generally only have access to aggregated information regarding the success of our advertisements. However, as part of so-called conversion tracking, we can determine which of our online marketing methods have led to a so-called conversion—that is, for example, the conclusion of a contract with us. Conversion tracking is used solely to analyze the success of our marketing efforts.

Unless otherwise specified, please assume that cookies used are stored for a period of two years.

Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed based on our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.

Target Audience Segmentation with Google Analytics: We use Google Analytics to display ads placed within Google’s advertising services and those of its partners only to users who have shown an interest in our online offering or who exhibit certain characteristics (e.g., interests in specific topics or products, determined based on the websites visited), which we transmit to Google (so-called “remarketing” or “Google Analytics audiences”). We also use Remarketing Audiences to ensure that our ads align with users’ potential interests

Facebook Pixel and Audience Targeting (Custom Audiences): Using the Facebook Pixel (or comparable functions for transmitting event data or contact information via interfaces in apps), Facebook is able, on the one hand, to identify visitors to our online platform as a target group for displaying ads (so-called “Facebook Ads”). Accordingly, we use the Facebook Pixel to ensure that the Facebook Ads we place are shown only to those users on Facebook and within the services of Facebook’s partner networks (the so-called “Audience Network” https://www.facebook.com/audiencenetwork/ ) to those users who have also shown an interest in our online offering or who exhibit certain characteristics (e.g., interest in specific topics or products, as indicated by the websites they have visited) that we transmit to Facebook (so-called “Custom Audiences”). We also use the Facebook Pixel to ensure that our Facebook ads align with users’ potential interests and do not come across as intrusive. Furthermore, the Facebook Pixel allows us to track the effectiveness of Facebook ads for statistical and market research purposes by determining whether users were redirected to our website after clicking on a Facebook ad (so-called “conversion tracking”).

We are jointly responsible with Facebook Ireland Ltd. for the collection or receipt—as part of a transfer (but not the further processing)—of “event data,” which Facebook collects via the Facebook Pixel and comparable functions (e.g., interfaces) running on our online platform, or receives as part of a transfer, for the following purposes: a) Displaying content and advertising information that corresponds to users’ presumed interests; b) Delivery of commercial and transaction-related messages (e.g., contacting users via Facebook Messenger); c) Improving ad delivery and personalizing features and content (e.g., improving the ability to identify which content or advertising information is likely to match users’ interests). We have entered into a special agreement with Facebook (“Addendum for Controllers,” https://www.facebook.com/legal/controller_addendum), which specifically outlines the security measures Facebook must adhere to (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to comply with data subject rights (i.e., users can, for example, submit requests for information or deletion directly to Facebook). Note: When Facebook provides us with metrics, analyses, and reports (which are aggregated—i.e., do not contain information about individual users and are anonymous to us), this processing does not take place under joint controllership but rather on the basis of a data processing agreement (“Data Processing Terms,” https://www.facebook.com/legal/terms/dataprocessing) and the “Data Security Terms” (https://www.facebook.com/legal/terms/data_security_terms) and, with regard to processing in the U.S., on the basis of standard contractual clauses (“Facebook-EU Data Transfer Addendum,” https://www.facebook.com/legal/EU_data_transfer_addendum). Users’ rights (in particular the rights to access, erasure, objection, and filing a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook.

  • Types of Data Processed: Usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses), event data (Facebook) (“Event Data” refers to data that may be transmitted by us to Facebook, for example via Facebook Pixel (through apps or other means), and that relates to individuals or their actions; This data includes, for example, information about website visits, interactions with content, features, app installations, product purchases, etc.; the event data is processed for the purpose of creating target audiences for content and advertising (Custom Audiences); Event Data does not include the actual content (such as comments posted), login information, or contact information (i.e., no names, email addresses, or phone numbers). Event data is deleted by Facebook after a maximum of two years; the target audiences created from this data are deleted when our Facebook account is deleted.
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Marketing, profiles containing user-related information (creation of user profiles), remarketing, audience targeting (identification of audiences relevant for marketing purposes or other content delivery), conversion tracking (measuring the effectiveness of marketing measures), audience targeting.
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6(1), sentence 1, lit. a GDPR), legitimate interests (Art. 6(1), sentence 1, lit. f GDPR).
  • Option to object (opt-out): We refer you to the privacy policies of the respective providers and the opt-out options specified by them. If no explicit opt-out option has been provided, you have the option of disabling cookies in your browser settings. However, this may limit certain features of our online service. We therefore also recommend the following opt-out options, which are summarized and organized by region:

Services Used and Service Providers:

Social Media Presence

We maintain online presences on social media platforms and, in this context, process user data to communicate with users active on those platforms or to provide information about us.

Please note that this may involve the processing of user data outside the European Union. This may pose risks to users, as it could, for example, make it more difficult to enforce their rights.

Furthermore, user data within social media platforms is generally processed for market research and advertising purposes. For example, usage profiles may be created based on users’ behavior and the resulting interests. These user profiles can in turn be used, for example, to display advertisements both within and outside the networks that are presumed to correspond to users’ interests. For these purposes, cookies are typically stored on users’ computers, in which their usage behavior and interests are recorded. Furthermore, data may also be stored in the usage profiles regardless of the devices used by users (particularly if users are members of the respective platforms and are logged in to them).

For a detailed description of the respective forms of processing and the options for opting out, please refer to the privacy policies and information provided by the operators of the respective networks.

We also note that requests for information and the exercise of data subject rights are most effectively addressed directly with the providers. Only the providers have access to the users’ data and can directly take appropriate measures and provide information. If you still need assistance, however, you can contact us.

Facebook: We are jointly responsible with Facebook Ireland Ltd. for the collection (but not the further processing) of data from visitors to our Facebook page (so-called “fan page”). This data includes information about the types of content users view or interact with, or the actions they take (see “Things You and Others Do and Share” in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices users use (e.g., IP addresses, operating system, browser type, language settings, cookie data; see “Device Information” in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Data Policy under “How do we use this information?” , Facebook also collects and uses information to provide analytics services—known as “Page Insights”—to page administrators, so they can gain insights into how people interact with their pages and the content associated with them. We have entered into a specific agreement with Facebook (“Information on Page Insights,” https://www.facebook.com/legal/terms/page_controller_addendum), which specifically sets forth the security measures Facebook must observe and in which Facebook has agreed to comply with data subject rights (i.e., users can, for example, submit requests for information or deletion directly to Facebook). Users’ rights (in particular the rights to access, erasure, objection, and filing a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the “Page Insights Information” (https://www.facebook.com/legal/terms/information_about_page_insights_data).

  • Types of data processed: Contact data (e.g., email, phone numbers), content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Contact requests and communication, feedback (e.g., collecting feedback via online forms), marketing.
  • Legal basis: Legitimate interests (Art. 6(1), first sentence, lit. f of the GDPR).

Services and service providers used:

Plugins, Embedded Features, and Content

We incorporate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos, or city maps (hereinafter collectively referred to as “content”).

This integration always requires that the third-party providers of this content process the user’s IP address, as they would not be able to send the content to the user’s browser without it. The IP address is therefore necessary for displaying this content or these features. We make every effort to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. These “pixel tags” allow information—such as visitor traffic on the pages of this website—to be analyzed. This pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, the time of the visit, and other details regarding the use of our online services; it may also be combined with such information from other sources.

Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, users’ data is processed on the basis of our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.

Facebook Plugins and Content: We are jointly responsible with Facebook Ireland Ltd. for the collection or receipt—as part of a transfer (but not the further processing)—of “event data” which Facebook collects via the Facebook social plugins (and content embedding features) running on our online platform or receives as part of a transfer for the following purposes: a) Displaying content and advertising information that corresponds to users’ presumed interests; b) Delivery of commercial and transaction-related messages (e.g., contacting users via Facebook Messenger); c) Improving ad delivery and personalizing features and content (e.g., improving the ability to identify which content or advertising information is likely to match users’ interests). We have entered into a special agreement with Facebook (“Addendum for Controllers,” https://www.facebook.com/legal/controller_addendum), which specifically outlines the security measures Facebook must adhere to (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to comply with data subject rights (i.e., users can, for example, submit requests for information or deletion directly to Facebook). Note: When Facebook provides us with metrics, analyses, and reports (which are aggregated—i.e., do not contain information about individual users and are anonymous to us), this processing does not take place under joint controllership but rather on the basis of a data processing agreement (“Data Processing Terms,” https://www.facebook.com/legal/terms/dataprocessing) and the “Data Security Terms” (https://www.facebook.com/legal/terms/data_security_terms) and, with regard to processing in the U.S., on the basis of standard contractual clauses (“Facebook-EU Data Transfer Addendum,” https://www.facebook.com/legal/EU_data_transfer_addendum). Users’ rights (in particular the rights to access, erasure, objection, and filing a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook.

  • Types of Data Processed: Usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses), event data (Facebook) (“Event Data” refers to data that may be transmitted by us to Facebook, for example via Facebook Pixel (through apps or other means), and that relates to individuals or their actions; This data includes, for example, information about website visits, interactions with content, features, app installations, product purchases, etc.; the event data is processed for the purpose of creating target audiences for content and advertising (Custom Audiences); Event Data does not include the actual content (such as comments posted), login information, or contact information (i.e., no names, email addresses, or phone numbers). Event data is deleted by Facebook after a maximum of two years; the target audiences created from this data are deleted upon deletion of our Facebook account; inventory data (e.g., names, addresses), contact data (e.g., email, phone numbers), and content data (e.g., entries in online forms).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user-friendliness, provision of contractual services and customer service, marketing, profiles containing user-related information (creation of user profiles).
  • Legal bases: Legitimate interests (Art. 6(1), first sentence, lit. f of the GDPR), Consent (Art. 6(1), first sentence, lit. a of the GDPR), performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, lit. b of the GDPR).

Services and service providers used:

Management, Organization, and Support Tools

We use services, platforms, and software from other providers (hereinafter referred to as “third-party providers”) for the purposes of organizing, managing, planning, and providing our services. When selecting third-party providers and their services, we comply with legal requirements.

In this context, personal data may be processed and stored on the third-party providers’ servers. This may involve various types of data that we process in accordance with this Privacy Policy. Such data may include, in particular, users’ master data and contact information, as well as data related to transactions, contracts, other processes, and their contents.

If users are referred to third-party providers or their software or platforms in the context of communication, business relationships, or other interactions with us, the third-party providers may process usage data and metadata for security purposes, to optimize their services, or for marketing purposes. We therefore ask that you review the privacy policies of the respective third-party providers.

Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Furthermore, their use may be part of our (pre)contractual services, provided that the use of third-party providers has been agreed upon in this context. Otherwise, user data is processed on the basis of our legitimate interests (i.e., our interest in providing efficient, cost-effective, and user-friendly services). In this context, we would also like to draw your attention to the information regarding the use of cookies in this Privacy Policy.

  • Types of Data Processed: Master data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., entries in online forms), usage data (e.g., websites visited, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
  • Data Subjects: Communication partners, users (e.g., website visitors, users of online services).
  • Purposes of processing: Contact requests and communication, managing and responding to inquiries, feedback (e.g., collecting feedback via online forms), surveys and questionnaires (e.g., surveys with input fields, multiple-choice questions), profiles containing user-related information (creation of user profiles).
  • Legal bases: Consent (Art. 6(1), sentence 1, lit. a GDPR), performance of a contract and pre-contractual inquiries (Art. 6(1), sentence 1, lit. b GDPR), Legitimate interests (Art. 6(1), first sentence, lit. f of the GDPR).

Services and service providers used:

Deletion of Data

The data we process is deleted in accordance with legal requirements as soon as the consent authorizing its processing is revoked or other legal grounds for processing no longer apply (e.g., if the purpose for processing this data no longer exists or the data is no longer necessary for that purpose).

If the data is not deleted because it is required for other legally permissible purposes, its processing will be limited to those purposes. This means that the data will be blocked and not processed for any other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary to assert, exercise, or defend legal claims, or to protect the rights of another natural or legal person.

As part of our privacy policy, we may provide users with further information regarding the deletion and retention of data that applies specifically to the respective processing operations.