Junges Buntes Leben in Freiburg

Preamble

With the following privacy policy, we would like to inform you about which types of your personal data (hereinafter also referred to briefly as “data”) we process, for which purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, as well as within external online presences, such as our social media profiles (hereinafter collectively referred to as “online offering”).

The terms used are not gender specific.

Last updated: February 16, 2026

Table of Contents

Controller

Christoph Röhrl / Sunroots
Rehlingstr. 9
79100 Freiburg
Germany

Email address: Sunroots@sunroots.de

Overview of Processing Activities

The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned.

Types of Data Processed

  • Inventory data.
  • Payment data.
  • Location data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta, communication, and procedural data.
  • Log data.
  • Member data.

Categories of Data Subjects

  • Prospective customers.
  • Communication partners.
  • Users.
  • Members.
  • Donors.
  • Third parties.

Purposes of Processing

  • Communication.
  • Security measures.
  • Direct marketing.
  • Reach measurement.
  • Tracking.
  • Audience formation.
  • Organizational and administrative procedures.
  • Feedback.
  • Marketing.
  • Profiles with user-related information.
  • Provision of our online offering and user-friendliness.
  • Information technology infrastructure.
  • Fundraising.
  • Public relations and information purposes.
  • Public relations.
  • Business processes and business management procedures.

Applicable Legal Bases

Applicable legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we base our processing of personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or registered office. Furthermore, should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.

  • Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
  • Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1)(f) GDPR) – processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
  • Membership contract (statutes) (Art. 6(1)(b) GDPR).

National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes in particular the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). The BDSG contains specific regulations on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply.

Security Measures

In accordance with legal requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access to it, its entry, its disclosure, ensuring its availability, and its separation. Furthermore, we have established procedures to ensure the exercise of data subject rights, the deletion of data, and responses to data threats. We also take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection through technology design and through privacy friendly default settings.

Securing online connections through TLS/SSL encryption technology (HTTPS): to protect the data of users transmitted via our online services against unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. If a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.

Transfer of Personal Data

In the course of our processing of personal data, it may occur that such data is transferred to, or disclosed to, other bodies, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements that serve to protect your data with the recipients of your data.

International Data Transfers

Data processing in third countries: if we transfer data to a third country (meaning outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third party services or disclosing or transmitting data to other persons, bodies, or companies (which is apparent from the postal address of the respective provider, or where the privacy policy explicitly refers to the transfer of data to third countries), this is always done in accordance with legal requirements.

For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission dated July 10, 2023. In addition, we have concluded standard contractual clauses with the respective providers, which comply with the requirements of the EU Commission and establish contractual obligations to protect your data.

This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary level of protection, while the standard contractual clauses serve as an additional safety net. Should changes occur within the framework of the DPF, the standard contractual clauses will take effect as a reliable fallback option. This ensures that your data remains adequately protected at all times, even in the event of political or legal changes.

For each individual service provider, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/ (in English).

For data transfers to other third countries, corresponding safeguards apply, in particular standard contractual clauses, explicit consent, or legally required transfers. Information on third country transfers and applicable adequacy decisions can be found on the EU Commission’s information page: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

General Information on Data Storage and Deletion

We delete personal data that we process in accordance with legal provisions as soon as the underlying consents are revoked or no other legal basis for the processing exists. This applies to cases where the original purpose of processing no longer applies, or the data is no longer needed. Exceptions to this rule exist where statutory obligations or particular interests require a longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for the purpose of asserting legal claims or protecting the rights of other natural or legal persons, must be archived accordingly.

Our data protection notices contain additional information on the retention and deletion of data that applies specifically to certain processing procedures.

If there are multiple specifications regarding the retention period or deletion deadlines for a piece of data, the longest period always applies. Data that is no longer processed for its originally intended purpose but is retained due to legal requirements or other reasons is processed exclusively for the reasons that justify its retention.

Retention and deletion of data: the following general periods apply to retention and archiving under German law:

  • 10 years, retention period for books and records, annual financial statements, inventories, management reports, opening balance sheet, as well as the work instructions and other organizational documents required to understand them (Section 147(1) No. 1 in conjunction with (3) of the German Fiscal Code (AO), Section 14b(1) of the German Value Added Tax Act (UStG), Section 257(1) No. 1 in conjunction with (4) of the German Commercial Code (HGB)).
  • 8 years, accounting vouchers, such as invoices and expense receipts (Section 147(1) No. 4 and 4a in conjunction with (3) sentence 1 AO, and Section 257(1) No. 4 in conjunction with (4) HGB).
  • 6 years, other business documents: received commercial or business letters, copies of commercial or business letters sent, other documents insofar as they are relevant for taxation purposes, for example hourly wage slips, cost accounting sheets, calculation documents, price labels, as well as payroll documents insofar as they are not already accounting vouchers, and cash register receipts (Section 147(1) Nos. 2, 3, 5 in conjunction with (3) AO, and Section 257(1) Nos. 2 and 3 in conjunction with (4) HGB).
  • 3 years, data required to consider potential warranty and damage claims or similar contractual claims and rights, and to process related inquiries, based on past business experience and common industry practices, is stored for the duration of the standard statutory limitation period of three years (Sections 195, 199 of the German Civil Code (BGB)).

Commencement of a period at year-end: if a period does not begin expressly on a specific date and lasts at least one year, it automatically starts at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships in which data is stored, the triggering event is the point at which the termination or other ending of the legal relationship takes effect.

Rights of Data Subjects

Rights of data subjects under the GDPR: as a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:

  • Right to object: you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling, to the extent that it is related to such direct marketing.
  • Right to withdraw consent: you have the right to withdraw consent you have given at any time.
  • Right of access: you have the right to request confirmation as to whether data concerning you is being processed, and to information about this data as well as further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: in accordance with legal requirements, you have the right to request the completion of data concerning you or the correction of inaccurate data concerning you.
  • Right to erasure and restriction of processing: in accordance with legal requirements, you have the right to demand that data concerning you be deleted without delay, or alternatively, in accordance with legal requirements, to demand a restriction of the processing of the data.
  • Right to data portability: you have the right to receive data concerning you that you have provided to us, in accordance with legal requirements, in a structured, commonly used, and machine readable format, or to request its transmission to another controller.
  • Complaint to a supervisory authority: without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR.

Performance of Duties under Statutes or Rules of Procedure

We process the data of our members, supporters, prospective members, business partners, or other persons (collectively “data subjects”) when we have a membership or other business relationship with them and carry out our duties, as well as when they are recipients of services and benefits. Beyond this, we process the data of data subjects on the basis of our legitimate interests, for example in connection with administrative tasks or public relations work.

The data processed in this context, and the nature, scope, purpose, and necessity of its processing, are determined by the underlying membership or contractual relationship, from which the necessity of any data provided also arises (we otherwise point out which data is required).

We delete data that is no longer required for fulfilling our statutory and operational purposes. This is determined according to the respective tasks and contractual relationships. We retain the data for as long as it may be relevant for the conduct of business, as well as with regard to any warranty or liability obligations, on the basis of our legitimate interest in resolving these matters. The necessity of retaining the data is reviewed regularly; otherwise, statutory retention obligations apply.

  • Types of data processed: inventory data (for example, full name, home address, contact information, customer number, etc.); contact data (for example, postal and email addresses or telephone numbers); contract data (for example, subject matter of the contract, duration, customer category); member data (for example, personal data such as name, age, gender, contact data (email address, telephone number), member number, information about membership fees, participation in events, etc.); payment data (for example, bank details, invoices, payment history). Content data (for example, text or image based messages and posts, as well as information relating to them, such as details of authorship or the time of creation).
  • Data subjects: members; prospective members; communication partners; donors. Third parties.
  • Purposes of processing and legitimate interests: communication; organizational and administrative procedures; public relations and information purposes; business processes and business management procedures. Fundraising.
  • Retention and deletion: deletion in accordance with the details in the section “General Information on Data Storage and Deletion.”
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR); membership contract (statutes) (Art. 6(1)(b) GDPR). Legal obligation (Art. 6(1)(c) GDPR).

Further information on processing activities, procedures, and services:

  • Membership administration: Procedures required for membership administration include the acquisition and admission of new members, the development and implementation of strategies for member retention, and ensuring effective communication with members. These processes include the careful recording and maintenance of member data, the regular updating of membership information, and the administration of membership fees, including invoicing and billing; Legal bases: legitimate interests (Art. 6(1)(f) GDPR), membership contract (statutes) (Art. 6(1)(b) GDPR).
  • Fee administration: The processing activities required for administering membership fees include recording membership fee data after a member joins, tracking membership fee payments and systematically updating payment status, carrying out payment transactions, processing reminders for overdue payments, reconciling accounts in the context of receivables and liabilities, as well as maintaining corresponding books and records; Legal bases: legal obligation (Art. 6(1)(c) GDPR), legitimate interests (Art. 6(1)(f) GDPR), membership contract (statutes) (Art. 6(1)(b) GDPR).
  • Events and organizational operations: Planning, conducting, and following up on events, as well as the general operation of statutory activities. Planning includes recording and processing participant data, coordinating logistical requirements, and setting the event agenda. Execution includes managing participant registration, updating participant information during the event, and recording attendance and participant activities. Follow up includes analyzing participant data to evaluate the success of the event, preparing reports, and archiving relevant information about the event. General organizational operations include managing member data, communicating with members and prospective members, and organizing internal meetings; Legal bases: legitimate interests (Art. 6(1)(f) GDPR), membership contract (statutes) (Art. 6(1)(b) GDPR).
  • Public relations: Procedures include the creation and distribution of informational materials, the maintenance of contact data for press and media relations, as well as the organization and execution of press conferences and public events. Creating informational materials involves collecting and preparing information for press releases, newsletters, reports, and other publications. Distribution takes place through digital and traditional channels, including email lists, websites, and social media. Maintaining contact data involves recording and updating data of media contacts and other relevant stakeholders. Organizing press conferences and events involves planning and conducting these events, invitation management, and coordinating event logistics. Interaction with media and stakeholders takes place through direct communication with journalists, bloggers, and other opinion leaders, responding to inquiries, and providing information; Legal bases: legitimate interests (Art. 6(1)(f) GDPR), membership contract (statutes) (Art. 6(1)(b) GDPR).
  • Fundraising: Procedures include the planning and execution of fundraising campaigns, the management of donor data, and communication with donors and potential supporters. Campaign planning involves developing strategies, setting goals, and selecting channels for fundraising. Campaign execution involves initiating and implementing specific fundraising activities, collecting donations via online platforms, events, and direct outreach. Donor data management includes collecting, updating, and analyzing data to optimize future campaigns. Communication with donors and potential supporters takes place through personalized outreach, thank you letters, and regular updates on project outcomes and use of funds; Legal bases: legitimate interests (Art. 6(1)(f) GDPR), membership contract (statutes) (Art. 6(1)(b) GDPR).

Provision of the Online Offering and Web Hosting

We process user data in order to provide our online services to them. For this purpose, we process the user’s IP address, which is necessary to deliver the content and functions of our online services to the user’s browser or device.

  • Types of data processed: usage data (for example, page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and procedural data (for example, IP addresses, timestamps, identification numbers, persons involved). Log data (for example, log files relating to logins or the retrieval of data or access times).
  • Data subjects: users (for example, website visitors, users of online services).
  • Purposes of processing and legitimate interests: provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices such as computers, servers, etc.). Security measures.
  • Retention and deletion: deletion in accordance with the details in the section “General Information on Data Storage and Deletion.”
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing activities, procedures, and services:

  • Provision of the online offering on rented storage space: To provide our online offering, we use storage space, computing capacity, and software that we rent or otherwise obtain from a corresponding server provider (also known as a “web host”); Legal bases: legitimate interests (Art. 6(1)(f) GDPR).
  • Collection of access data and log files: Access to our online offering is recorded in the form of so-called “server log files.” Server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, notification of successful retrieval, browser type and version, the user’s operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. Server log files can be used for security purposes, for example to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks), and to ensure server load balancing and stability; Legal bases: legitimate interests (Art. 6(1)(f) GDPR). Deletion of data: log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose further retention is required for evidentiary purposes is excluded from deletion until the respective incident has been fully clarified.

Use of Cookies

The term “cookies” refers to functions that store information on users’ devices and read information from them. Cookies may also be used for various purposes, such as ensuring the functionality, security, and convenience of online offerings, as well as generating analyses of visitor flows. We use cookies in accordance with legal requirements. Where necessary, we obtain users’ consent in advance. If consent is not required, we rely on our legitimate interests. This applies where the storage and retrieval of information is essential in order to provide expressly requested content and functions. This includes, for example, storing settings as well as ensuring the functionality and security of our online offering. Consent can be withdrawn at any time. We clearly inform users about the scope of consent and which cookies are used.

Notes on data protection legal bases: Whether we process personal data using cookies depends on consent. If consent has been given, it serves as the legal basis. Without consent, we rely on our legitimate interests, as explained above in this section and in the context of the respective services and procedures.

Storage period: With regard to storage period, the following types of cookies are distinguished:

  • Temporary cookies (also known as session cookies): temporary cookies are deleted at the latest after a user has left an online offering and closed their device (for example, browser or mobile application).
  • Permanent cookies: permanent cookies remain stored even after the device is closed. For example, this allows login status to be saved and preferred content to be displayed directly when a user visits a website again. Similarly, user data collected using cookies may be used for reach measurement. Unless we provide users with explicit information about the type and storage period of cookies (for example, when obtaining consent), users should assume that these are permanent and that the storage period may be up to two years.

General information on withdrawal and objection (opt-out): Users can withdraw the consent they have given at any time and may also object to processing in accordance with legal requirements, including through their browser’s privacy settings.

  • Types of data processed: meta, communication, and procedural data (for example, IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: users (for example, website visitors, users of online services).
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR). Consent (Art. 6(1)(a) GDPR).

Further information on processing activities, procedures, and services:

  • Processing of cookie data based on consent: We use a consent management solution in which user consent to the use of cookies, or to the procedures and providers named within the consent management solution, is obtained. This procedure serves to obtain, log, manage, and withdraw consent, particularly with regard to the use of cookies and comparable technologies used to store, read, and process information on users’ devices. As part of this procedure, users’ consent for the use of cookies and the related processing of information, including the specific processing activities and providers named in the consent management procedure, is obtained. Users also have the option to manage and withdraw their consent. Consent declarations are stored to avoid repeated queries and to be able to provide proof of consent in accordance with legal requirements. Storage takes place server side and/or in a cookie (a so called opt in cookie) or by means of comparable technologies, in order to be able to assign consent to a specific user or their device. Unless specific information about consent management service providers is available, the following general information applies: the duration of consent storage is up to two years. In this process, a pseudonymous user identifier is created and stored together with the time of consent, details of the scope of consent (for example, the categories of cookies and/or service providers concerned), as well as information about the browser, system, and device used; Legal bases: consent (Art. 6(1)(a) GDPR).

Blogs and Publication Media

We use blogs or comparable means of online communication and publication (hereinafter “publication medium”). Readers’ data is processed for the purposes of the publication medium only to the extent necessary for its presentation and for communication between authors and readers, or for security reasons. Otherwise, we refer to the information on the processing of visitors to our publication medium within these data protection notices.

  • Types of data processed: inventory data (for example, full name, home address, contact information, customer number, etc.); contact data (for example, postal and email addresses or telephone numbers); content data (for example, text or image based messages and posts, as well as information relating to them, such as details of authorship or the time of creation); usage data (for example, page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication, and procedural data (for example, IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: users (for example, website visitors, users of online services).
  • Purposes of processing and legitimate interests: feedback (for example, collecting feedback via an online form); provision of our online offering and user-friendliness; security measures. Organizational and administrative procedures.
  • Retention and deletion: deletion in accordance with the details in the section “General Information on Data Storage and Deletion.”
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing activities, procedures, and services:

  • Comments and posts: If users leave comments or other posts, their IP addresses may be stored on the basis of our legitimate interests. This is done for our own security, in case someone leaves unlawful content in comments and posts (insults, prohibited political propaganda, etc.). In such a case, we ourselves may be held liable for the comment or post and are therefore interested in the identity of the author. We furthermore reserve the right, on the basis of our legitimate interests, to process user information for the purpose of spam detection.

    On the same legal basis, we reserve the right, in the case of surveys, to store users’ IP addresses for their duration and to use cookies in order to prevent multiple votes.

    The personal information provided as part of comments and posts, any contact and website information, as well as the content itself, will be stored by us on an ongoing basis until the user objects; Legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Contact and Inquiry Management

When contacting us (for example, by post, contact form, email, telephone, or via social media) as well as within the framework of existing user and business relationships, the information provided by the inquiring parties is processed to the extent necessary to respond to the contact inquiries and any requested actions.

  • Types of data processed: contact data (for example, postal and email addresses or telephone numbers); content data (for example, text or image based messages and posts, as well as information relating to them, such as details of authorship or the time of creation). Meta, communication, and procedural data (for example, IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: communication partners.
  • Purposes of processing and legitimate interests: communication; organizational and administrative procedures; feedback (for example, collecting feedback via an online form). Provision of our online offering and user-friendliness.
  • Retention and deletion: deletion in accordance with the details in the section “General Information on Data Storage and Deletion.”
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR). Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).

Further information on processing activities, procedures, and services:

  • Contact form: When contacting us via our contact form, email, or other means of communication, we process the personal data transmitted to us in order to respond to and process the respective inquiry. This generally includes information such as name, contact information, and, where applicable, further information provided to us that is necessary for appropriate processing. We use this data exclusively for the stated purpose of contact and communication; Legal bases: performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).

Newsletter and Electronic Notifications

We send newsletters, emails, and other electronic notifications (hereinafter “newsletter”) only with the recipients’ consent or on the basis of a legal permission. Where the contents of the newsletter are specifically described as part of the sign up process, they are decisive for the users’ consent. Registering for our newsletter usually only requires providing your email address. However, in order to offer you a personalized service, we may ask for your name for personal address in the newsletter, or for further information if this is necessary for the purpose of the newsletter.

Deletion and restriction of processing: we may store unsubscribed email addresses for up to three years on the basis of our legitimate interests, before deleting them, in order to be able to prove that consent was previously given. Processing of this data is limited to the purpose of a potential defense against claims. An individual deletion request is possible at any time, provided that the prior existence of consent is confirmed at the same time. In the event of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose on a block list.

The sign up process is logged on the basis of our legitimate interests, for the purpose of proving that it was carried out properly. Insofar as we commission a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure sending system.

Content:

Information about us, our services, promotions, and offers.

  • Types of data processed: inventory data (for example, full name, home address, contact information, customer number, etc.); contact data (for example, postal and email addresses or telephone numbers). Meta, communication, and procedural data (for example, IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: communication partners.
  • Purposes of processing and legitimate interests: direct marketing (for example, by email or post).
  • Legal bases: consent (Art. 6(1)(a) GDPR).
  • Right to object (opt-out): you can cancel receipt of our newsletter at any time, meaning you can withdraw your consent or object to further receipt. You can find a link to cancel the newsletter either at the end of every newsletter, or you can otherwise use one of the contact options listed above, preferably email, for this purpose.

Web Analytics, Monitoring, and Optimization

Web analytics (also known as “reach measurement”) is used to evaluate visitor flows on our online offering and may include information about visitor behavior, interests, or demographic details, such as age or gender, as pseudonymous values. Reach analysis allows us, for example, to identify at what time our online offering, or its functions or content, is used most frequently, or to encourage repeat use. It also enables us to understand which areas require optimization.

In addition to web analytics, we may also use testing procedures to test and optimize different versions of our online offering or its components.

Unless otherwise stated below, profiles may be created for these purposes, meaning data combined into a usage record, and information may be stored in a browser or on a device and subsequently read out. The information collected includes, in particular, websites visited and elements used there, as well as technical information such as the browser used, the computer system used, and information on usage times. If users have consented to the collection of their location data, either toward us or toward the providers of the services we use, the processing of location data is also possible.

Furthermore, users’ IP addresses are stored. However, we use an IP masking procedure (meaning pseudonymization by shortening the IP address) to protect users. In general, no clear text user data (such as email addresses or names) is stored within the context of web analytics, A/B testing, and optimization, only pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, only the information stored in their profiles for the purpose of the respective procedures.

Notes on legal bases: if we ask users for their consent to the use of third party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (meaning our interest in efficient, economical, and recipient friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: usage data (for example, page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication, and procedural data (for example, IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: users (for example, website visitors, users of online services).
  • Purposes of processing and legitimate interests: reach measurement (for example, access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles). Provision of our online offering and user-friendliness.
  • Retention and deletion: deletion in accordance with the details in the section “General Information on Data Storage and Deletion.” Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing activities, procedures, and services:

  • Google Analytics: We use Google Analytics to measure and analyze the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any clear personal data, such as names or email addresses. It serves to link analytical information to a device, in order to determine which content users have accessed within one or several usage sessions, which search terms they have used, whether they have revisited content, or whether they have interacted with our online offering. Likewise, the time and duration of use are stored, as well as the sources referring users to our online offering, and technical aspects of their devices and browsers.
    In this process, pseudonymous user profiles are created using information gathered from the use of various devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides approximate geographic location data by deriving the following metadata from IP addresses: city (and the derived city latitude and longitude), continent, country, region, subcontinent (and ID based equivalents). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being immediately deleted. It is not logged, is not accessible, and is not used for any further purposes. When Google Analytics collects measurement data, all IP lookups are carried out on EU based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Security measures: IP masking (pseudonymization of the IP address); Privacy policy: https://policies.google.com/privacy; Data processing agreement: https://business.safety.google/adsprocessorterms/; Basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms); Right to object (opt-out): opt out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, ad personalization settings: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (types of processing and processed data).

Presence on Social Networks (Social Media)

We maintain online presences within social networks and, in this context, process user data in order to communicate with users active there or to provide information about us.

We would like to point out that user data may be processed outside the European Union in this context. This may result in risks for users, since, for example, the enforcement of user rights could be made more difficult.

Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created based on usage behavior and resulting user interests. These profiles may in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For this purpose, cookies are usually stored on users’ computers, in which the usage behavior and interests of the users are stored. In addition, data may also be stored in usage profiles independently of the devices used by users (particularly if they are members of the respective platforms and are logged in there).

For a detailed presentation of the respective forms of processing and the options for objection (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.

Also, in the case of requests for information and the exercise of data subject rights, we would like to point out that these can be exercised most effectively directly with the providers. Only the providers have access to user data and can take appropriate action and provide information directly. If you nevertheless need assistance, you may contact us.

  • Types of data processed: contact data (for example, postal and email addresses or telephone numbers); content data (for example, text or image based messages and posts, as well as information relating to them, such as details of authorship or the time of creation). Usage data (for example, page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions).
  • Data subjects: users (for example, website visitors, users of online services).
  • Purposes of processing and legitimate interests: communication; feedback (for example, collecting feedback via an online form). Public relations.
  • Retention and deletion: deletion in accordance with the details in the section “General Information on Data Storage and Deletion.”
  • Legal bases: legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing activities, procedures, and services:

  • Instagram: Social network, enables the sharing of photos and videos, commenting on and favoriting posts, sending messages, and subscribing to profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.instagram.com; Privacy policy: https://privacycenter.instagram.com/policy/. Basis for third country transfers: Data Privacy Framework (DPF).
  • Facebook pages: Profiles within the Facebook social network. The controller is jointly responsible, together with Meta Platforms Ireland Limited, for collecting and transmitting data about visitors to our Facebook page (“fan page”). This includes, in particular, information about user behavior (for example, content viewed or interacted with, actions taken) as well as device information (for example, IP address, operating system, browser type, language settings, cookie data). More detail can be found in Facebook’s data policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us with statistical evaluations via the “Page Insights” service, which give insight into how people interact with our page and its content. This is based on an agreement with Facebook (“Information about Page Insights”: https://www.facebook.com/legal/terms/page_controller_addendum), which regulates, among other things, security measures as well as the exercise of data subject rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data. Users may therefore direct requests for information or deletion directly to Facebook. The rights of users (in particular access, deletion, objection, complaint to a supervisory authority) remain unaffected by this. Joint responsibility is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for any further processing, including any possible transmission to Meta Platforms Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Basis for third country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).

Plug-ins and Embedded Functions and Content

We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third party providers”). These may include, for example, graphics, videos, or city maps (hereinafter uniformly referred to as “content”).

Integration always requires that the third party providers of this content process the users’ IP address, since without an IP address they would not be able to send the content to the user’s browser. The IP address is therefore necessary for the display of this content or functions. We endeavor to use only content whose respective providers use the IP address solely to deliver the content. Third party providers may also use so called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. Through these “pixel tags,” information such as visitor traffic on the pages of this website can be evaluated. The pseudonymous information may also be stored in cookies on the user’s device, and may contain, among other things, technical information about the browser and operating system, referring websites, the time of visit, as well as further details about the use of our online offering, but may also be combined with such information from other sources.

Notes on legal bases: if we ask users for their consent to the use of third party providers, the legal basis for data processing is that consent. Otherwise, user data is processed on the basis of our legitimate interests (meaning our interest in efficient, economical, and recipient friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: usage data (for example, page views and time spent, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and procedural data (for example, IP addresses, timestamps, identification numbers, persons involved). Location data (information about the geographic position of a device or a person).
  • Data subjects: users (for example, website visitors, users of online services).
  • Purposes of processing and legitimate interests: provision of our online offering and user-friendliness; reach measurement (for example, access statistics, recognition of returning visitors); tracking (for example, interest/behavior based profiling, use of cookies); audience formation. Marketing.
  • Retention and deletion: deletion in accordance with the details in the section “General Information on Data Storage and Deletion.” Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
  • Legal bases: consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing activities, procedures, and services:

  • Google Fonts (retrieved from Google server): Retrieval of fonts (and icons) for the purpose of technically secure, maintenance free, and efficient use of fonts and icons, with regard to their timeliness and load times, their uniform presentation, and consideration of possible licensing restrictions. The font provider is informed of the user’s IP address, so that the fonts can be made available in the user’s browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) is transmitted, which is necessary for providing the fonts depending on the devices used and the technical environment. This data may be processed on a server of the font provider in the USA. When visiting our online offering, users’ browsers send HTTP requests to the Google Fonts Web API (meaning a software interface for retrieving fonts). The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) of Google Fonts and subsequently the fonts specified in the CSS. These HTTP requests include (1) the IP address used by the respective user to access the internet, (2) the requested URL on the Google server, and (3) the HTTP headers, including the user agent, which describes the browser and operating system versions of website visitors, as well as the referrer URL (meaning the web page on which the Google font is to be displayed). IP addresses are neither logged nor stored on Google servers, and they are not analyzed. The Google Fonts Web API logs details of HTTP requests (requested URL, user agent, and referrer URL). Access to this data is limited and strictly controlled. The requested URL identifies the font families for which the user wants to load fonts. This data is logged so that Google can determine how often a particular font family is requested. With the Google Fonts Web API, the user agent must adapt the font generated for the respective browser type. The user agent is primarily logged and used for debugging, and to generate aggregated usage statistics, which are used to measure the popularity of font families. These aggregated usage statistics are published on the Google Fonts “Analytics” page. Finally, the referrer URL is logged, so that the data can be used for production maintenance, and an aggregated report on top integrations can be generated, based on the number of font requests. According to its own statements, Google does not use any of the information collected via Google Fonts to create end user profiles or to serve targeted advertisements; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: legitimate interests (Art. 6(1)(f) GDPR); Website: https://fonts.google.com/; Privacy policy: https://policies.google.com/privacy; Basis for third country transfers: Data Privacy Framework (DPF). Further information: https://developers.google.com/fonts/faq/privacy?hl=de.
  • Google Maps: We integrate the maps of the “Google Maps” service provided by Google. The data processed may include, in particular, IP addresses and location data of users; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal bases: consent (Art. 6(1)(a) GDPR); Website: https://mapsplatform.google.com/; Privacy policy: https://policies.google.com/privacy. Basis for third country transfers: Data Privacy Framework (DPF).
  • YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: consent (Art. 6(1)(a) GDPR); Website: https://www.youtube.com; Privacy policy: https://policies.google.com/privacy; Basis for third country transfers: Data Privacy Framework (DPF). Right to object (opt-out): opt out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, ad personalization settings: https://myadcenter.google.com/personalizationoff.

Changes and Updates

We ask that you regularly inform yourself about the content of our privacy policy. We will adjust the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require your participation (for example, consent) or any other individual notification.

Where we provide addresses and contact information of companies and organizations in this privacy policy, please note that addresses may change over time, and we ask that you verify this information before making contact.

Definitions

This section provides an overview of the terms used in this privacy policy. Where terms are legally defined, their legal definitions apply. The following explanations are primarily intended to aid understanding.

  • Inventory data: inventory data includes essential information necessary for identifying and managing contractual partners, user accounts, profiles, and similar assignments. This data may include, among other things, personal and demographic information such as names, contact information (addresses, telephone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Inventory data forms the basis for any formal interaction between individuals and services, institutions, or systems, by enabling clear identification and communication.
  • Content data: content data includes information generated in the course of creating, editing, and publishing content of any kind. This category of data may include text, images, videos, audio files, and other multimedia content published across various platforms and media. Content data is not limited to the actual content itself, but also includes metadata that provides information about the content, such as tags, descriptions, author information, and publication dates.
  • Contact data: contact data is essential information that enables communication with individuals or organizations. It includes, among other things, telephone numbers, postal addresses, and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
  • Meta, communication, and procedural data: meta, communication, and procedural data are categories that contain information about how data is processed, transmitted, and managed. Metadata, also known as data about data, includes information describing the context, origin, and structure of other data. It may include details about file size, creation date, the author of a document, and change history. Communication data captures the exchange of information between users through various channels, such as email traffic, call logs, messages on social networks, and chat histories, including the persons involved, timestamps, and transmission paths. Procedural data describes the processes and workflows within systems or organizations, including workflow documentation, transaction and activity logs, as well as audit logs used to track and review processes.
  • Member data: member data includes information relating to the individuals who are part of an organization, association, online service, or other group. This data is used to manage memberships, enable communication, and provide services or benefits associated with membership. Member data may include personal identification information, contact information, information on membership status and duration, fee payments, participation in events and activities, as well as preferences and interests. It may also include data on the use of the organization’s offerings. Collection and processing of this data is carried out in compliance with data protection regulations and serves both administrative purposes and the promotion of member engagement and satisfaction.
  • Usage data: usage data refers to information that records how users interact with digital products, services, or platforms. This data includes a wide range of information showing how users use applications, which functions they prefer, how long they stay on certain pages, and what paths they take when navigating an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information, and location data. It is particularly valuable for analyzing user behavior, optimizing user experiences, personalizing content, and improving products or services. In addition, usage data plays a decisive role in identifying trends, preferences, and potential problem areas within digital offerings.
  • Personal data: “personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); a natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (for example, a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
  • Profiles with user-related information: the processing of “profiles with user-related information,” or “profiles” for short, encompasses any type of automated processing of personal data consisting of using such personal data to analyze, evaluate, or predict certain personal aspects relating to a natural person (depending on the type of profiling, this can include various information regarding demographics, behavior, and interests, such as interaction with websites and their content, etc.), for example the interests in certain content or products, click behavior on a website, or location. Cookies and web beacons are frequently used for profiling purposes.
  • Log data: log data is information about events or activities that have been recorded in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages, and other details about the use or operation of a system. Log data is often used to analyze system problems, for security monitoring, or to generate performance reports.
  • Reach measurement: reach measurement (also known as web analytics) is used to evaluate the visitor flows of an online offering and may include the behavior or interests of visitors in certain information, such as website content. With the help of reach analysis, operators of online offerings can, for example, determine at what time users visit their websites and what content they are interested in. This allows them, for example, to better tailor website content to the needs of their visitors. Pseudonymous cookies and web beacons are frequently used for reach analysis purposes, in order to recognize returning visitors and thereby obtain more accurate analyses of the use of an online offering.
  • Location data: location data is generated when a mobile device (or another device with the technical capability for location determination) connects to a cell tower, WLAN, or similar technical means and functions for determining location. Location data is used to indicate the geographically determinable position on Earth at which the respective device is located. Location data may be used, for example, to display map functions or other location dependent information.
  • Tracking: “tracking” refers to the ability to track user behavior across multiple online offerings. As a rule, behavioral and interest information relating to the online offerings used is stored in cookies or on the servers of the providers of the tracking technologies (known as profiling). This information may subsequently be used, for example, to display advertisements to users that are likely to correspond to their interests.
  • Controller: “controller” refers to the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: “processing” is any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses practically any handling of data, whether collecting, evaluating, storing, transmitting, or deleting it.
  • Contract data: contract data is specific information relating to the formalization of an agreement between two or more parties. It documents the conditions under which services or products are provided, exchanged, or sold. This category of data is essential for managing and fulfilling contractual obligations, and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include the start and end dates of the contract, the type of services or products agreed upon, price agreements, payment terms, termination rights, renewal options, and special conditions or clauses. It serves as the legal basis for the relationship between the parties and is decisive for clarifying rights and obligations, enforcing claims, and resolving disputes.
  • Payment data: payment data includes all information required to process payment transactions between buyers and sellers. This data is of crucial importance for electronic commerce, online banking, and any other form of financial transaction. It includes details such as credit card numbers, bank details, payment amounts, transaction data, verification numbers, and invoice information. Payment data may also include information about payment status, chargebacks, authorizations, and fees.
  • Audience formation: audience formation (English “custom audiences”) refers to defining target groups for advertising purposes, for example the display of advertisements. For instance, a user’s interest in certain products or topics on the internet may lead to the conclusion that this user is interested in advertisements for similar products, or for the online shop in which they viewed the products. “Lookalike audiences” (or similar target groups), in turn, refers to displaying content deemed suitable to users whose profiles or interests presumably correspond to the users for whom the profiles were created. Cookies and web beacons are usually used for the purpose of creating custom audiences and lookalike audiences.

Created with the free Privacy Policy Generator from Dr. Thomas Schwenke