Privacy Policy
1. Introduction
This website is operated by: Dubly.AI GmbH.
It is very important to us to handle our website visitors' data confidentially and to protect it in the best possible way. For this reason, we make every effort to comply with the requirements of the GDPR.
Below we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you really understand what happens to your data.
2. General information
2.1 Processing of personal data and other terms
Data protection applies to the processing of personal data. Personal data means all data with which you can be personally identified. This is, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently sitting in front of. Such data is processed when 'something happens to it'. Here, for example, the IP is transmitted from the browser to our provider and automatically stored there. This is then a processing (according to Art. 4 No. 2 GDPR) of personal data (according to Art. 4 No. 1 GDPR).
These and other legal definitions can be found in Art. 4 GDPR.
2.2 Applicable regulations/laws - GDPR, BDSG and TDDDG
The scope of data protection is regulated by law. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national law.
In addition, the TDDDG supplements the provisions of the GDPR as far as the use of cookies is concerned.
2.3 The person responsible
The controller within the meaning of the GDPR is responsible for data processing on this website. This is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
You can reach the person responsible at:
Dubly.AI GmbH
Zimmersmühlenweg 27 61440 Oberursel
hello@dubly.ai
2.4 Data Protection Officer
We have appointed a data protection officer for our company. You can reach him under:
simply Legal GmbH
Sebastian Schenk
Burkarderstr. 36, 97082 Würzburg
dpo@dieter-datenschutz.de
2.5 How data is generally processed on this website
As we have already established, there is data (e.g. IP address) that is collected automatically. This data is mainly required for the technical provision of the website. If we also use personal data or collect other data, we will inform you of this or ask for your consent.
You consciously provide us with other personal data.
You will find detailed information on this below.
2.6 Your rights
The GDPR provides you with comprehensive rights. These include, for example, free information about the origin, recipient and purpose of your stored personal data. You can also request the rectification, blocking or erasure of this data or lodge a complaint with the competent data protection supervisory authority. You can revoke your consent at any time.
You can find out what these rights look like in detail and how to exercise them in the last section of this Privacy Policy.
2.7 Data protection - Our view
Data protection is more than just a chore for us! Personal data has great value and careful handling of this data should be a matter of course in our digitalized world. As a website visitor, you should also be able to decide for yourself what "happens" to your data, when and by whom. That is why we are committed to complying with all legal regulations, only collect the data we need and, of course, treat it confidentially.
2.8 Forwarding and deletion
The transfer and deletion of data are also important and sensitive issues. We would therefore like to briefly inform you in advance about our general approach to this.
Data will only be passed on on the basis of a legal basis and only if this is unavoidable. This may be the case in particular if it is a so-called Data Processor and a Data Processing Agreement has been concluded in accordance with Art. 28 GDPR.
We delete your data when the purpose and legal basis for processing no longer apply and the deletion does not conflict with any other legal obligations. Art. 17 GDPR also provides a 'good' overview of this.
For further information, please refer to this Privacy Policy and contact the person responsible if you have any specific questions.
2.9 Hosting
Amazon Web Services (AWS)
Our website uses hosting and infrastructure services from Amazon Web Services (AWS), provided by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855, Luxembourg. AWS enables the operation and delivery of web applications, websites and content through hosting, data transmission and scalable storage and computing services. In particular, technical connection data such as IP addresses, browser information and server accesses are processed as part of the use of and access to our website. Data processing is carried out for the purpose of offering stable, secure web services, maintaining operational security and, if necessary, for error analysis. The legal basis for the processing is Art. 6 para. 1 lit. f GDPR due to the legitimate interest in the reliable and secure provision of online services. AWS itself does not use cookies or comparable technologies for visitors to our website. However, personal data may be transferred to third countries, in particular the USA. This is based on the EU standard contractual clauses, which guarantee the protection of data even when it is processed outside the EEA. The storage period of the logged data depends on the respective purposes and legal requirements; data is deleted as soon as processing is no longer required for the stated purposes or statutory retention periods expire. Further information is available at https://aws.amazon.com/privacy/.
Webflow
Hosting and content management services from Webflow are used on this website. Webflow is provided by Webflow, Inc. represented for the GDPR by Bird & Bird GDPR Representative Services SRL, Avenue Louise 235, 1050 Bruxelles, Belgium. Webflow enables the design, management and delivery of responsive websites including dynamic content, e-commerce functions and integrated forms. In particular, technical connection data (e.g. IP address, time of request, browser information), content of forms filled out via the website (such as name, e-mail address, communication content) and, if applicable, behavioral data (e.g. page views) are processed if these functions are actively used. The data is processed for the purpose of providing and delivering the website content, technical administration, communication and ensuring the stability and security of the website. The legal basis for the processing is Art. 6 para. 1 lit. f GDPR, as the website operators pursue a legitimate interest in the secure and functional provision of the online presence. Insofar as content is provided on a contractual basis (e.g. contact requests), Art. 6 para. 1 lit. b GDPR is also relevant. Webflow uses technically necessary cookies for the provision and basic functionality of the website. Analysis or marketing cookies are only set if corresponding consent is given via the cookie banner. The legal basis for technically necessary cookies is Art. 6 para. 1 lit. f GDPR i.V. m. § 25 para. 2 TDDDG, for all other cookie types Art. 6 para. 1 lit. a GDPR i.V. m. § 25 para. 1 TDDDG. A transfer of personal data to third countries, in particular to the USA, cannot be ruled out in the context of hosting. Webflow uses the EU standard contractual clauses as suitable guarantees to ensure an adequate level of data protection. Data is deleted as soon as it is no longer required to achieve the aforementioned purposes or to fulfill statutory retention obligations or if consent is revoked. Webflow's Privacy Policy is available at the following link: https://webflow.com/legal/privacy
Vercel
For the hosting and provision of our website we use the service Vercel, operated by Vercel GmbH, Ungenannte Str., 13089 Berlin, Germany. Vercel provides a cloud platform for the development, hosting and performance optimization of websites and web applications, including features such as continuous integration/delivery, globally distributed CDN, serverless backends and edge computing. When using Vercel, anonymized page view data such as URLs visited, referrers, country of origin, browser information, performance metrics (web vitals) and the user agent are processed in particular; according to Vercel, personal identification features such as IP addresses or email addresses are not collected by default unless special integrations are used. Data processing is carried out for the purpose of secure and efficient provision of the website, optimization of performance and to ensure operation and to analyze technical faults or malicious queries. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR due to the legitimate interest in an efficient and secure provision of the website. Vercel does not use cookies for the operation of the hosting environment or for analysis. The data collected in this context is not transferred to third countries; processing takes place within the European Union. The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected or, at the latest, after any statutory retention periods have expired or if the legitimate interest no longer applies. Further information on data protection at Vercel can be found at https://vercel.com/legal/privacy-policy.
Supabase
We use Supabase on our website as a backend-as-a-service solution that provides functions such as database management, authentication, file storage and serverless edge functions. Supabase is operated by Supabase, Inc, 3500 S Dupont Hwy, Dover, DE 19901, United States. Supabase enables the management of user databases, the provision of login and registration functions including social login, the synchronization of data in real time and the storage and delivery of files. In particular, personal data such as email addresses and other information provided during registration or authentication, authentication data, IP addresses, usage and interaction data, uploaded files and all content managed via the database are processed. Data processing is carried out for the purpose of technical provision and security of the website, user administration, storage and synchronization of web content and for the implementation of serverless functions. The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as the processing is necessary for the performance of a contract or for the implementation of pre-contractual measures, otherwise Art. 6 para. 1 lit. f GDPR due to our legitimate interest in the secure and high-performance operation of the website and Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG for the use of cookies or comparable technologies, insofar as consent is obtained for this. Supabase may use cookies for functional and security-related purposes; their use is only based on prior consent. Personal data is transferred to a third country (USA). Supabase relies on the EU standard contractual clauses as suitable guarantees within the meaning of Art. 46 GDPR. Data is only stored for as long as is necessary to fulfill the purpose or until consent is revoked; statutory retention periods remain unaffected by this. Further information can be found in Supabase's Privacy Policy at: https://supabase.com/privacy
2.10 Legal basis
The processing of personal data always requires a legal basis. The GDPR provides the following possibilities in Art. 6 para. 1 sentence 1:
a) The data subject has given their consent to the processing of their personal data for one or more specific purposes;
b) Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
c) The processing is necessary for compliance with a legal obligation to which the controller is subject;
d) Processing is necessary in order to protect the vital interests of the data subject or of another natural person;
e) The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
f) Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
In the following sections, we will provide you with the specific legal basis for the respective processing.
3. What happens on our website
When you visit our website, we process your personal data.
We use SSL or TLS encryption to protect this data in the best possible way against unauthorized access by third parties. You can recognize this encrypted connection by the https:// or lock symbol in the address bar of your browser.
Below you can find out what data is collected when you visit our website, for what purpose this is done and on what legal basis.
3.1 Data collection when accessing the website
When you visit the website, information is automatically stored in so-called server log files. This is the following information:
• Browser type and browser version
• Operating system used
• Referrer URL
• Host name of the accessing computer
• Time of the server request
• IP address
This data is temporarily required in order to be able to display our website to you permanently and without any problems. In particular, this data is used for the following purposes:
• System security of the website
• System stability of the website
• Troubleshooting on the website
• Establishing a connection to the website
• Presentation of the website
Data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR and is based on our legitimate interest in the processing of this data, in particular our interest in the functionality of the website and its security.
Where possible, this data is stored in pseudonymized form and deleted once the respective purpose has been achieved.
If the server log files make it possible to identify the data subject, the data is stored for a maximum period of 14 days. An exception is made if a security-relevant event occurs. In this case, the server log files are stored until the security-relevant event has been resolved and finally clarified.
Otherwise, no merging with other data takes place.
3.2 Cookies
3.2.1 General information
This website uses so-called cookies. This is a data record, information that is stored in the browser of your end device and is related to our website.
The use of cookies can make it easier for visitors to navigate the website.
In our cookie consent tool you will find all information about the cookies that we use on our website (if applicable after your consent).
3.2.2 Rejecting cookies
You can manage all cookies that are not technically necessary directly via our cookie consent tool.
You can prevent cookies from being set by adjusting your browser settings.
Here you will find the corresponding links to frequently used browsers:
Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen?redirectslug=Cookies+l%C3%B6schen&redirectlocale=en
Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=de
Microsoft Edge: https://support.microsoft.com/de-de/windows/l%C3%B6schen-und-verwalten-von-cookies-168dab11-0753-043d-7c16-ede5947fc64d
Safari: https://support.apple.com/de-de/guide/mdm/mdmf7d5714d4/web and https://support.apple.com/de-de/guide/safari/sfri11471/mac.
If you are using a different browser, we recommend that you enter the name of your browser and 'delete and manage cookies' in a search engine and follow the official link to your browser.
Alternatively, you can also manage your cookie settings at www.aboutads.info/choices/ or www.youronlinechoices.com.
However, we must point out that a comprehensive blocking/deletion of cookies can lead to impairments in the use of the website.
3.2.3 Technically necessary cookies
We use technically necessary cookies on this website to ensure that our website functions correctly and in accordance with the applicable laws. They help to make the website user-friendly. Some functions of our website cannot be displayed without the use of cookies.
The legal basis for this is Art. 6 para. 1 lit. b, c and/or f GDPR, depending on the individual case.
3.2.4 Technically not necessary cookies
We also use cookies on our website that are not technically necessary. These cookies are used, among other things, to analyze the surfing behavior of the website visitor or to offer functions of the website that are not technically necessary.
The legal basis for this is your consent in accordance with Art. 6 para. 1 lit. a GDPR.
Technically unnecessary cookies are only set with your consent, which you can revoke at any time in the cookie consent tool.
3.3 Data processing through user input
3.3.1 Use of AI
Personal data of visitors to this website may be processed using artificial intelligence (e.g. for the automatic evaluation of contact forms, by means of an AI chatbot or to optimize internal processes).
In particular, contact data and form or chat content may be recorded and analyzed by AI models. The legal basis for this is Art. 6 para. 1 lit. a GDPR (if consent has been given) or Art. 6 para. 1 lit. f GDPR (legitimate interest in increasing efficiency). Data is only transferred to third parties (e.g. CRM providers or external AI service providers) if this is necessary to achieve the stated purposes. The tools used are listed in this Privacy Policy in the context of their functionality and details are provided.
3.3.2 Own data collection
We offer the following (service) on our website: Transcription, translation and dubbing of video content.
We collect the following data for this purpose:
• Name
• E-mail address
• Address
• Phone number
• Account details
The legal basis for this data processing is Art. 6 para. 1 lit. b GDPR.
The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.
3.3.3 Reviews
On our website we offer the possibility to write and submit a review. This can then be published on our website.
This involves processing the data provided by the user when submitting the review. This primarily includes the name, a contact if applicable and the content of the rating.
The legal basis for data processing is consent in accordance with Art. 6 para. 1 lit. a GDPR. Consent can be revoked at any time.
If the evaluation is published, the name and content can be made accessible to the public.
3.3.4 Contact us
a) e-mail
When you contact us by email, we process your email address and any other data contained in the email. This data is stored on the mail server and in some cases on the respective end devices. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.
b) Telephone
If you contact us by telephone, the call data may be stored in pseudonymized form on the respective end device and with the telecommunications provider used. Personal data collected during the telephone call will only be processed in order to process your request. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.
c) Contact form
Contact form (own development)
A self-developed contact form is provided on our website to enable direct contact. The form is used to enter and transmit personal inquiries and we, the website operator, are solely responsible for its technical content. The contact form is generally used to process the communication content entered (such as name, email address and message text), technical metadata (e.g. IP address, time of transmission, browser used) and any other information provided by users. This data is processed for the purpose of processing and responding to inquiries and initiating or processing contractual relationships. The legal basis for the processing is Art. 6 para. 1 lit. b GDPR for the implementation of (pre-)contractual measures or Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in efficient and user-friendly communication. No cookies are set as part of the contact form. Personal data is not transferred to third countries. The data is deleted as soon as it is no longer required to fulfill the purpose, consent is revoked or statutory retention obligations have expired. Further information can be found in this Privacy Policy.
d) Chat
plain.com
This service will be added shortly.
e) Chatbot
plain.com
This service will be added shortly.
f) Appointment scheduling tool
Cal.com
On our website, we use the appointment booking function of Cal.com, a service for online appointment scheduling and automated calendar management, operated by Cal.com, Inc, USA. Cal.com enables the integration of a booking calendar with which visitors can make appointments directly on the website, for example for consultations, demo calls or other services. Personal data such as name, e-mail address, contact information, account data if applicable, registration and booking information, payment data (if payment is made) and electronic communication content are processed in the course of use. The processing is carried out for the purpose of appointment management, customer communication, organization and processing of inquiries and, if necessary, automated workflows in connection with appointment bookings. The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as the booking is made as part of a (pre-)contractual relationship, and Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in the efficient allocation and processing of appointments. Cal.com may use functional cookies or similar technologies that are technically necessary for the provision of the appointment booking function. Analysis or marketing cookies are only used on the basis of consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG. Personal data is transferred to the USA. To secure the transfer, Cal.com states that it uses suitable guarantees, in particular the EU standard contractual clauses. The data is generally deleted as soon as the purpose of storage ceases to apply, if consent is withdrawn or after expiry of statutory retention obligations. Further information can be found in Cal.com's Privacy Policy: https://cal.com/privacy
3.3.5 Questionnaires/Forms
In-house development
We integrate self-developed forms on our website. The data entered is stored on our servers. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time. The legality of the processing that has already taken place remains unaffected by any revocation. The stored data can be made available at any time by e-mail or a request for deletion of the data can be made.
3.4 Cookie Consent Tool
Usercentrics
The consent management tool Usercentrics is used on our website. Usercentrics is a service provided by Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany. The service makes it possible to obtain, manage and document consent to the use of cookies and to the processing of personal data by us and integrated third parties. Usercentrics provides consent banners, documents user decisions and controls which scripts and cookies are loaded depending on the individual consent. In particular, the selected consents (opt-in/opt-out), time stamps of the consents, banner interactions and specific consent statuses for integrated services and cookies are processed. The purpose of data processing is the legally compliant collection and management of consent for the use of non-essential cookies and other tracking technologies as well as proof of consent in accordance with legal requirements. The legal basis for the use of Usercentrics is Art. 6 para. 1 lit. c GDPR to fulfill legal obligations in the area of data protection and Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in transparent and documented consent management; for the setting of non-technically necessary cookies, consent is also obtained in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG, if necessary. Usercentrics uses technical cookies to store consent preferences; these cookies are functionally necessary to ensure compliance with data protection regulations. There is no transfer of personal data to third countries; processing takes place exclusively within the European Union. The recorded consents are deleted as soon as they are no longer required for the documentation, the purposes no longer apply or statutory retention obligations do not prevent deletion; consents can be revoked at any time with effect for the future. Detailed information is available at https://usercentrics.com/privacy-policy/.
Cookiebot
We use the consent management service Cookiebot on our website to manage and document cookie consents, offered by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. Cookiebot enables the display of an individualized consent banner, the automatic recognition and categorization of all cookies used on the website and blocks non-essential cookies and trackers until consent is given by users. In particular, the user's consent preferences (e.g. consent or refusal for necessary, functional, statistical and marketing cookies), the time and status of the consent given, technical metadata on cookies and trackers, as well as anonymous usage data such as browser type, referrer information, timestamps and random identifiers when the analysis function is activated are processed. The purpose of data processing is the legally compliant recording, documentation and management of cookie consents as well as the implementation of legal transparency and verification obligations with regard to the use of cookies and other tracking technologies on this website. The legal basis for the processing of personal data in connection with the use of Cookiebot is Art. 6 para. 1 lit. c GDPR for the fulfillment of legal obligations in the context of consent management and Art. 6 para. 1 lit. f GDPR due to the legitimate interest in a verifiable, data protection-compliant design of the website. The storage and evaluation of any cookie consents by means of technically unnecessary cookies is carried out exclusively on the basis of express consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG, which can be revoked at any time. Cookiebot uses both technically necessary cookies to manage consent and - depending on the selected user decision - optional cookies for analysis and marketing purposes. The exact cookie types and their duration are listed transparently in the cookie banner and can be viewed at any time. Cookiebot does not transfer data to third countries, as data processing takes place within the European Union. Personal data in connection with consent is stored for as long as is necessary for the documentation of consent or in accordance with the statutory retention obligations. Personal data will be deleted at the latest as soon as the purpose of the processing ceases to apply or consent given is revoked, provided that there are no legal retention periods to the contrary. Further information on data protection at Cookiebot can be found at: https://www.cookiebot.com/en/privacy-policy/
3.5 AI services
Anthropic
The Anthropic API is used on our website to provide AI-supported functions. Anthropic is offered by Anthropic PBC, 548 Market Street, PMB 64534, San Francisco, CA 94104-5401, USA. Anthropic's API enables the automated generation, processing and analysis of content as well as the integration of conversational AI solutions into internal and external workflows. In particular, user requests, responses generated by the AI, metadata such as timestamps and device information and, if applicable, data marked as critical by content recognition are processed. The purpose of data processing is to provide AI-based automation, text generation and the optimization of business and communication processes. The legal basis is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in the efficient provision and improvement of interactive content; for the use of any analysis or functionality cookies and the storage of information on end devices, consent is required in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. No cookies are currently set by the API connection. Personal data is transferred to the USA. The EU standard contractual clauses are used as guarantees for an adequate level of data protection. Personal data is only stored for as long as is necessary to achieve the stated purpose or until it is deleted following revocation or on the basis of statutory retention obligations. Further information on data protection at Anthropic can be found at: https://privacy.claude.com/en/
Google APIs
We use various Google APIs services on our website, which are provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to provide functions such as map integration, user authentication, analysis tools or productivity functions. The Google APIs enable, among other things, the integration of interactive maps (Google Maps), login via Google accounts (Google Sign-In), the evaluation of visit data (e.g. Google Analytics), synchronization with Google services such as Calendar or Drive and other API-based integrations. The following personal data may be processed in the course of use Information from the Google account (e.g. email address, name, profile picture depending on the permission granted), IP address, device and browser data, usage and activity data, location-based information (e.g. via the Maps API), communication and metadata (e.g. for calendar or GMail API), as well as input and interaction data from embedded forms or widgets. The purpose of data processing is to enable enhanced website functions, user-friendliness, authentication processes, analysis of user behavior and the integration of Google products. The relevant legal basis in each case depends on the service used and the respective function: If the user's consent is required for the functionality, the data processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR in conjunction with Art. 25 para. 1 TDDD. § 25 para. 1 TDDDG (e.g. setting of analysis or marketing cookies); for technically required integrations, Art. 6 para. 1 lit. f GDPR (legitimate interest in an attractive website) or Art. 6 para. 1 lit. b GDPR (quasi-contractual relationship) is used. If cookies are set as part of specific API services, this is only done with prior consent, depending on their purpose, in particular for analysis and marketing purposes. The legal basis for this is Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG; technically necessary cookies are used on the basis of Art. 6 para. 1 lit. f GDPR or § 25 para. 2 TDDDG. In individual cases, personal data is transmitted to Google servers in third countries, in particular in the USA. Google uses the standard contractual clauses of the European Commission as suitable guarantees within the meaning of Art. 46 GDPR. Google provides further information on this in its own Privacy Policy. The storage period depends on the Google service used and the settings selected: Data is deleted as soon as it is no longer required for the purposes pursued, consent is withdrawn or statutory retention obligations no longer apply. Further information can be found at: https://policies.google.com/privacy
3.6 Newsletter
MailerLite
We use MailerLite to provide our newsletter. This service is provided by MailerLite Limited, 38 Mount Street Upper, Dublin 2, D02 PR89, Ireland. This service can be used to organize and analyse the sending of newsletters. The data entered in order to receive the newsletter is stored on MailerLite's servers. With the help of MailerLite, interactions with the newsletter can be analyzed. In addition, conversion rates can be determined and the users of the newsletter can be categorized in order to adapt the newsletter to the different target groups. This analysis can be objected to via the link in every newsletter message. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. Consent can be revoked at any time when subscribing to the newsletter. The legality of the processing that has already taken place remains unaffected by any revocation. We also use other email services from MailerLite to fulfill our contractual services and for customer administration. The legal basis for this is Art. 6 para. 1 lit. b GDPR. The data will be deleted at the end of the contract between us and MailerLite, unless the website visitor withdraws their consent beforehand. If this is the case, the data will be deleted from the distribution list. In addition, after subscribing to the newsletter, the email address is stored on a blacklist separately from other data for an indefinite period of time. The legal basis for this is Art. 6 para. 1 lit. f GDPR. It serves the interest of website visitors as well as our interest in using/operating a newsletter in accordance with the legal requirements. Further details: https://www.mailerlite.com/features. https://www.mailerlite.com/legal/privacy-policy.
3.7 Analysis and tracking tools
Google Ads
Our website uses Google Ads, an online advertising service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to place, control and analyze advertisements. Google Ads makes it possible to place targeted ads based on usage data, to measure the reach of advertising measures and to offer so-called conversion and remarketing functions. Depending on the integration, the following personal data may be processed IP address, information on browser and device type, pages and URLs accessed, click data, location data (if available), conversion and engagement information (e.g. purchases, completed forms), as well as contact information pseudonymized using a hash when using enhanced conversions. The data is processed in order to efficiently manage advertising campaigns, measure the success of advertisements (conversion tracking), retarget website visitors (remarketing), analyze user behavior with regard to advertisements and optimize advertising playout. The legal basis for the processing of personal data when using Google Ads is generally consent in accordance with Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as cookies or comparable technologies are used for recognition; the use can be based on Art. 6 para. 1 lit. f GDPR in individual cases, provided that there is a legitimate interest in efficient marketing and no consent is required. Google Ads uses cookies and similar technologies as part of its functions to evaluate user behavior, measure conversions and create target groups; if this concerns analysis, conversion and marketing cookies, they are only set with the active consent of the website visitor in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with Art. 25 para. 1 TDDD. § 25 para. 1 TDDDG. A transfer of data to third countries, in particular to the USA, cannot be ruled out; for such transfers, Google uses the EU standard contractual clauses as suitable guarantees in accordance with Art. 46 GDPR. Personal data is stored for as long as it is required for the stated purposes or until consent is withdrawn; statutory retention obligations remain unaffected, after which it is deleted. Further information on data protection at Google and specific information on Google Ads can be found at: https://policies.google.com/privacy?hl=de
Meta pixel
We use meta pixels on this website. Meta Pixel is a conversion tracking tool. This service is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Meta Pixel enables us to track the behavior of visitors after they have been redirected to the website via a Facebook ad. Meta-Pixel uses cookies for its own advertising purposes. The data is stored and processed by Facebook so that a connection to the respective user profile can be established. The data collected is also transferred to the USA and other third countries. The standard contractual clauses (SCC) of the EU Commission apply to data transfers to the USA. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time. If personal data is collected on this website using meta pixels and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for data processing in accordance with Art. 26 GDPR. This joint responsibility is limited exclusively to the collection and transfer of data to Facebook. There is an agreement on joint processing for this: https://www.facebook.com/legal/controller_addendum. We are responsible for providing the data protection information when using the Facebook tool and for the secure integration of the tool on the corresponding website in accordance with data protection law. Facebook, on the other hand, is responsible for the data security of its products. This means that data subjects' rights with regard to data processed by Facebook must be asserted directly with Facebook. Further details: https://de-de.facebook.com/about/privacy/ https://www.facebook.com/ads/preferences/?entry_product=ad_settings_scrnen http://www.youronlinechoices.com/de/praferenzmanagement/ https://www.facebook.com/legal/EU_data_transfer_addendum https://de-de.facebook.com/help/566994660333381.
OpenAI Ads pixel
We use the OpenAI Ads pixel on this website, a conversion tracking tool for advertisements shown in ChatGPT. The service is provided by OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. When visitors reach our website by clicking an advertisement in ChatGPT, the pixel reads the click identifier appended to the link and stores it in a cookie on our domain, so that a later registration or purchase in our application at app.dubly.ai can be assigned to that advertisement. In doing so the pixel processes the IP address, browser information (user agent), the page visited, a timestamp, the click identifier and a browser identifier, and transmits them to OpenAI. With consent we additionally report the completed registration to OpenAI from our server, together with the e-mail address in hashed form, so that the assignment also works when the pixel is blocked. The processing serves to measure the success of our advertising campaigns and to assign conversions to advertisements. The legal basis is consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG; without consent the pixel is not loaded and no data is transmitted. Consent can be revoked at any time via the cookie settings. Personal data may be transferred to OpenAI servers in the USA; the standard contractual clauses of the EU Commission serve as suitable guarantees in accordance with Art. 46 GDPR. The cookie holding the click identifier is stored for a maximum of 30 days. Further information on data protection at OpenAI: https://openai.com/policies/eu-privacy-policy/
LinkedIn Insight Tag
Our website uses the LinkedIn Insight Tag, an analysis and tracking service provided by LinkedIn Ireland Unlimited Company, Gardner House, 2 Wilton Place, Dublin 2, Ireland. The LinkedIn Insight Tag enables website visits to be analyzed, conversions to be measured and target groups to be created for LinkedIn advertising campaigns. The service typically collects the IP address, device type, operating system, referral source, referrer domain, URLs visited, timestamps, page views, form submissions and - if visitors are LinkedIn members - information such as job title, company and industry. The processing is carried out for the purposes of web analysis, measuring the success of advertising measures, target group formation and retargeting. The legal basis for the use of the LinkedIn Insight Tag is consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG, insofar as information is stored in the end device or information already stored in the end device (e.g. cookies) is accessed. If consent is not given, no processing takes place. The service sets cookies that are used both to analyze website usage and for marketing purposes through targeted advertising on external platforms; these cookies are only set with express consent. Personal data may be transferred to third countries such as the USA. In these cases, LinkedIn uses the standard contractual clauses approved by the European Commission as suitable guarantees in accordance with Art. 46 GDPR. The stored data is generally deleted as soon as it is no longer required for the stated purposes or consent is revoked, provided that there are no legal retention obligations to the contrary. Further information on data protection at LinkedIn can be found at https://www.linkedin.com/legal/privacy-policy
PostHog
Our website uses the analytics service PostHog, which is operated by PostHog, Inc, 2261 Market Street, Suite 4008, San Francisco, California 94114, USA. PostHog enables the collection and evaluation of usage data to analyze user behavior, for example by recording clicks, page views, form submissions, session histories, A/B tests and feature usage. Typical data such as IP address (unless deactivated), browser information (type, device, operating system), session data, URL paths, referrers, usage-related events, HTML attributes of relevant elements and unique user IDs may be processed. Processing is carried out for the purpose of analyzing and optimizing our website, troubleshooting, measuring the success of product functions and improving user-friendliness. As a rule, the legal basis is consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § Section 25 (1) TDDDG, provided that a corresponding consent has been given in the cookie banner. Insofar as consent is not required for technically necessary data processing, the processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR out of a legitimate interest in economic and secure web optimization. Cookies may be set for analysis and tracking purposes, which are only used with prior consent. Technically necessary cookies may be used without consent; further details can be found in the website's cookie banner. Personal data may be transferred to the USA. For these transfers, PostHog relies on the standard contractual clauses of the EU Commission as suitable guarantees in accordance with Art. 46 para. 2 lit. c GDPR. Personal data is stored for as long as is necessary for the purposes of the analysis or until consent is withdrawn, provided there are no statutory retention obligations to the contrary. If the data is no longer required for the stated purposes, it will be deleted. Further information is available at https://posthog.com/privacy.
Vercel Analytics
This website uses the Vercel Analytics service of Vercel Inc, 440 N Barranca Ave #4133, Covina, CA 91723, USA, to analyze usage and performance. Vercel Analytics makes it possible to collect and evaluate anonymous statistics on page views, URLs visited, referrer, visitor country, device used (mobile device/tablet/desktop), operating system, browser information and optionally customer-specific defined events (such as clicks on certain buttons or logins). In particular, anonymized visitor IDs (daily reset), pages accessed, referrers, country information, device type, operating system and browser and - if configured - individual usage events are processed. No personal data such as personally identifiable IP addresses or other directly identifying information is stored. The purpose of data processing is the evaluation of website usage for the continuous improvement of content and technical offers as well as for the analysis of usage events for optimization purposes. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR, based on the legitimate interest in a statistical analysis of the website and the optimization of the online offer. Vercel Analytics does not use cookies or third-party scripts or other tracking mechanisms that enable the identification of individual users. Therefore, no cookies or comparable identifiers are stored. Personal data is not transferred to third countries, in particular to the USA, as Vercel Analytics only processes data in anonymized form. The stored data is deleted as soon as it is no longer required to achieve the purpose of its processing or a justified objection to the processing is made, provided there are no statutory retention obligations. Detailed information on data processing by Vercel Analytics can be found at: https://vercel.com/docs/analytics/privacy-policy
Vercel Speed Insights
This website uses the analysis tool Vercel Speed Insights from Vercel Inc, 440 N Barranca Avenue #4133, Covina, CA 91723, United States. Vercel Speed Insights is used to monitor and analyze web performance and provides, among other things, analyses of core web vitals and to evaluate the effects of deployments. The service collects anonymous performance data, including metrics such as First Contentful Paint (FCP), Largest Contentful Paint (LCP), Cumulative Layout Shift (CLS), Time to First Byte (TTFB), First Input Delay (FID) and Interaction to Next Paint (INP). In addition, information on the type of device used, browser, country, network speed and page paths accessed is processed. According to Vercel, IP addresses or other uniquely identifying information are not stored. The data processing is carried out for the purpose of continuous monitoring, analysis and optimization of website performance, as well as for the diagnosis of performance bottlenecks and the evaluation of changes in new deployments. The legal basis for the use of Vercel Speed Insights is Art. 6 para. 1 lit. f GDPR, based on the legitimate interest in optimizing and ensuring the technical functionality and user-friendliness of the website. No cookies are set on the end device as part of Vercel Speed Insights. Data is transmitted to Vercel Inc. in the United States. The Standard Contractual Clauses (SCC) of the European Commission are used as a suitable guarantee to ensure an adequate level of data protection. The performance data collected is deleted as soon as it is no longer required for the aforementioned analysis and optimization purposes or if there is a justified objection, provided that there are no statutory retention obligations to the contrary. Further information on data protection at Vercel Speed Insights can be found at: https://vercel.com/docs/speed-insights/privacy-policy
Calendly
On our website, we use the appointment scheduling and analysis functions of Calendly, operated by Calendly, LLC, 115 E Main St Ste A1B, Buford, GA 30518, United States. Calendly enables automated online appointment booking and provides a calendar and embeddings that allow the booking of appointments and meetings directly via the website, as well as the possibility of analyzing and tracking bookings made, e.g. through integration into web analytics tools such as Google Analytics. When using Calendly, in particular page views of appointment scheduling forms, form submissions, selection of date and time, the actual booking made and - if linked via third-party integrations - possibly also the e-mail address used, content of the booked appointment and UTM or referrer data are processed. This data processing serves the purpose of the organizational processing of appointments, the optimization of customer experiences and the evaluation of conversion rates in the context of marketing. The legal basis for the analysis and tracking functions of Calendly is regularly the consent pursuant to Art. 6 para. 1 lit. a GDPR in conjunction with. § In individual cases, Art. 6 para. 1 lit. b or f GDPR may also be relevant if an appointment booking serves directly to fulfill the contract or if our legitimate interest in efficient appointment processing and performance measurement prevails. When Calendly is integrated, cookies may be used depending on the functionality and integration; cookies are primarily used for functional purposes and for web analysis. Analysis and tracking cookies are only stored on the basis of consent. In connection with the use of Calendly, personal data may be transferred to the USA; the EU standard contractual clauses are used as sufficient guarantees for the level of data protection. Personal data will be deleted as soon as the purpose of the processing no longer applies, in particular after an appointment has been made or consent has been withdrawn, provided that there are no statutory retention periods to the contrary. Further information can be found in Calendly's Privacy Policy: https://calendly.com/legal/privacy-notice
HubSpot
Our website uses the analysis and tracking service HubSpot, operated by HubSpot, Inc, 1 Sir John Rogerson's Quay, Dublin 2, Ireland. HubSpot provides functions for marketing automation, lead generation, analysis of user behavior and the integration of CRM systems. Typically, the IP address, email address (for form entries), browser information, pages visited, entries in web forms, interactions with pop-ups and forms, engagement histories and traffic analysis data are processed. The processing is carried out for the purpose of measuring success and optimizing marketing measures, personalizing content, generating leads and analyzing and evaluating user behavior. The legal basis is regularly the consent pursuant to Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG, insofar as tracking technologies or cookies are used, as well as Art. 6 para. 1 lit. f GDPR for technically necessary analyses or to safeguard legitimate interests in targeted marketing. HubSpot uses various cookies, including analysis and personalization cookies, which are only activated with prior consent. Technically necessary cookies are used on the basis of Section 25 (2) TDDDG. Data may be transferred to locations outside the European Economic Area; in this case, HubSpot uses the EU standard contractual clauses as appropriate safeguards in accordance with Art. 46 GDPR to ensure an adequate level of data protection. The storage period of the processed data depends on the respective processing purpose; it will be deleted as soon as the purpose no longer applies or consent is revoked, provided that there are no legal storage obligations to the contrary. Further information can be found in HubSpot's Privacy Policy: https://legal.hubspot.com/privacy-policy
Facebook Conversion API
This website uses the Facebook Conversion API of Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin, D02 X525, Ireland, to transmit server-side events and user interactions to Meta and to improve the accuracy of the performance measurement of online advertising campaigns. With the help of the API, events such as purchases, completed forms, registrations or other website interactions are transmitted directly from the server to Meta in order to better evaluate and optimize advertising measures and their effectiveness - even if browser cookies are restricted or the Facebook pixel is blocked. The categories of data processed include, in particular, IP address, browser information (user agent), Facebook-specific identifiers (e.g. fbc, fbp), e-mail address and telephone number (each hashed), timestamp and event information and, if applicable, other usage-related parameters. The processing of the data is used to analyze and optimize advertising campaigns, to measure success and to assign conversions to advertisements. The legal basis for the use of the Facebook Conversion API is generally consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with Section 25 para. 1 TDDDG, provided that such consent was given in the context of the cookie banner; no transmission takes place without consent. As part of the Conversion API, cookies are set or read for advertising and analysis purposes (including, for example, the "fbp" cookie for recognition and assignment). The storage and access to information in the end device as well as the forwarding are carried out exclusively on the basis of an actively granted consent (Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG). Personal data may be transferred to third countries, in particular to Meta servers in the USA; the standard contractual clauses published by the EU Commission are used as suitable guarantees. Data is deleted as soon as the purpose of processing no longer applies, consent is withdrawn or statutory retention periods require deletion. Further information on data processing by Meta is available at https://www.facebook.com/privacy/policy/.
3.8 Social media plugins
YouTube
Video content is integrated on this website via the YouTube service, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. YouTube allows videos to be displayed directly on the website, providing multimedia content for information and entertainment and strengthening user loyalty. Personal data is regularly processed, including IP address, browser and device information, usage data such as playback and interaction behavior and, if applicable, account-related data if users are logged in with a Google or YouTube account during use. The purpose of data processing is to provide video content, make the website appealing, increase reach and promote interaction. The legal basis for the integration is Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG, provided that consent to the use of cookies and comparable technologies has been given. No integration or transmission of personal data to YouTube takes place without consent. YouTube uses cookies and similar technologies as part of the video integration, which are used in particular for analysis, functional and marketing purposes. These are only set on the basis of the user's express consent. When using YouTube, personal data may be transferred to Google LLC companies in the USA. In this case, the transfer takes place on the basis of the EU standard contractual clauses of the European Commission as suitable guarantees within the meaning of Art. 46 para. 2 lit. c GDPR. Personal data will be deleted as soon as it is no longer required for the processing purposes or consent has been revoked, provided that there are no statutory retention obligations to the contrary. Further information on data protection at YouTube can be found at: https://policies.google.com/privacy?hl=de
3.9 Social media profiles
In addition to our website, our company is also present on social networks. Here we want to present our company and create the opportunity to get in touch with us.
We also use the opportunity to place advertisements and job advertisements on social media.
In the following, we provide information about which data we and the respective social network process when you visit and interaction with our profile.
We operate a Facebook fan page on https://www.facebook.com/. This social network is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Interaction with our company profile
When you visit our Facebook profile and interact with us, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information. The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our Facebook profile. Insofar as an inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.
Page Insights
As explained in the Meta Privacy Policy under "How do we use your information?", Meta also collects and uses information to provide analytics services, known as Page Insights, for page operators. This also applies to our Facebook page. Page insights are summarized statistics that are created based on certain interactions of visitors with pages and the content associated with them (e.g. viewing a page or a video, subscribing to a page, marking a page with "Like" or "No longer like", etc.) and are logged by the Meta servers. Meta provides us with summarized statistics and insights in connection with the Page Insights, which give us information about how people interact with our company website. We do not have access to any personal data, only to the summarized Page Insights. With the help of Page Insights, we can view anonymous statistics, e.g. the reach of our account, page views, likes, etc.. These also contain evaluations according to the age, gender and location of the users (as specified by them in their respective Facebook profiles). To evaluate the reach, we can make settings or set appropriate filters with regard to the selection of a time period, the viewing of a specific post and demographic groupings. This data is anonymized. It is not possible for us to draw conclusions about specific individuals. The purpose of processing this data is to analyze our reach and adapt our content and advertisements to user interests so that visitors can derive the greatest possible benefit from them. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target group-specific content and place advertising to better market our company and our services. The processing is based on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. When processing personal data in the course of the so-called Page Insights, we are jointly responsible with Facebook in accordance with Art. 26 para. 1 GDPR. We have concluded a corresponding agreement with Facebook for this purpose, which can be viewed here: https://www.facebook.com/legal/terms/page_controller_addendum. Facebook's contact details are as follows: Online contact: https://www.facebook.com/help/contact/1650115808681298 Postal: Meta Platforms Ireland Limited, ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland. For Facebook, you can contact the data protection officer at the following link: https://www.facebook.com/help/contact/540977946302970. Further information about Page Insights: https://de-de.facebook.com/legal/terms/page_cntroller_addendum
Processing of personal data and cookies by Meta
When a Facebook page is accessed, the IP address assigned to the end device is transmitted to Facebook. According to Facebook, this IP address is anonymized (for "German" IP addresses). Facebook also stores information about the end devices of its users (e.g. as part of the "login notification" function); Facebook may thus be able to assign IP addresses to individual users. Anyone who is currently logged in to Facebook has a cookie with a Facebook identifier on their device. This enables Facebook to track who has visited this page and how it has been used. Facebook buttons integrated into websites enable Facebook to record visits to these websites and assign them to Facebook profiles. This data can be used to offer personalized content or advertising. Information on how personal data can be managed or deleted can be found in Facebook's Privacy Center: https://www.facebook.com/privacy/center/. More information on how Facebook handles data can be found here: http://de-de.facebook.com/about/privacy.
WhatsApp channel
We operate a WhatsApp channel. The channel is operated by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Through WhatsApp channels, information and relevant messages can be played out directly on WhatsApp by subscribing to channels of people and organizations. When a channel is subscribed to, messages are sent in the form of text messages, links to information, images or videos. Channels are public, which means that anyone can find, follow and view them. Since channels are public and the number of users is unlimited, channel status messages are visible to everyone and to WhatsApp. WhatsApp collects information from users, for example about their reactions, their choice of language and the channels they follow. However, we ourselves as the operator do not have access to personal data. WhatsApp channels are designed in such a way that operators do not receive any information such as the identity or contact details of users. Information about data processing by WhatsApp: https://www.whatsapp.com/legal/channels-privacy-policy-eea?lang=de_DE.
We operate an Instagram profile. This social media platform is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Interaction with our company profile
When you visit our Instagram profile and interact with us, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information. The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our Instagram profile. Insofar as a request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.
Insights
As explained in the Meta Privacy Policy under "How do we use your information?" (https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect), Meta also collects and uses information to provide analytics services, known as insights, for site operators. This also applies to our Instagram profile. Insights are summarized statistics that are created based on certain interactions of visitors with pages and the content associated with them and are logged by the Meta servers. This includes the following information: - how many people see and interact with our products, services or content, such as posts, videos, Instagram pages, advertisements, stores and advertisements (if the advertisement is shown on Meta products); - how people interact with our content, websites, apps and services; - which group of people interact with our content or which group of people use our services. Meta provides us with aggregated reports and insights that tell us how well our content, features, products and services are performing. We do not have access to personal data, only to the summarized reports. To evaluate the reach, we can make settings or set appropriate filters with regard to the selection of a time period, the viewing of a specific post and demographic groupings. This data is anonymized. It is not possible for us to draw conclusions about specific individuals. The purpose of processing this data is to analyze our reach and adapt our content and advertisements to user interests so that visitors can derive the greatest possible benefit from them. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target-group-specific content and place advertising to better market our company and our services. The processing is based on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. When processing personal data in the course of the so-called Insights, the processing is carried out in joint responsibility with Meta in accordance with Art. 26 para. 1 GDPR. We have entered into a corresponding agreement with Meta for this purpose, which can be viewed [here](https://www.facebook.com/legal/terms/page_controller_addendum.). Meta's contact details are as follows: Online contact: https://www.facebook.com/help/contact/1650115808681298 Postal: Meta Platforms Ireland Limited, ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland. For Instagram, you can contact the data protection officer at the following link: https://www.facebook.com/help/contact/540977946302970. Further information about Insights: https://de-de.facebook.com/help/pages/insights. The complete privacy policy of Instagram: https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect
Processing of personal data and cookies by Meta
When an Instagram page is accessed, the IP address assigned to the end device is transmitted to Meta. According to Meta, this IP address is anonymized (for "German" IP addresses). Meta also stores information about the end devices of its users (e.g. as part of the "login notification" function); Meta may thus be able to assign IP addresses to individual users. If you are currently logged in to Instagram as a user, a cookie with the Instagram identifier is stored on the end device. This enables Meta to track who has visited and used this page. Meta buttons integrated into websites enable Meta to record your visits to these websites and assign them to your Instagram profile. This data can be used to offer personalized content or advertising. Further information: https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect
We operate a LinkedIn profile on https://www.linkedin.com/. This social network is operated by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.
Interaction with our company profile
When you visit our LinkedIn profile and interact with us, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information. The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our LinkedIn profile. Insofar as a request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.
Page Insights
LinkedIn provides us with aggregated statistics and insights (called Page Insights) that tell us how people interact with our Company Page. Among other things, we receive information about the number of profiles that view, comment on or otherwise interact with our posts, as well as aggregated demographic and other information that helps us learn about the interaction with our page or LinkedIn profile. Page Insights provided to us by LinkedIn consist of aggregated data, and LinkedIn does not provide us with any personally identifiable information about members in relation to Page Insights. We also have no way of linking Page Insights to individual members. When placing ads, LinkedIn provides us with information about the types of people who see our ads and the success of our ads. Personal data is only passed on to us if this person has consented to such processing. We also receive information from LinkedIn that allows us to understand which of our ads led to a purchase being made or an action being taken. This data is processed for the purpose of analyzing our reach and adapting our content and ads to user interests. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target-group-specific content and place advertisements in order to better market our company and our services. The processing is based on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. When processing personal data in the course of the so-called Page Insights, the processing is carried out in joint responsibility with LinkedIn in accordance with Art. 26 para. 1 GDPR. We have concluded a corresponding agreement with LinkedIn for this purpose, which can be viewed [here](https://legal.linkedin.com/pages-joint-controller-addendum). LinkedIn's contact details are as follows: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. For LinkedIn, you can contact the data protection officer at the following link: https://www.linkedin.com/help/linkedin/ask/TSO-DPO.
Processing by LinkedIn
By visiting our company profile, LinkedIn may also process additional personal data. In this case, the processing is carried out under the sole responsibility of LinkedIn and without our knowledge. More information from LinkedIn on this: https://de.linkedin.com/legal/privacy-policy.
TikTok
We operate a TikTok channel. TikTok is provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (hereinafter "TikTok Ireland"). Our TikTok channel gives us the opportunity to present ourselves to TikTok users and to get in touch with them.
Interactions with our TikTok channel
Users can interact with our TikTok channel via their TikTok account, for example by liking or commenting on our posts. In doing so, we process the associated data such as the user name and profile picture. We use this data to optimize our content and its presentation and to adapt it to the respective user interests. It is also possible to send us direct messages on our TikTok channel. The user name and profile picture are also displayed here. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in optimizing our TikTok channel and the content published there. We also have a legitimate interest in communicating with users in order to answer questions, respond to criticism, build a relationship and exchange information. This enables us to improve our services and respond to the needs of potential customers. By communicating via TikTok, we reach younger customers in particular. Comments are stored on the channel for an unlimited period of time and can be viewed by other users. The same applies to the use of the Like function and direct messages.
TikTok analysis
When our TikTok channel is accessed and used, additional data is processed for TikTok analysis. These are summarized statistics that are created and logged by TikTok based on certain interactions of visitors with our TikTok channel and provide information about how our channel is interacted with. This data includes, but is not limited to:
- Follower growthVideo viewsProfile viewsLikes, comments and sharesAverage watch timePercentage of viewers who watch the entire videoSources of traffic (e.g. profile, For You feed)Geographical distribution of audienceFollower activity times.
The data is provided to us in aggregated form as statistics. We do not have access to personal data, only to the summarized statistics. Further information on TikTok analyses can be found here: https://www.tiktok.com/creators/creator-portal/en-us/tiktok-content-strategy/understanding-your-analytics/. This data is processed solely for the purpose of analyzing and improving the content on our TikTok channel. By evaluating this data, we can recognize how our content and our TikTok channel are consumed. This enables us to create target group-oriented content and, if necessary, to place advertising in order to better market our company and our services. The processing is based on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. When processing personal data in the course of TikTok analyses, the processing is carried out in joint responsibility with TikTok in accordance with Art. 26 para. 1 GDPR. We have concluded a corresponding agreement with TikTok for this purpose, which can be viewed here. TikTok's contact details are as follows: Online contact: https://privacytiktok.zendesk.com/hc/en-us/requests/new. By post: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. You can contact TikTok's Data Protection Officer using this form: https://www.tiktok.com/legal/report/DPO.
Processing of personal data by TikTok
When using TikTok's services, TikTok processes the personal data of users. This includes data such as your IP address, location data, time zone settings, advertising IDs, app and browser versions and device data (system, network type, device ID, screen resolution, operating system, audio settings and connected audio devices). The TikTok profiles and channels accessed, likes, messages and other usage data are also processed. If you are logged in with your own TikTok account, this data will be assigned to your account. Further information on the processing of data by TikTok can be found here: https://www.tiktok.com/legal/page/eea/privacy-policy/de.
X (formerly Twitter)
We use the short message service "X" (formerly Twitter). This is a service provided by X Corp, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland, is responsible for the data processing of persons living outside the United States.
Interactions with our account
In principle, we do not collect or process any personal data when you use our short message service. The data entered on X, in particular the user name and the content published under the account, is processed by us on the basis of consent in accordance with Art. 6 para. 1 lit. a GDPR, insofar as the tweets are retweeted, if applicable, we reply to them or tweets are written that refer to the account. The data freely published and disseminated on X is thus included by us and made accessible to our followers.
Data processed by X
We have no control over the nature and extent of the data processed by X Corp., how it is processed and used, or whether it is disclosed to third parties. When you use X, personal data will be collected, transferred, stored, disclosed and used by X Corp. and transferred to, stored and used in the United States, Ireland and any other country in which X Corp. does business, regardless of your country of residence. On the one hand, X processes all voluntarily entered data such as name and user name, e-mail address, telephone number or the contacts of the address book, insofar as these have been uploaded or synchronized. On the other hand, X also evaluates the shared content to determine which topics the user is interested in. Confidential messages that are sent directly to other users are processed and stored by X. X can use GPS data, information on wireless networks or the IP address to determine the user's location. X also receives information about what content is viewed, even if the user has not created an account. X processes so-called "log data". This includes the IP address, the browser type, the operating system, information on the previously accessed website and the pages accessed, the location, the mobile phone provider, the end device used (including device ID and application ID), the search terms used and cookie information. Due to the fact that X Corp. is a non-European provider that only has a European branch in Ireland, it is not bound by German data protection regulations in its own opinion. This applies, for example, to the rights to information, blocking or deletion of data or the possibility of objecting to the use of usage data for advertising purposes. The processing of data can be restricted in the general settings of the X account and under "Data protection and security". In addition, on mobile devices (smartphones, tablet computers), X's access to contact and calendar data, photos, location data, etc. can be restricted in the settings options there. However, this depends on the operating system used. Further information can be found here: https://help.twitter.com/de/safety-and-security/x-privacy-settings. Information on the processing of data by X can be found in X's Privacy Policy: https://twitter.com/de/privacy. In addition, information can be requested via the X data protection form or the archive requests: https://support.twitter.com/forms/privacy
YouTube
The social profile and functions of YouTube are integrated on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. YouTube enables the display of video content, the increase of reach and user interaction as well as the presentation of social media profiles directly on the website. As part of the integration, YouTube processes personal data such as IP addresses, unique identifiers (e.g. device or browser IDs), usage and interaction data (such as videos viewed, playback times and click activities), demographic and preference information as well as information obtained via cookies and similar technologies. The purpose of data processing is to provide video content, display the YouTube profile, improve the user experience and analyze interactions to optimize the website and increase reach. As a rule, Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG serves as the legal basis, provided that consent has been given for processing and for the setting of cookies and comparable technologies. For purely technical, absolutely necessary processes, Art. 6 para. 1 lit. f GDPR may be relevant. Cookies of different categories are set through the integration, in particular analysis and marketing cookies. These cookies are only set after active consent; their functionality depends on the selected privacy settings of the integrated YouTube player. The transfer of personal data to third countries, in particular to the USA, cannot be ruled out. Google uses the EU standard contractual clauses pursuant to Art. 46 (2) and (3) GDPR as suitable guarantees for data transfers. Personal data is deleted when the purpose no longer applies, consent is withdrawn or on request, provided there are no statutory retention periods. Further information can be found at https://policies.google.com/privacy?hl=de
Google company profile
We have a so-called Google company profile. We use the information service offered by Google and the services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Data processing by Google
The Google page and its functions are used under your own responsibility. This applies in particular to the use of social and interactive functions (e.g. commenting, sharing, rating, direct messages). When you visit and interact with our Google company profile entry, Google also collects your IP address and other information that is stored on your device in the form of cookies. This may enable Google to assign IP addresses to individual users or user accounts. This information is used to provide us, as the operator of the Google company profile entry, with statistical information about the use of Google services. The data collected in this context is processed by Google and may be transferred to countries outside the European Union. Google generally describes what information Google receives and how it is used in its Privacy Policy. If you contact us via our Google company profile entry or other Google services by direct message, we cannot rule out the possibility that these messages may also be read and analyzed by Google (both by employees and automatically). We therefore advise against communicating personal data to us there. Instead, another form of communication should be chosen as early as possible. The use of this service is subject to the Google Privacy Policy. Further information can be found in the Privacy Policy at the following link: https://policies.google.com/privacy?hl=de.
Data processing by us
As the provider of our Google company profile entry, we do not collect and process any further data from the use of this Google service. When you contact us or publish a review, we process published profile data and the content of the review/comment. The legal basis is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the presentation of our company and in enabling the evaluation of our services in order to present our company and our services and to present them well to the outside world.
3.9.1 LinkedIn Ads
We also integrate the functions of LinkedIn Ads on our website.
With the help of LinkedIn Ads, we can easily create effective ads that can be seen by a large audience on LinkedIn.
LinkedIn collects personal data for this purpose using cookies. This is used to evaluate user behavior in order to analyze the effectiveness of advertising measures and adapt them to future campaigns in a more user-oriented manner.
These cookies are only set with consent. Consent can be withdrawn at any time. The legal basis for this is Art. 6 para. 1 lit. a GDPR.
Otherwise, the legal basis for the processing of data by LinkedIn Ads is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in expanding and optimizing our advertising presence on the LinkedIn platform.
3.10 Third-party content
Google Fonts
Fonts from the Google Fonts service, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, are used on our website. Google Fonts makes it possible to integrate fonts directly from Google's servers in order to provide uniform and appealing typography and optimal loading times via a content delivery network (CDN). As part of the integration, the IP address of the website visitor, the requested font resource and HTTP header information such as user agent and referrer are processed. The purpose of the data processing is the technical provision of the fonts, the improvement of the design and the optimization of the display on different devices and browsers. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in an appealing and consistent website design and technically secure and efficient provision. According to current information, Google Fonts does not use cookies to provide the fonts. There is no transfer of personal data to third countries, as the processing is carried out in Europe by Google Ireland Limited in accordance with Google. Personal data is only stored for as long as is necessary for the provision of the fonts and the security of the service; if the purpose ceases to apply or a justified request for deletion is made, the data is deleted, provided that there are no statutory retention obligations to the contrary. Further information is available at https://developers.google.com/fonts/faq/privacy.
Vimeo
Videos from the Vimeo service are integrated on the website. Vimeo is a video platform for the provision and management of high-quality videos and is operated by Vimeo.com, Inc, 330 West 34th Street, 5th Floor, New York, NY 10001, USA. Vimeo enables the embedding of advertising and information videos, video presentations as well as interactive and exclusive content via a customizable player function. When using the embedded Vimeo player, the IP address, browser type, device data, pages and content accessed, referrer URL and information on interactions with the video (e.g. playback duration) are collected and processed. Cookies and similar technologies are also used, in particular to generate analysis and profiling data. The purpose of the processing is the needs-based display and optimization of video content, the statistical evaluation of video usage and the technical provision of video functionality. The legal basis for the playout of non-essential content and for the use of cookies and analysis tools is Art. 6 para. 1 lit. a GDPR in conjunction with. § Section 25 (1) TDDDG; cookies required for the technical display of the videos may be set on the basis of Art. 6 (1) (f) GDPR. Vimeo uses functional as well as analysis and marketing cookies, whereby these - unless technically necessary - are only activated with express consent. Personal data is transferred to the USA; Vimeo relies on the EU standard contractual clauses and participation in the EU-U.S. Data Privacy Framework as suitable guarantees in accordance with Art. 46 GDPR. The data collected is stored for the duration of the user relationship and is deleted as soon as the purpose no longer applies, consent is revoked or mandatory statutory retention obligations prevent deletion. Further information on data processing by Vimeo can be found at: https://vimeo.com/privacy
Google reCAPTCHA
Google reCAPTCHA is integrated on our website, a service for detecting and preventing bots, spam and cases of abuse. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google reCAPTCHA is used to prevent automated access and to increase the security of forms and login areas. The service analyzes the behavior of website visitors (e.g. mouse movements, length of stay, input patterns) and decides whether they are human users. Various categories of personal data are collected, including IP address, mouse movements, dwell time, screenshots of the browser window, cookie information, browsing behavior and, if applicable, data on hand gestures when gesture matching is activated. Data processing is carried out for the purpose of securing technical processes against misuse and maintaining the integrity of the website. The legal basis for the use of Google reCAPTCHA is Art. 6 para. 1 lit. f GDPR, the legitimate interest in protection against automated attacks, and - if cookies are set on the end device by reCAPTCHA - Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG on the basis of consent given. Google reCAPTCHA uses both functional and analytical cookies to detect bots and improve the functionality of the service. Analysis and tracking cookies are only used on the basis of active consent. The transmission of personal data to Google LLC servers in the USA cannot be ruled out. In these cases, Google relies on the standard contractual clauses of the EU Commission pursuant to Art. 46 GDPR as a suitable guarantee of an adequate level of data protection. The storage period of the data depends on the respective purpose pursued. Data is generally deleted as soon as the purpose for which it was collected no longer applies or consent has been withdrawn, provided there are no statutory retention obligations to the contrary. Further information on Google reCAPTCHA can be found in the Google Cloud Platform Service Specific Terms at: https://cloud.google.com/terms/service-terms.
YouTube
Video content is integrated on our website via the third-party service YouTube, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. YouTube enables the direct playback and display of videos on our website as well as the use of associated functions such as starting, stopping or sharing videos. As part of the integration, personal data such as IP address, cookie and local storage information as well as interaction and usage data on video playback behavior may be processed. Data processing is carried out for the purpose of providing video content, increasing the user-friendliness of the website and integrating interactive media offerings. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG, provided that consent has been given for the use of cookies or other storage technologies in the end device; otherwise Art. 6 para. 1 lit. f GDPR is relevant, as there is a legitimate interest in an appealing and informative design of the website. YouTube uses cookies and similar technologies for analytical, functional and, if necessary, marketing purposes, in particular to enable video playback and to evaluate user behavior. However, this only takes place with prior consent via the website's consent banner. In the context of use, the transfer of data to third countries, in particular to the USA, cannot be ruled out. The standard contractual clauses of the EU Commission are used to protect the data. Personal data is deleted as soon as the purpose of the processing no longer applies, consent is no longer given or statutory retention periods expire. Further information on data processing by YouTube can be found at https://policies.google.com/privacy?hl=de
Trustpilot reviews
Our website includes reviews and testimonials via Trustpilot. Trustpilot is operated by Trustpilot Group plc, 5th Floor, The Minster Building, 21 Mincing Lane, London, England, EC3R 7AG, United Kingdom. The service enables the display of customer ratings, TrustScore badges and other rating elements in order to strengthen the trust of potential customers and transparently display business ratings. As part of the integration, Trustpilot processes the IP address, browser information, details of the end device used and interaction data such as page views and clicks on the reviews, among other things. This takes place in particular when loading Trustpilot widgets or displaying individual reviews on the website. The purpose of data processing is to display third-party reviews, to increase trustworthiness and to make user reviews transparent and visible. The legal basis for the integration and processing is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in a transparent external presentation and a sound basis for decision-making for potential customers. If Trustpilot uses cookies or similar technologies to analyze user behavior or for cross-device recognition, this is done exclusively on the basis of consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § Section 25 (1) TDDDG, which is requested in the consent banner. If only technical cookies necessary for the provision of content are used, the processing is carried out on the basis of Art. 6 para. 1 lit. f GDPR in conjunction with Art. 25 para. 2 no. 2 TDDDG. § Section 25 para. 2 no. 2 TDDDG. A transfer of personal data to third countries cannot be ruled out, in particular to the United Kingdom, where Trustpilot is based. According to the current status, there are adequacy decisions by the EU Commission for a transfer to this country. Personal data is deleted as soon as it is no longer required to achieve the respective purpose, consent has been withdrawn or storage has been objected to, provided that there are no statutory retention obligations to the contrary. Further information can be found in Trustpilot's Privacy Policy at: https://corporate.trustpilot.com/legal/for-reviewers/privacy-policy-end-user/jan-2026
Trustpilot Widget
Our website uses the Trustpilot widget, which is provided by Trustpilot Group Plc, The Minster Building, 21 Mincing Lane, London, EC3R 7AG, United Kingdom. The widget is used to display customer experiences, TrustScore and star ratings in order to strengthen trust in the offer and increase conversion rates. As part of the integration, the widget processes public rating data (such as user names, rating comments and star ratings), technical information such as IP address and browser data as well as interaction data (e.g. views, clicks, impressions of the widget). The processing is carried out for the purpose of displaying customer reviews, improving the user experience and analyzing interactions. The legal basis for processing is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in providing trust-building content and optimizing the website. If the widget is actively integrated, Trustpilot may also set cookies for reach measurement and analysis; these are only activated with the consent of the user, so that in this respect Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG applies. The data processed by the widget may be transferred to the United Kingdom, which is considered a safe third country within the meaning of the GDPR; according to the current state of knowledge, Trustpilot does not include other third countries. The storage period depends on the purpose of use; data will be deleted as soon as it is no longer required for the purposes described or consent given is revoked, provided that there are no legal storage obligations to the contrary. Further information can be found in Trustpilot's Privacy Policy at https://corporate.trustpilot.com/legal/for-businesses/privacy-policy/14-mar-2025.
Amazon CloudFront
This website uses the Amazon CloudFront content delivery network service, which offers central functions to accelerate the delivery of web content such as HTML, CSS, JavaScript, images and videos and is provided by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855, Luxembourg. Amazon CloudFront ensures that static and dynamic content is delivered via a global network of edge locations to optimize website loading times, increase availability and ensure integrated protection against DDoS attacks and data transmissions via HTTPS. During use, IP addresses, timestamps of requests, HTTP methods, requested URLs, status codes, transferred data volumes, browser information (user agent) and referrers are recorded and processed. The purpose of the processing is the efficient delivery of web content, optimization of loading times, protection of the IT infrastructure as well as technical logging and ensuring the secure operation of the website. The legal basis for the processing is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in the secure and high-performance provision of web content; if the use of certain functionalities requires consent, this is done on the basis of Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG. Amazon CloudFront may use technically necessary cookies, for example to control content delivery or session management; these are processed on the basis of Art. 6 para. 1 lit. f GDPR, while cookies requiring consent are only set after corresponding consent (Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG). Data transfer to locations outside the EU, in particular to the USA, cannot be excluded in the context of service operation; Amazon Web Services uses the standard contractual clauses approved by the EU Commission in accordance with Art. 46 para. 2 lit. c GDPR as suitable guarantees for this purpose. The data will be deleted as soon as it is no longer required for the purposes of processing; this can take place after the session has ended, after the purpose has ceased to exist or if consent has been withdrawn, provided that there are no statutory retention periods to the contrary. Further information on data processing by Amazon CloudFront can be found at: https://aws.amazon.com/privacy/
Short.io
This website uses the Short.io service, operated by Short.cm, Delaware, USA, to create, manage and analyze shortened URLs with their own domain. Short.io provides functions such as URL shortening, branding, target group control (e.g. geo and mobile targeting), real-time analytics and integrations for content management systems and third-party platforms. In particular, data such as click information (including timestamp and frequency), geographical location, device type (e.g. mobile device or desktop), referrer URL and usage and conversion statistics are processed. The purpose of data processing is the shortening of URLs, the analysis and optimization of campaigns and the evaluation of user interactions in order to measure the reach and performance of digital offers. The legal basis for the use of analysis and tracking functions is generally consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § Section 25 (1) TDDDG, for technically necessary functions Art. 6 para. 1 lit. f GDPR due to the legitimate interest in the optimization and secure functioning of the website. Short.io may set cookies for analysis and tracking purposes, which are only used with the prior consent of the website user. If data is transferred to the USA, EU standard contractual clauses are used as suitable guarantees in accordance with Art. 46 GDPR. The data is stored and deleted after the purpose no longer applies, consent is withdrawn or statutory retention periods expire. Further information can be found at: https://short.io/privacy
Google APIs
Various functions of Google APIs are used on this website. Google APIs are interfaces for integrating Google services such as Maps, Translate, Drive, Analytics, Calendar and more. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The integration enables, among other things, the display of interactive maps, authentication via Google Sign-In, access to cloud and productivity services as well as analysis and automation functions. During use, personal data such as IP address, browser and device information, usage and interaction data, location information, referrer URLs, timestamps and, if applicable, authentication data are regularly processed. The processing is carried out for the purpose of providing the respective integrated functions, improving the user experience and ensuring the integrity and security of the website. Depending on the specific function, the legal basis is Art. 6 para. 1 lit. a GDPR (consent, in particular for analysis or marketing functionality and for cookies in accordance with Section 25 para. 1 TDDDG), Art. 6 para. 1 lit. b GDPR (processing for the performance of a contract, e.g. for Google Sign-In) or Art. 6 para. 1 lit. f GDPR (legitimate interest in the technically reliable and economical provision of web services). When using certain APIs, cookies may be set for functional, analytical or marketing purposes. These are used exclusively on the basis of prior, express consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with Section 25 para. 1 TDDDG. A transfer of personal data to third countries outside the EU, in particular to the USA, cannot be ruled out. For such transfers, the standard contractual clauses of the EU Commission are regularly applied as suitable guarantees in accordance with Art. 46 GDPR. Data is deleted as soon as the respective processing purpose no longer applies, consent is no longer given or statutory retention periods expire. Further information can be found in Google's Privacy Policy: https://policies.google.com/privacy
Google Maps
Our website uses the map service Google Maps, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Maps provides interactive maps, shows locations and directions and enables the integration of Street View and other cartographic functions. Personal data such as IP address, device and browser information, possibly location data (if enabled by the end device) and interaction data (e.g. search terms, zoom level, locations clicked on) are processed during use. This data is processed for the purpose of geographical presentation, navigation, displaying company locations and improving the user-friendliness of our website. The legal basis is generally Art. 6 para. 1 lit. a GDPR i.V.m. § Section 25 (1) TDDDG, provided that consent is obtained via the cookie banner. If consent is not obtained, Google Maps will not be activated. If cookies are used, these are functional and possibly analysis cookies, which are only set with express consent. Personal data may be transferred to a third country, in particular to the USA. Google uses the standard contractual clauses approved by the EU Commission as suitable guarantees for such transfers. The personal data will be deleted as soon as the purpose of the processing no longer applies or the consent is revoked, provided that there are no statutory retention obligations to the contrary. Further information on data protection can be found at: https://policies.google.com/privacy
3.10.1 How we integrate Amazon Cloudfront on our website
We have adapted Amazon Cloudfront so that no or only technically necessary cookies are set on our website. The legal basis is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in increasing the security and delivery speed of our website and in using a CDN.
3.11 Audio and video conferencing
Zoom
Our website uses the video conferencing and communication service Zoom, provided by Zoom Video Communications, Inc, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA, for European users with services via regional subsidiaries such as ZVC Germany, ZVC Netherlands or ZVC UK. Zoom enables audio and video conferences, webinars, live chats, screen sharing and online meetings to be held directly via the website. In the course of use, IP addresses, account information, session and meeting data, registration information for webinars, engagement data (e.g. recordings, transcripts) and interaction data such as chat messages, shared files or technical usage information are usually processed. The data processing serves the provision and management of online meetings, interactive communication and the implementation and evaluation of digital events. The legal basis for the processing is regularly Art. 6 para. 1 lit. b GDPR (implementation of (pre-)contractual measures), for support or administrative processes as well as analysis purposes Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient communication and IT security). Depending on the integration, Zoom uses functional cookies for session management and, if necessary, analysis or marketing cookies to evaluate usage, whereby analysis and marketing cookies are only used with consent in accordance with Art. 6 Para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG are used. Functional cookies are necessary for operation and are used in accordance with Art. 6 para. 1 lit. f GDPR in conjunction with. § 25 para. 2 TDDDG are used. Personal data is transferred to third countries, in particular to the USA, whereby Zoom uses the EU standard contractual clauses as suitable guarantees in accordance with Art. 46 para. 2 lit. c GDPR. The storage period depends on the respective purpose, i.e. data is deleted or blocked after the purpose of processing ceases to apply, if consent is revoked or objected to, or if statutory retention periods expire. Further information can be found in Zoom's Privacy Policy: https://www.zoom.com/en/trust/privacy/privacy-statement/
Google Meet
The Google Meet service is used on our website to conduct audio and video conferences. Google Meet is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Meet enables virtual meetings, audio and video conferences and functions such as screen sharing, live subtitling, chat and collaboration in real time. In particular, we process participants' identity data (such as name and email address), attendance data (e.g. joining and leaving times, roles in the meeting), device information and technical metrics (device type, network data such as latency and packet loss for audio/video), location data, meeting events (e.g. presentations, surveys, reports of abuse), meeting artifacts (recordings, transcripts, if activated) as well as browser and network analysis data. The data processing is carried out for the purpose of organizing and conducting online conferences and virtual collaboration, including the provision, safeguarding and analysis of the technical functionality of the meetings. The legal basis for the processing is Art. 6 para. 1 lit. b GDPR for contractual and pre-contractual purposes and Art. 6 para. 1 lit. f GDPR based on our legitimate interest in efficient, secure and modern communication. If functions such as recording or extended analyses are used, additional consent may be required in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG. Google Meet may use functional and analytical cookies to ensure the stability of the connection and to analyze performance. These cookies are only set with prior consent. The legal basis for this is Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. A transfer of personal data to third countries, in particular to the USA, cannot be ruled out in the context of support or maintenance processes. Google guarantees compliance with an appropriate level of data protection by concluding EU standard contractual clauses in accordance with Art. 46 para. 2 lit. c GDPR. The data will be deleted as soon as the purpose of the processing no longer applies, consent has been revoked or statutory retention periods have expired. Further information can be found in Google's Privacy Policy: https://policies.google.com/privacy?hl=de
3.12 Data transfer to providers on our platform
As part of the use of our platform for the use of services or the purchase of products, we pass on certain personal data to the providers (e.g. service providers, sellers) in order to enable the processing of the corresponding services. This data transfer is necessary so that the providers can provide their services or deliver products.
In doing so, we may pass on the name to identify the user, the contact details for contacting in the event of queries or problems, the address for providing the service or delivering products, the order data for transmitting details of the requested service or ordered products and, if necessary, payment information for processing the payment (this is usually encrypted and in accordance with the applicable security standards) to the providers.
The legal basis for data transfer is Art. 6 para. 1 lit. b GDPR, as it is necessary for the fulfillment of the contractual relationship between you and the provider.
The providers are obliged to use the transmitted data exclusively for processing the requested services or deliveries and to protect the data in accordance with the applicable data protection laws. They are the direct contractual partner and therefore bear their own responsibility for the processing of personal data. If you have any questions about their data processing, you can contact the provider directly.
3.13 Payment services
Stripe
The Stripe payment service is integrated on the website to enable the secure and efficient processing of online payments and subscriptions. Stripe Payments Europe, Limited, 3 Dublin Landings, North Wall Quay, Dublin 1, D01 C4E0, Ireland, is responsible for the service in Europe. Stripe provides various payment functions, such as payment by credit card, direct debit, instant bank transfer or digital wallets, as well as automated invoicing and fraud prevention. In the context of use, Stripe processes personal data such as name, e-mail address, telephone number, billing and delivery address, credit card and account data, IP address, device and browser information, usage and transaction data and, if applicable, documents to confirm identity. The processing is carried out for the purpose of payment processing, contract execution, fraud prevention and compliance with legal requirements. The legal basis is Art. 6 para. 1 lit. b GDPR for contractual or pre-contractual measures, if applicable Art. 6 para. 1 lit. f GDPR due to legitimate interests in secure payment processing and § 25 para. 2 no. 2 TDDDG for technically necessary cookies and technologies. Stripe uses technically necessary cookies as part of the payment process, including authentication and security cookies as well as session IDs for fraud prevention and payment processing. These cookies are absolutely necessary for operation and are processed without consent (Section 25 (2) No. 2 TDDDG). Analytical or marketing cookies, on the other hand, are only used with consent in accordance with Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Personal data may be transferred to third countries (in particular the USA) as part of payment processing. Stripe uses the standard contractual clauses approved by the EU Commission in accordance with Art. 46 para. 2 lit. c GDPR as suitable guarantees. Personal data is generally deleted as soon as it is no longer required for the purposes for which it was collected and there are no statutory retention obligations. If consent is withdrawn or after expiry of statutory periods, the data will be deleted, provided there are no other statutory retention periods to the contrary. Further information on data processing by Stripe is available at: https://stripe.com/privacy
3.14 Affiliate marketing
Rewardful
This service will be added shortly.
3.15 CRM systems
Notion
Notion from Notion Labs, Inc., 2300 Harrison Street, San Francisco, CA 94110, USA, is used for customer relationship management (CRM) on this website. Notion enables the central management of customer data, the administration of contact information, the organization of sales processes and the automation of tasks and workflows. Notion typically processes personal data such as name, e-mail address, telephone number, social profiles, address, company name and job title, communication histories (e.g. call, appointment or e-mail logs), individually stored notes and status information in the customer history. The purpose of data processing is to efficiently manage customer relationships, communication, the sales process and the automation and documentation of interactions. The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as the processing is carried out to fulfil (pre-)contractual measures, and Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in the effective organization of customer management; depending on the forms or functions integrated, Art. 6 para. 1 lit. a GDPR in conjunction with. § Section 25 (1) TDDDG may also apply if express consent is given. Insofar as cookies are set via embedded notion pages or form functions, these are regularly functional cookies for session management and analysis cookies (e.g. service or user preferences, for which third-party providers such as Google Analytics may also be integrated); these are only placed with consent and can be revoked at any time via the cookie settings. Personal data is transferred to the USA, whereby Notion uses the standard contractual clauses provided by the EU Commission for data protection in accordance with Art. 46 GDPR. The data will be deleted accordingly when the processing purposes cease to apply, for example after completion of projects or if consent is withdrawn, provided that there are no statutory retention obligations to the contrary. Further information on data protection at Notion can be found at https://www.notion.so/help/guides/privacy.
Google Sheets
This website uses the Google Sheets service for CRM purposes, offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Sheets is used to manage, store and process customer-related data, in particular for tasks such as lead management, contact management, tracking of sales processes or the documentation of interactions provided via entries through web forms or automated integrations. The categories of data processed include details such as name, email address, telephone number, address, interaction notes, status information, appointment data and other CRM-related information collected through corresponding web integrations. The purpose of data processing is the structured organization and digital processing of customer data for contract initiation, processing and maintenance of customer relationships as well as for tracking business transactions. The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as the processing is necessary for the performance of a contract or pre-contractual measures, as well as Art. 6 para. 1 lit. f GDPR based on the legitimate interest in efficient and transparent customer management; insofar as integrations collect further information with consent (e.g. web forms), Art. 6 para. 1 lit. a GDPR in conjunction with. § Section 25 (1) TDDDG applies. Google Sheets uses cookies in the context of integrations and when used as an embedded element, including necessary cookies for functionality, analysis or marketing cookies can also be used if they are accepted by the user; explicit consent is required for this, legal basis: Art. 6 para. 1 lit. a GDPR i.V.m. § 25 para. 1 TDDDG. A transfer of personal data to third countries cannot be ruled out, in particular to the USA; in these cases, the standard contractual clauses provided by the EU Commission are used as guarantees - Google provides more detailed information on this. The stored data will be deleted as soon as the purpose of its processing no longer applies, in the event of withdrawal of consent or after the expiry of statutory retention periods. Further information can be found at https://policies.google.com/privacy?hl=de.
In-house development
We use a customer relationship management (CRM) system that we developed ourselves. This CRM enables us to manage existing and potential customers and contacts and to organize sales, accounting and communication processes. This system is crucial for analyzing and optimizing our customer-related processes. With the help of the CRM system, we can efficiently organize our customer communication via various channels to present relevant information and offers that match our customers' interests. As soon as we collect personal data on our website, we process it in the CRM system. The data is processed on the basis of Art. 6 para. 1 lit. b GDPR for the fulfillment of (pre-)contractual obligations and Art. 6 para. 1 lit. f GDPR, as the use of CRM functions is of central importance for the growth and scaling of our company and we have a legitimate interest in the most efficient customer management and communication possible. If a corresponding consent has been requested, the processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR; the consent can be revoked at any time. Thanks to our in-house development, we can ensure that no data is transferred to third parties.
3.16 Cloud backups
AWS Backup
On our website, we use the AWS Backup service from Amazon Web Services, Inc, 410 Terry Ave North, Seattle, WA 98109-5210, USA, for the automated backup and restoration of data in our cloud infrastructure. The service enables the centralized and automated creation, storage and restoration of backups for various AWS resources such as EC2 instances, EBS volumes, S3 buckets, RDS databases, EFS file systems and DynamoDB tables used for the operation of our website. The data specified in the backup configuration is processed from the aforementioned cloud resources as well as metadata on the backup processes (e.g. timestamps, resource IDs, status messages) and access and administration data (e.g. IAM roles and authorizations). The processing of this data serves the purpose of fail-safety, the recovery of systems in the event of a disaster, compliance with legal and business archiving obligations and the prevention of data loss. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in data security and business continuity, unless a contractual requirement pursuant to Art. 6 para. 1 lit. b GDPR is relevant in individual cases. AWS Backup does not use cookies as part of this functionality, as the service is not integrated into the user interaction on the website, but works exclusively on the server side for backup purposes. Data may be transferred to third countries, in particular to the USA, in certain cases. In this case, Amazon Web Services relies on the EU standard contractual clauses as suitable guarantees in accordance with Art. 46 GDPR. Data will be deleted as soon as the purpose of the backup no longer applies, a retention period expires or at the request of the website operator, provided that there are no legal retention obligations to the contrary. Further information on data protection at Amazon Web Services can be found at: https://aws.amazon.com/privacy/
Vercel
We use the Vercel cloud hosting and provisioning service on our website, operated by Vercel Inc, San Francisco, California, United States. Vercel enables the hosting and automated provision of web applications as well as serverless functions and analysis services in real time. During use, Vercel processes, among other things, IP addresses, the approximate location (city and country, derived from the IP address), information on the end device used (device type, browser, operating system), the page URLs accessed (without query parameters), referrer information, host names, traffic data (page views, clicks, timestamps), UTM parameters (for Plus/Enterprise use), a daily, pseudonymized visitor hash, web performance metrics and other system-related information. Data processing is carried out for the purpose of secure and high-performance hosting, monitoring website performance and ensuring the functionality of the websites provided. The legal basis is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in the secure and efficient provision and analysis of the website. Vercel does not set any cookies that require consent, but processes the aforementioned data for the purpose of technical provision and statistical evaluation on the basis of legitimate interest. Personal data may be transferred to the USA as a third country. The EU standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR are used as a suitable guarantee. The storage period depends on the respective processing purpose; personal data is deleted as soon as it is no longer required to achieve the respective purpose or a statutory retention period expires. Further information on data protection at Vercel can be found at: https://vercel.com/legal/privacy-policy
Supabase
On our website, we use the cloud backup and backend-as-a-service solution from Supabase, operated by Supabase, Inc, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Supabase provides web applications with a scalable database, authentication, real-time data, file hosting and backup and restore functions. When using Supabase in the context of cloud backups, personal data is processed that is stored in the respective application, in particular names, e-mail addresses, IP addresses and other content generated by users. In addition, authentication data (e.g. social logins, email) and operational metadata (platform usage data, no end-user data unless explicitly configured) as well as logs to ensure technical security may be processed. The processing is carried out for the purpose of secure and efficient storage, backup and recovery of application data, to prevent IT threats and to ensure the operational capability of the application. The legal basis for the processing is Art. 6 para. 1 lit. b GDPR for the fulfillment of (pre-)contractual obligations, Art. 6 para. 1 lit. c GDPR for the legal obligation to secure data and Art. 6 para. 1 lit. f GDPR due to the legitimate interest in secure, reliable and efficient data storage and its protection. Supabase may use technically necessary cookies for authentication and security purposes, the storage of which is essential for the operation and security of the application; Art. 6 para. 1 lit. f GDPR in conjunction with. § Section 25 para. 2 no. 2 TDDDG. Data may be transferred to third countries, in particular to Singapore; the standard contractual clauses of the EU Commission are used as a suitable guarantee for an adequate level of data protection. The stored data will be deleted as soon as the purpose of the processing no longer applies, there are no longer any statutory retention obligations or deletion has been requested, provided that there are no mandatory statutory provisions to the contrary. Further information on data protection at Supabase can be found at https://supabase.com/privacy.
4. What else is important
Finally, we would like to inform you in detail about your rights and how you will be informed about changes to data protection requirements.
4.1 Your rights in detail
4.1.1 Right to information in accordance with Art. 15 GDPR
You can request information about whether your personal data is being processed. If this is the case, you can request further information on the type and manner of processing. A detailed list can be found in Art. 15 para. 1 lit. a to h GDPR.
4.1.2 Right to rectification in accordance with Art. 16 GDPR
This right includes the correction of incorrect data and the completion of incomplete personal data.
4.1.3 Right to erasure in accordance with Art. 17 GDPR
This so-called 'right to be forgotten' gives you the right, under certain conditions, to request the deletion of personal data by the controller. This is generally the case if the purpose of the data processing no longer applies, if consent has been withdrawn or the initial processing took place without a legal basis. A detailed list of reasons can be found in Art. 17 para. 1 lit. a to f GDPR. This "right to be forgotten" also corresponds to the controller's obligation under Art. 17 para. 2 GDPR to take reasonable steps to ensure that the data is generally erased.
4.1.4 Right to restriction of processing in accordance with Art. 18 GDPR
This right is subject to the conditions set out in Art. 18 para. 1 lit. a to d.
4.1.5 Right to data portability in accordance with Art. 20 GDPR
This regulates the basic right to receive your own data in a commonly used form and to transfer it to another controller. However, this only applies to data processed on the basis of consent or a contract in accordance with Art. 20 (1) (a) and (b) and insofar as this is technically feasible.
4.1.6 Right to object pursuant to Art. 21 GDPR
In principle, you can object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the legitimate interest of the controller in the processing and if the processing relates to direct marketing and/or profiling.
4.1.7 Right to "individual decision-making" pursuant to Art. 22 GDPR
In principle, you have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. However, this right is also restricted and supplemented by Art. 22 (2) and (4) GDPR.
4.1.8 Further rights
The GDPR contains comprehensive rights to inform third parties about whether or how you have asserted rights under Art. 16, 17, 18 GDPR. However, this only applies insofar as this is possible or feasible with reasonable effort.
We would like to take this opportunity to draw your attention once again to your right to withdraw your consent in accordance with Art. 7 (3) GDPR. However, this does not affect the lawfulness of the processing carried out up to that point.
We would also like to draw your attention to your rights under §§ 32 ff. BDSG, which, however, are largely congruent with the rights just described.
4.1.9 Right to lodge a complaint pursuant to Art. 77 GDPR
You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes this Regulation.
5. What if the GDPR is abolished tomorrow or other changes take place?
The current status of this Privacy Policy is 30.04.2026. From time to time it is necessary to adapt the content of the Privacy Policy in order to react to actual and legal changes. We therefore reserve the right to amend this Privacy Policy at any time. We will publish the amended version in the same place and recommend that you read the Privacy Policy regularly.
Created with the kind support of Dieter macht den Datenschutz