We are delighted that you are interested in our organization. The protection of your personal data is of particular importance to our management. You may use our websites without providing any personal data. However, if you wish to use special services via our websites, other online platforms, applications, and social media pages, we may need to process your personal data. Where we intend to process your data and cannot rely on another legal basis, we will always ask for your consent first (for example, via a cookie banner).

When handling your personal data (such as your name, address, email address, or telephone number), we always comply with the applicable data protection laws. Through this Privacy Policy, we inform you which data we process and what rights you have as a data subject.

We have implemented a variety of technical and organizational measures to protect your data on our websites as effectively as possible. Nevertheless, there are always risks associated with Internet-based data transmissions, and complete protection cannot be guaranteed. Therefore, if you prefer, you may also transmit your personal data to us by alternative means, such as by telephone.

This Privacy Policy serves not only to fulfill the requirements of the General Data Protection Regulation (GDPR) and the laws of the Member States of the European Union (EU) and the European Economic Area (EEA). It is also intended to comply with and be interpreted in accordance with other applicable privacy laws, including but not limited to the UK GDPR, the Swiss Federal Act on Data Protection (FADP), the California Consumer Privacy Act (CCPA/CPRA), China’s Personal Information Protection Law (PIPL), and other global privacy regulations.

For reasons of readability, this Privacy Policy and our communications may use gender-neutral language or general grammatical forms. All terms apply equally to all genders.


1. Definitions

In this Privacy Policy, we use certain legal terms that originate from various privacy laws. To make this policy easier to understand, we explain these terms in advance.

a) Personal Data

Personal data means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

b) Data Subject

A data subject is any identified or identifiable natural person whose personal data is processed by a controller, processor, international organization, or other recipient.

c) Processing

Processing means any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, restriction, erasure, or destruction.

d) Restriction of Processing

Restriction of processing means the marking of stored personal data with the aim of limiting its future processing.

e) Profiling

Profiling means any form of automated processing of personal data used to evaluate certain personal aspects relating to a natural person, particularly to analyze or predict aspects concerning performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

f) Pseudonymization

Pseudonymization means the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and protected by technical and organizational measures.

g) Controller

A controller is the natural or legal person, public authority, agency, or other body which determines the purposes and means of processing personal data, alone or jointly with others.

h) Processor

A processor is a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

i) Recipient

A recipient is a natural or legal person, public authority, agency, or other body to which personal data is disclosed, regardless of whether it is a third party.

j) Third Party

A third party is any natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons authorized to process personal data under the direct authority of the controller or processor.

k) Consent

Consent means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them.


2. Name and Address of the Controller

Generation Hope by Point of Difference e.V.
Wollgrasstr. 1a
26802 Moormerland
Germany

Phone: +49 4954 3052873
Email: Info@generationhope.de
Website: https://www.generationhope.de

Because the uploaded document was truncated, I do not have access to the complete text. To translate the entire privacy policy accurately, I would need access to the full document content rather than the truncated extract.

3. Collection of General Data and Information

Our websites collect a series of general data and information each time they are accessed by a data subject or an automated system. This general data and information are stored in the log files of the respective server. The following may be collected:

  1. the browser types and versions used,
  2. the operating system used by the accessing system,
  3. the website from which an accessing system reaches our website (so-called referrers),
  4. the subpages accessed on our website via an accessing system,
  5. the date and time of access to the website,
  6. an Internet Protocol address (IP address),
  7. the Internet service provider of the accessing system, and
  8. other similar data and information used for security purposes in the event of attacks on our information technology systems.

When using this general data and information, we do not draw any conclusions about the data subject. Rather, this information is required to:

  1. correctly deliver the content of our websites,
  2. optimize the content of our websites and related advertising,
  3. ensure the ongoing functionality of our information technology systems and website technology, and
  4. provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack.

Therefore, these anonymously collected data and information are evaluated both statistically and with the aim of increasing data protection and data security within our organization, ultimately ensuring an optimal level of protection for the personal data we process.

The server log file data are stored separately from any personal data provided by a data subject.

Purpose of processing: Prevention of threats, ensuring IT security, and the purposes mentioned above.

Legal basis: Article 6(1)(f) GDPR.

Legitimate interest: In particular, the protection of our information technology systems.

Retention period: Log files are deleted once the purposes described above have been fulfilled.


4. Contact Options via the Website and Other Data Transfers; Your Consent

Our websites contain information that enables a quick electronic contact with our organization and direct communication with us, including a general email address and, where applicable, a telephone number.

If a data subject contacts us by email, through a contact form, an input form, or by any other means, the personal data transmitted by the data subject are automatically stored. Such personal data voluntarily provided to us are processed for the purpose of handling the inquiry or communicating with the data subject.

For the transmission, storage, and processing of your contact details and inquiries, as well as for contacting you, we obtain your consent pursuant to Article 6(1)(a) GDPR and Article 49(1)(a) GDPR as follows:

By submitting your personal data, you voluntarily consent to the processing of the personal data you have entered or provided for the purpose of handling your inquiry and contacting you. By transmitting your data to us, you also voluntarily provide your explicit consent pursuant to Article 49(1)(a) GDPR for transfers of data to third countries involving the companies and purposes described in this Privacy Policy. This includes transfers to countries for which an adequacy decision by the EU/EEA may or may not exist, as well as transfers to companies or other entities that are not covered by an adequacy decision through self-certification or other accession criteria, and where significant risks and inadequate safeguards for the protection of your personal data may exist (e.g., due to Section 702 FISA, Executive Order 12333, or the U.S. CLOUD Act).

By giving your voluntary and explicit consent, you acknowledge that an adequate level of data protection may not exist in certain third countries and that your rights as a data subject may not be enforceable there. You may withdraw your consent at any time with future effect. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

By a single act of entering and submitting your data, you grant multiple consents, including consents under EU/EEA data protection law, the CCPA/CPRA, ePrivacy law, telecommunications and telemedia law, and other international legal provisions that may serve as the legal basis for further processing of your personal data. By submitting your data, you also confirm that you have read and understood this Privacy Policy.


5. Routine Erasure and Restriction of Personal Data

We process and store personal data only for the period necessary to achieve the purpose of processing, or for as long as required by European directives and regulations, other legislators, applicable laws, or as long as a valid legal basis for processing exists.

If the purpose of processing ceases to apply, the legally prescribed retention period expires, or the legal basis for processing no longer exists, personal data will be routinely restricted or deleted in accordance with the applicable legal provisions.

6. Rights of the Data Subject under the GDPR

a) Right to Confirmation

Every data subject has the right to obtain confirmation from the controller as to whether personal data concerning them are being processed.

If a data subject wishes to exercise this right, they may contact us at any time.

b) Right of Access

Every data subject has the right to obtain, free of charge and at any time, information about the personal data stored concerning them and a copy of such data.

Furthermore, the GDPR grants data subjects access to the following information:

  • the purposes of the processing,
  • the categories of personal data concerned,
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed, particularly recipients in third countries or international organizations,
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period,
  • the existence of the right to request rectification or erasure of personal data, restriction of processing, or to object to processing,
  • the existence of the right to lodge a complaint with a supervisory authority,
  • where the personal data are not collected from the data subject, any available information as to their source,
  • the existence of automated decision-making, including profiling pursuant to Article 22(1) and (4) GDPR, and meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing.

The data subject also has the right to know whether personal data have been transferred to a third country or an international organization. Where this is the case, the data subject has the right to be informed of the appropriate safeguards relating to the transfer.

If a data subject wishes to exercise this right, they may contact us at any time.

c) Right to Rectification

Every data subject has the right to obtain without undue delay the rectification of inaccurate personal data concerning them.

Taking into account the purposes of the processing, the data subject also has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

If a data subject wishes to exercise this right, they may contact us at any time.

d) Right to Erasure (“Right to be Forgotten”)

Every data subject has the right to obtain from the controller the erasure of personal data concerning them without undue delay where one of the following grounds applies and the processing is not otherwise required:

  • The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
  • The data subject withdraws consent on which the processing is based and there is no other legal ground for the processing.
  • The data subject objects to processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for the processing, or objects pursuant to Article 21(2) GDPR.
  • The personal data have been unlawfully processed.
  • The personal data must be erased for compliance with a legal obligation under EU or Member State law.
  • The personal data were collected in relation to information society services offered pursuant to Article 8(1) GDPR.

Where one of the above grounds applies and a data subject wishes to request the deletion of personal data stored by us, they may contact us at any time.

Where we have made personal data public and are obliged pursuant to Article 17(1) GDPR to erase the data, we shall, taking account of available technology and implementation costs, take reasonable steps, including technical measures, to inform other controllers processing the personal data that the data subject has requested the erasure of any links to, copies of, or replications of those personal data, insofar as processing is not required.

e) Right to Restriction of Processing

Every data subject has the right to obtain restriction of processing where one of the following applies:

  • The accuracy of the personal data is contested by the data subject, for a period enabling verification of the accuracy of the data.
  • The processing is unlawful and the data subject opposes erasure and requests restriction instead.
  • The controller no longer needs the data for processing purposes, but the data subject requires them for the establishment, exercise, or defense of legal claims.
  • The data subject has objected to processing pursuant to Article 21(1) GDPR and verification of overriding legitimate grounds is pending.

If one of the above conditions is met and a data subject wishes to request restriction of processing, they may contact us at any time.

f) Right to Data Portability

Every data subject has the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used, and machine-readable format.

They also have the right to transmit those data to another controller without hindrance, where:

  • the processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, or on a contract pursuant to Article 6(1)(b) GDPR; and
  • the processing is carried out by automated means.

Furthermore, when exercising the right to data portability pursuant to Article 20(1) GDPR, the data subject has the right to have the personal data transmitted directly from one controller to another, where technically feasible and where doing so does not adversely affect the rights and freedoms of others.

If a data subject wishes to exercise this right, they may contact us at any time.

g) Right to Object

Every data subject has the right, on grounds relating to their particular situation, to object at any time to processing of personal data concerning them based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions.

We shall no longer process the personal data unless we demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.

Where we process personal data for direct marketing purposes, the data subject has the right to object at any time to such processing, including profiling related to direct marketing. If the data subject objects, we will no longer process the personal data for these purposes.

Additionally, the data subject may object, on grounds relating to their particular situation, to the processing of personal data for scientific or historical research purposes or for statistical purposes pursuant to Article 89(1) GDPR, unless such processing is necessary for the performance of a task carried out for reasons of public interest.

The data subject may exercise this right at any time by contacting us. They are also free, in the context of the use of information society services and notwithstanding Directive 2002/58/EC, to exercise their right to object by automated means using technical specifications.

h) Automated Individual Decision-Making, Including Profiling

Every data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision:

  1. is necessary for entering into or performing a contract between the data subject and the controller;
  2. is authorized by Union or Member State law and includes suitable safeguards; or
  3. is based on the data subject’s explicit consent.

In cases (1) and (3), we shall implement appropriate measures to safeguard the rights, freedoms, and legitimate interests of the data subject, including at least the right to obtain human intervention, express their point of view, and contest the decision.

If a data subject wishes to exercise this right, they may contact us at any time.

i) Right to Withdraw Data Protection Consent

Every data subject has the right to withdraw consent to the processing of personal data at any time.

If a data subject wishes to exercise this right, they may contact us at any time.

7. General Purpose of Processing, Categories of Processed Data, and Categories of Recipients

The general purpose of processing personal data is the handling of all matters relating to the controller, customers, prospective customers, business partners, or other contractual or pre-contractual relationships between these groups (in the broadest sense), as well as the fulfillment of the controller’s legal obligations. This general purpose applies whenever no more specific purpose is stated for a particular processing activity.

The categories of personal data processed by us include:

  • Customer data
  • Prospective customer data
  • Employee data (including applicant data)
  • Supplier data

The categories of recipients of personal data include:

  • Public authorities
  • External entities
  • Internal departments
  • Intra-group entities
  • Other organizations and entities

A list of our data processors, recipients in third countries, and, where applicable, international organizations is either published on our website or can be requested from us free of charge.


8. Legal Bases for Processing

Article 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose.

Where the processing of personal data is necessary for the performance of a contract to which the data subject is a party—such as processing required for the delivery of goods or the provision of services—the processing is based on Article 6(1)(b) GDPR. The same applies to processing necessary for carrying out pre-contractual measures, for example in connection with inquiries regarding our products or services.

Where we are subject to a legal obligation requiring the processing of personal data, such as compliance with tax obligations, the processing is based on Article 6(1)(c) GDPR.

In rare cases, processing of personal data may be necessary to protect the vital interests of the data subject or another natural person. For example, if a visitor were injured at our premises and their name, age, health insurance details, or other vital information had to be disclosed to a doctor, hospital, or another third party, the processing would be based on Article 6(1)(d) GDPR.

Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, the legal basis is Article 6(1)(e) GDPR.

Finally, processing operations may be based on Article 6(1)(f) GDPR. This legal basis applies to processing activities not covered by any of the foregoing legal bases, where processing is necessary for the purposes of the legitimate interests pursued by our organization or by a third party, except where such interests are overridden by the interests, fundamental rights, and freedoms of the data subject.

Such processing operations are permitted in particular because they have been expressly recognized by the European legislator. In this regard, the legislator considered that a legitimate interest may exist, for example, where the data subject is a customer of the controller (Recital 47, sentence 2 GDPR).


9. Legitimate Interests Pursued by the Controller or a Third Party and Direct Marketing

Where the processing of personal data is based on Article 6(1)(f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the conduct of our business activities for the benefit of our employees and stakeholders.

We may send you direct marketing regarding our own goods or services that are similar to products or services you have requested, ordered, or purchased.

You may object to direct marketing at any time (for example, by email). No costs will arise other than the transmission costs according to the applicable basic rates.

The processing of personal data for direct marketing purposes is based on Article 6(1)(f) GDPR. The legitimate interest is direct marketing.

Our messages and newsletters may also constitute communication for the purposes of direct marketing within the meaning of Article 13(2) of Directive 2002/58/EC (ePrivacy Directive) and the applicable national laws derived from that Directive, provided that:

  • we obtained your electronic or other contact information in connection with the sale of a product or service, including the creation of a free user account that grants access to free content on our websites or publications (such as newsletters); and
  • we use those contact details to promote similar products or services.

In such cases, direct marketing may be permissible without separate consent (see ECJ judgment of 13 November 2025, Case C‑654/23).

You may object to the use of your contact information at any time and free of charge.


10. Period for Which Personal Data Will Be Stored

The criterion used to determine the duration of storage of personal data is the applicable statutory retention period.

Where no statutory retention period exists, the applicable criterion is the contractual retention period or our internal retention policies.

Upon expiry of the relevant retention period, the corresponding data will be routinely deleted, provided they are no longer required for the performance or initiation of a contract.

This applies in particular to all processing activities for which no more specific retention criteria have been defined.


11. Statutory or Contractual Requirements to Provide Personal Data; Necessity for Contract Conclusion; Obligation of the Data Subject to Provide Personal Data; Possible Consequences of Failure to Provide Such Data

We inform you that the provision of personal data may in part be required by law (e.g., tax regulations) or may result from contractual provisions (e.g., information relating to the contractual partner).

In some cases, the conclusion of a contract may require a data subject to provide us with personal data that we must subsequently process.

For example, a data subject is obliged to provide personal data where our organization enters into a contract with them.

Failure to provide the required personal data would result in the contract not being concluded.

Before providing personal data, the data subject should contact us. We will clarify on a case-by-case basis:

  • whether the provision of personal data is required by law or contract,
  • whether the provision of personal data is necessary for the conclusion of a contract,
  • whether there is an obligation to provide the personal data, and
  • what consequences may result from failure to provide the personal data.

12. Existence of Automated Decision-Making

As a responsible organization, we generally refrain from automated decision-making and profiling.

If, in exceptional cases, we carry out automated decision-making or profiling, we will inform the data subject separately or by means of a specific subsection within this Privacy Policy.

In such cases, the following applies:

Automated decision-making, including profiling, may take place where:

  1. it is necessary for entering into or performing a contract between the data subject and us;
  2. it is authorized by Union or Member State law to which we are subject and those laws contain appropriate measures to safeguard the rights, freedoms, and legitimate interests of the data subject; or
  3. it is based on the explicit consent of the data subject.

In the cases referred to in Article 22(2)(a) and (c) GDPR, we shall take appropriate measures to safeguard the rights, freedoms, and legitimate interests of the data subject.

In these situations, you have at least the right to:

  • obtain human intervention on the part of the controller,
  • express your own point of view, and
  • contest the decision.

Meaningful information about the logic involved, as well as the significance and intended consequences of such processing for the data subject, will be provided in this Privacy Policy where applicable.

13. Recipients in Third Countries and Appropriate or Suitable Safeguards, and How to Obtain a Copy of Them or Where They Are Available

Pursuant to Article 46(1) GDPR, a controller or processor may transfer personal data to a third country only if appropriate safeguards have been provided and enforceable data subject rights and effective legal remedies are available.

Appropriate safeguards may, without requiring specific authorization from a supervisory authority, be provided through Standard Contractual Clauses (SCCs) in accordance with Article 46(2)(c) GDPR.

Before any initial transfer of personal data to recipients in third countries, we conclude the EU Standard Contractual Clauses or other appropriate safeguards with such recipients, or the transfers are based on adequacy decisions. As a result, appropriate safeguards, enforceable rights, and effective remedies are ensured for all processing activities involving personal data.

Any data subject may obtain a copy of the Standard Contractual Clauses or adequacy decisions from us. These documents are also available in the Official Journal of the European Union.

Article 45(3) GDPR empowers the European Commission to determine, by means of an implementing act, that a non-EU country ensures an adequate level of protection. This means a level of protection for personal data that is essentially equivalent to the level of protection within the EU.

Adequacy decisions allow personal data to flow from the EU (as well as Norway, Liechtenstein, and Iceland) to a third country without additional restrictions. Similar rules apply in the United Kingdom, Switzerland, and certain other jurisdictions.

In all cases where the European Commission, or the government or competent authority of another country, has determined that a third country ensures an adequate level of protection and/or where a valid framework exists (e.g., the EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, or UK Extension to the EU-U.S. Data Privacy Framework), all of our transfers to members of such frameworks (e.g., self-certified organizations) are based solely on their participation in the respective framework or the applicable adequacy decisions.

If we or one of our affiliated companies are members of such a framework, transfers to us or our affiliated companies are based solely on that membership. Likewise, where we or one of our affiliated companies are established in a third country recognized as providing an adequate level of protection, transfers to us or our affiliated companies are based solely on the relevant adequacy decision.

Any data subject may obtain a copy of such frameworks from us. The frameworks are also available in the Official Journal of the European Union, in published legislative materials, or on the websites of data protection supervisory authorities and other competent authorities or institutions.


14. Right to Lodge a Complaint with a Data Protection Supervisory Authority

As the controller, we are obliged to inform data subjects of their right to lodge a complaint with a supervisory authority.

This right is set out in Article 77(1) GDPR.

Under this provision, every data subject has the right, without prejudice to any other administrative or judicial remedy, to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement, if they consider that the processing of personal data relating to them infringes the GDPR.

The European legislator has limited this right to the extent that it may be exercised before only one supervisory authority (Recital 141, sentence 1 GDPR). This rule is intended to avoid duplicate complaints concerning the same matter by the same data subject.

Therefore, if a data subject wishes to lodge a complaint concerning us, we kindly request that only a single supervisory authority be contacted.


15. Data Protection in Applications and the Recruitment Process

We collect and process the personal data of applicants as part of the recruitment process. Processing may also take place electronically.

This is particularly the case if an applicant submits relevant application documents to us electronically, for example by email or via a web form located on our website or on a third-party website.

For applicant data, the purpose of processing is to evaluate the application during the recruitment process.

For this purpose, we process all data provided by the applicant. Based on the information submitted as part of the application, we assess whether the applicant should be invited to an interview as part of the selection process.

Furthermore, in the case of applicants who are generally considered suitable, we may process additional personal data provided by them, particularly during interviews, where such information is relevant to our hiring decision.

Legal bases for processing:

  • Article 6(1)(b) GDPR
  • Article 9(2)(b) GDPR
  • Article 9(2)(h) GDPR
  • Article 88(1) GDPR
  • Applicable national legislation

If no employment contract is concluded with the applicant, the application documents will be deleted no later than six months after the rejection decision has been communicated, provided that no other legitimate interests of the controller prevent deletion.

Such a legitimate interest may exist, for example, where the information is required for evidentiary purposes in legal proceedings.


16. Registration or Completion of Input Forms on Our Website and Your Consent

You may register on our websites and/or complete input forms by providing personal data.

The specific personal data transmitted to us are determined by the respective registration or input form used.

The personal data you enter are processed exclusively for our internal use and our own purposes.

However, we may disclose your personal data to one or more processors, such as parcel delivery service providers, who may only use the personal data for purposes attributable to us as the controller.

Disclosure may also occur if you instruct us to share the data. In such cases, the legal basis is Article 6(1)(b) GDPR.

By registering or entering information on our website, the IP address assigned by your Internet Service Provider (ISP), together with the date and time of registration or submission, may also be stored.

These data are stored because this is the only way to prevent misuse of our services and, where necessary, to investigate criminal offences.

Accordingly, the storage of these data is necessary for our protection.

Purpose of processing:

  • Prevention of threats
  • Detection of misuse
  • Investigation of criminal offences
  • The purposes described above

Legal basis: Article 6(1)(f) GDPR.

Legitimate interest: In particular, the protection of our IT systems and the investigation of criminal offences.

As a general rule, these data will not be disclosed to third parties unless disclosure is required by law or serves the prosecution of criminal offences.

Registration, submission, and transmission of your personal data also enable us to provide content or services that, by their nature, can only be offered to registered users or persons known to us.

You are free to modify the personal data provided during registration at any time or to request its deletion from our records.

Purposes of processing:

  • Receipt of data by us
  • Further processing of your data
  • Communication with you
  • Implementation of the registration or input purposes

Legal basis: Your consent pursuant to Article 6(1)(a) GDPR and/or Article 49(1)(a) GDPR.

Consent Statement

By entering and submitting your data, you voluntarily consent to the processing of the personal data you have entered. By providing and transmitting your data to us, you also voluntarily grant your explicit consent pursuant to Article 49(1)(a) GDPR for transfers of data to third countries involving the companies and purposes named in this Privacy Policy. This includes transfers to countries for which an EU/EEA adequacy decision exists or does not exist, and to organizations that are not covered by an adequacy decision through self-certification or similar mechanisms, and where significant risks and insufficient safeguards for the protection of personal data may exist (e.g., due to Section 702 FISA, Executive Order EO 12333, and the U.S. CLOUD Act).

By providing your voluntary and explicit consent, you acknowledge that adequate data protection levels may not exist in certain third countries and that your rights as a data subject may not be enforceable there. You may withdraw your consent at any time with future effect. Withdrawal does not affect the lawfulness of processing based on consent before the withdrawal.

By one single action (entering and submitting your data), you grant multiple consents, including those under EU/EEA data protection law, the CCPA/CPRA, ePrivacy law, telemedia law, and other international legal provisions that may be required as legal bases for future processing of your personal data. By your action, you also confirm that you have read and understood this Privacy Policy.

Upon request, we will provide any data subject with information regarding the personal data stored about them at any time.

Furthermore, we will correct or delete personal data upon request or notification by the data subject, provided that no statutory retention obligations or other valid legal grounds for processing prevent us from doing so.

All of our employees are available as contact persons in this regard.

17. Blog and Comment Function

A blog is a publicly accessible portal in which one or more persons, known as bloggers or web bloggers, publish articles or thoughts in so-called blog posts. Our blog may allow you to leave individual comments on blog posts.

If you leave comments on our blog, in addition to the comment itself, information about the time the comment was entered and your username (or a pseudonym, where applicable) will be stored, published, and distributed.

By submitting comments, you enter into a publication agreement with us under which you grant us all worldwide copyright usage rights to your comments, free of charge and irrevocably. This includes, in particular, the rights to reproduce, distribute, and make publicly available any comments you submit.

The legal basis for this processing is therefore Article 6(1)(b) GDPR.

Purposes of processing:

  • Providing a blog with a comment function
  • Enabling users to submit comments

In addition, when a comment is submitted, the IP address assigned to your internet connection by your Internet Service Provider (ISP) is logged.

The storage of the IP address serves security purposes and protects us in the event that you infringe the rights of third parties or post unlawful content through a comment. The storage of this personal data is therefore in our own legitimate interest so that, where necessary, we can exonerate ourselves in the event of a legal violation.

These purposes constitute our legitimate interests pursuant to Article 6(1)(f) GDPR.

As a general rule, these data are not disclosed to third parties unless disclosure is legally required or serves criminal prosecution or legal defense.


18. Subscription to Comments

Comments posted on our blog can generally be subscribed to by any visitor.

In particular, a commenter may subscribe to follow-up comments posted after their own comment on a specific blog article.

For legal reasons, a confirmation email using the double opt-in procedure is sent to the email address initially entered by the data subject for the comment subscription.

This confirmation email serves to verify whether the owner of the email address, as the data subject, has authorized the comment subscription.

Legal basis for sending the confirmation email:

Article 6(1)(c) GDPR, as there is a legal obligation to send comment subscriptions only to confirmed recipients.

The option to subscribe to comments may be terminated at any time.

Purposes of processing:

  • Providing a blog with a comment function
  • Enabling users to subscribe to comments

Legal basis for sending comment notifications:

Article 6(1)(b) GDPR, based on the contract concluded with us for the delivery of comment notifications.


19. Privacy Policy Regarding the Use of Real Cookie Banner: GDPR & ePrivacy Cookie Consent

Real Cookie Banner is a WordPress plugin that enables website operators to manage cookie consent in compliance with the GDPR and the ePrivacy Directive.

The tool provides a solution for the legally compliant collection and management of consent regarding the use of cookies and other tracking technologies on websites. It also allows users to customize their preferences concerning the processing of their personal data through cookies.

The application is installed on our own IT infrastructure. We are the operator of the service.

Purpose and Legal Basis

The purpose of using Real Cookie Banner is to ensure compliance with legal requirements regarding the use of cookies and tracking technologies.

The processing is based on Article 6(1)(c) GDPR, as it is necessary for compliance with a legal obligation to which our organization is subject.

Retention Criteria

The criteria for determining the duration of processing are statutory or contractual retention periods.

The processing of personal data is legally required because it is necessary for compliance with data protection and consent-management obligations.

Users are required to provide their cookie preferences or reject cookies, and this information must be stored to properly document their decision.

Further information about Real Cookie Banner is available at WordPress.org.


20. Privacy Policy Regarding the Use of CodeTwo Email Signatures 365

We use CodeTwo Email Signatures 365 to centrally manage email signatures for our Microsoft 365 accounts.

This cloud-based service enables us to create, maintain, and automatically insert consistent, professionally designed signatures across the organization in both outgoing and internal emails.

The integration takes place directly with Microsoft 365 and Exchange Online.

In the course of this processing, personal data contained in email content or signature data may be processed, including:

  • First and last names
  • Job titles
  • Contact details such as email addresses and telephone numbers
  • Company information
  • Custom user fields

The service does not access the body content of emails. Instead, it processes email headers and user information to correctly apply signatures.

This process occurs server-side after a message is sent and does not alter the actual email content.

The application also allows statistical evaluations, such as:

  • Signature usage statistics
  • Click analyses on embedded banners and links

Configuration and management are performed through a web-based administration portal accessible to authorized administrators.

The solution is fully integrated with Microsoft Azure and the Microsoft Graph API.

Service Provider

CodeTwo sp. z o.o. sp. k.
Wolności 16
58-500 Jelenia Góra
Poland

Purpose and Legal Basis

The processing is carried out to ensure:

  • Consistent and automated provision of email signatures
  • Uniform corporate presentation in business communications

The processing is based on Article 6(1)(f) GDPR.

Legitimate interest:

  • Automated signature management
  • Improved corporate presentation
  • Centralized administration
  • Reduction of manual configuration by employees

Retention Criteria

The retention period is determined by:

  • The contractual relationship between us and the service provider, and/or
  • Applicable legal or contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data to us or to the service provider.

However, if such data are not provided, our services or the services of the provider may not be available in whole or in part.

Further information and the applicable privacy policy of CodeTwo can be found at:

https://www.codetwo.com

21. Privacy Policy Regarding the Use of DeepL

We use the DeepL translation service to efficiently and accurately translate content into other languages.

DeepL provides advanced AI-based translation technology that enables us to translate texts from various sources into different target languages, either manually via the web portal or automatically through APIs.

During this process, personal data may be processed, particularly where users submit content containing personal information.

Additionally, DeepL automatically processes technical metadata such as:

  • IP addresses
  • Browser information
  • Time stamps
  • Usage data

When texts are submitted for translation, processing is generally temporary.

According to DeepL, content entered through the web application is used solely for translation purposes and is not permanently stored unless users make use of additional features such as:

  • Saved translation histories
  • User accounts

When using the Pro version, additional data may be processed, including:

  • Account information
  • Billing information
  • Preferred language settings
  • Contractual usage details

DeepL uses this information to:

  • Provide contracted services
  • Ensure quality assurance
  • Analyze usage
  • Improve its technology

Processing is carried out automatically.

Service Provider

DeepL SE
Maarweg 165
50825 Cologne
Germany

Purpose and Legal Basis

The purposes of processing include:

  • Provision of machine translation services
  • User account management
  • Improvement of translation quality
  • Protection and maintenance of technical operations

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • User-friendly translation services
  • Secure and efficient operation
  • Continuous technological improvement

Retention Criteria

The retention period is determined by:

  • The contractual relationship between us and DeepL, and/or
  • Applicable legal or contractual retention periods

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for contract formation

You are not obliged to provide personal data.

However, if personal data are not provided, our services or DeepL’s services may not be fully available.

Further information and DeepL’s privacy policy can be found at:

https://www.deepl.com/privacy

22. Privacy Policy Regarding the Use of Facebook Connect

We use Facebook Connect to allow users to register or log in to our website conveniently using their Facebook credentials. The service simplifies access by automating login processes and transferring profile information.

In the course of using Facebook Connect, personal data may be processed, particularly data that users provide to Facebook or that is transmitted technically. This includes, among other things:

  • Name
  • Email address
  • Profile picture
  • Language settings
  • Facebook ID
  • IP address
  • Browser data
  • Device data
  • Login timestamps

Processing is carried out automatically through Meta’s systems.

Once users log in with Facebook, Facebook provides us with an authenticated connection, confirms their identity, and transmits the profile information they have authorized for sharing. Data transmission is encrypted.

Meta uses this information for authentication, improving user security, and analyzing login behavior. We receive only the data that users have authorized us to access.

Service Provider

Meta Platforms, Inc.
1 Meta Way
Menlo Park, CA 94025
USA

For data subjects in the EU and EEA:

Meta Platforms Ireland Ltd.
Merrion Road
Dublin D04 X2K5
Ireland

Representative in the United Kingdom:

Meta Platforms Technologies UK Ltd
10 Brock Street
Regent’s Place
London NW1 3FG
United Kingdom

Purpose and Legal Basis

The purpose of processing is to optimize and simplify the login process.

The processing is based on Article 6(1)(f) GDPR.

Legitimate interest: Efficient authentication and login to our systems and websites.

International Data Transfers

The service provider is located in a third country, namely the United States.

Data transfers may be based on:

  • Standard Contractual Clauses (SCCs)
  • Other appropriate safeguards under Article 46(2) GDPR

Meta may also be certified under one or more Data Privacy Frameworks.

Information is available at:

https://www.dataprivacyframework.gov/list

A copy of the applicable safeguards can be requested from us.

Retention Criteria

Data retention depends on:

  • The contractual relationship between us and Meta
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if the data are not provided, our services or Facebook Connect services may not be available.

Further information and Meta’s privacy policy are available at:

https://facebook.com

23. Privacy Policy Regarding the Use of Google Chrome

We use the Google Chrome web browser for accessing web-based applications, displaying internet content, and integrating browser-based business services.

Google Chrome is provided by Google and offers numerous features, including:

  • Synchronization across devices through Google accounts
  • Integration with other Google services
  • Automatic form completion
  • Voice control
  • Browser extensions
  • Security technologies

When using Google Chrome, personal data may be processed, especially when the browser is linked to a Google account or when users voluntarily activate synchronization services and extensions.

The processed data may include:

  • IP addresses
  • Search queries
  • Browsing history
  • Installed extensions
  • Location data
  • Language settings
  • Technical device information

When users are logged into a Google account, browser activities such as:

  • Visited websites
  • Bookmarks
  • Passwords
  • Browser settings

may be synchronized across devices and stored on Google servers.

Chrome may also collect diagnostic and usage data to improve browser stability, security, and performance, provided this function is enabled.

Personal information may additionally be processed locally or server-side when using automatic form completion (e.g., addresses or credit card information).

Chrome may also utilize third-party services such as:

  • Google Safe Browsing
  • Translation services

which may trigger additional processing operations.

Service Provider

Google LLC
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA

For data subjects in the EU and EEA:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Representative in the United Kingdom:

Google UK Limited
Belgrave House
76 Buckingham Palace Road
London SW1W 9TQ
United Kingdom

Swiss Representative:

Google Switzerland GmbH
Brandschenkestrasse 110
8002 Zurich
Switzerland

Purpose and Legal Basis

The processing serves the following purposes:

  • Secure and stable browser operation
  • Personalized browser functionality
  • Synchronization of user preferences
  • Browser performance improvements
  • Protection against malicious content
  • Integration with other Google services

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Secure provision of internet functions
  • Technical stability
  • User convenience
  • Integration of services that improve the online experience

International Data Transfers

Google is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Google may also be certified under one or more Data Privacy Frameworks.

Information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards can be requested from us.

Retention Criteria

Data retention depends on:

  • The contractual relationship with Google
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for contract formation

You are not obliged to provide personal data.

However, if such data are not provided, our services or Google services may not be fully available.

Further information and Google’s privacy policy are available at:

https://policies.google.com/privacy

24. Privacy Policy Regarding the Use of Microsoft Dynamics 365

We use Microsoft Dynamics 365 to manage and optimize business processes in the areas of:

  • Customer Relationship Management (CRM)
  • Sales
  • Marketing
  • Customer Service
  • Finance

Dynamics 365 is a cloud-based business solution that integrates a variety of applications through a unified platform.

As part of our use of Dynamics 365, we process personal data such as:

  • First and last names
  • Email addresses
  • Telephone numbers
  • Professional contact details
  • Customer numbers
  • Communication content
  • Contract data
  • Quotation and proposal data
  • Interaction history
  • IP addresses
  • System access timestamps
  • User identifiers
  • Device data
  • Browser information

The processing is performed to:

  • Organize customer relationships
  • Facilitate sales and support communications
  • Generate quotations and process orders
  • Document business activities
  • Automate internal processes

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

For data subjects in the EU and EEA:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

Representative in the United Kingdom:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

International Data Transfers

Microsoft is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses (SCCs)
  • Other safeguards under Article 46(2) GDPR

Microsoft is certified under:

  • EU-U.S. Data Privacy Framework
  • UK Extension to the EU-U.S. Data Privacy Framework
  • Swiss-U.S. Data Privacy Framework

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the applicable safeguards may be requested from us.

Purpose and Legal Basis

The purposes of processing are:

  • Digital management and analysis of customer data
  • Management of sales and marketing information
  • Business process administration
  • Efficient organization of internal operations

The processing is based on:

  • Article 6(1)(b) GDPR (performance or initiation of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Improving customer relationships
  • Workflow automation
  • Traceability of business interactions
  • Centralized data management

Retention Criteria

Retention depends on:

  • The contractual relationship between us and Microsoft
  • Applicable legal retention requirements
  • Applicable contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if the data are not provided, our services or Microsoft’s services may not be available.

Further information and Microsoft’s privacy policy are available at:

https://microsoft.com

25. Privacy Policy Regarding the Use of Microsoft Edge

We use the Microsoft Edge web browser. When using the browser, personal data may be processed by Microsoft, particularly when features such as synchronization with a Microsoft account, browser extensions, Bing search integration, or personalized content display are used.

When visiting websites, Microsoft Edge processes various technical information required for displaying content and interacting with online services, including:

  • IP addresses
  • Browser type and browser version
  • Language settings
  • Operating systems used
  • Device identifiers
  • Location data
  • Cookies
  • Stored form data
  • Visited URLs

Microsoft Edge may also interact with other Microsoft services, for example:

  • Microsoft SmartScreen (protection against malicious websites)
  • Microsoft 365 accounts
  • Synchronization of favorites and passwords

In this context, personal data may be transferred to Microsoft for identity verification, usage analysis, and security improvements.

Users can enable or disable these features through the browser settings.

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

For data subjects in the EU and EEA:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

Representative in the United Kingdom:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

Purpose and Legal Basis

The purpose of processing is to provide a modern web browser with advanced functionality for displaying content, online interaction, and security.

The processing is based on Article 6(1)(f) GDPR.

Legitimate interests:

  • Secure and convenient use of web services
  • Synchronization of settings across devices
  • Improvement of browser performance
  • Improvement of browser security

International Data Transfers

Microsoft is located in the United States.

Transfers to third countries may be based on:

  • Standard Contractual Clauses (SCCs)
  • Other appropriate safeguards under Article 46(2) GDPR

Microsoft may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Microsoft
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is not:

  • legally required,
  • contractually required, nor
  • necessary for entering into a contract.

You are not obliged to provide personal data to Microsoft. However, without providing such data, certain browser functions may not be fully available.

Further information and Microsoft’s privacy policy can be found at:

https://privacy.microsoft.com

26. Privacy Policy Regarding the Use of Microsoft Login / Sign-In

We use Microsoft Login / Sign-In to provide users with secure authentication when accessing our web-based applications and systems.

This service forms part of the Microsoft Entra Identity Platform (formerly Azure Active Directory) and allows users to sign in using either a Microsoft account or an Azure AD account.

To facilitate authentication, user management, and identity verification, the following personal data may be processed:

  • Names
  • Email addresses
  • User IDs
  • IP addresses
  • Device types
  • Browser information
  • Language settings
  • Timestamps
  • Location data
  • Authentication information
  • Login logs
  • Usage logs

Microsoft also processes security-related information such as:

  • Multi-factor authentication data
  • Tokens
  • Session cookies
  • Access permissions

These data are used to protect against unauthorized access and to securely manage digital identities.

Processing occurs automatically through Microsoft’s cloud infrastructure and through configurable interfaces integrated into our applications.

Microsoft may also collect usage statistics to improve:

  • Performance
  • Security
  • Reliability

Data may be processed in data centers located both inside and outside the European Economic Area.

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

For data subjects in the EU and EEA:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

Representative in the United Kingdom:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

Purpose and Legal Basis

The processing serves:

  • User authentication
  • Access control to protected systems
  • User rights management
  • Security of IT infrastructure

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Secure and reliable identity management
  • Prevention of unauthorized access
  • Compliance with internal security standards
  • Integration with existing Microsoft services and platforms

International Data Transfers

Microsoft is located in the United States.

Transfers may take place based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Microsoft may be certified under one or more Data Privacy Frameworks.

Information is available at:

https://www.dataprivacyframework.gov/list

A copy of the relevant safeguards can be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Microsoft
  • Legal retention requirements
  • Contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Microsoft’s services may not be available.

Further information and Microsoft’s privacy policy can be found at:

https://privacy.microsoft.com

27. Privacy Policy Regarding the Use of Microsoft Power Automate

We use Microsoft Power Automate to simplify and accelerate business processes and recurring tasks through automated workflows, for example:

  • Sending emails
  • Updating databases
  • Integrating multiple systems without manual intervention

The service enables data to be transferred and processed automatically between various applications and services.

As part of its use, personal data may be processed, particularly data involved in triggered automation workflows, including:

  • Names
  • Email addresses
  • Telephone numbers
  • Contract information
  • Document content
  • Status information
  • Log data
  • Device data
  • IP addresses
  • Timestamps
  • System logs
  • Usage logs

Processing occurs automatically through Microsoft’s cloud infrastructure as part of the Power Platform environment.

Triggers within Power Automate detect predefined events in connected applications (e.g., SharePoint, Outlook, Dynamics 365) and initiate configured actions. Data are processed temporarily and forwarded to the defined destination systems.

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

For data subjects in the EU and EEA:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

Representative in the United Kingdom:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

International Data Transfers

Microsoft is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Microsoft is certified under:

  • EU–U.S. Data Privacy Framework
  • UK Extension to the EU–U.S. Data Privacy Framework
  • Swiss–U.S. Data Privacy Framework

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards can be requested from us.

Purpose and Legal Basis

The processing serves the purposes of:

  • Automating business processes and workflows
  • Integrating applications
  • Simplifying business operations
  • Reducing errors
  • Increasing productivity

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract or pre-contractual measures)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Increased efficiency
  • Reduction of manual routine tasks
  • Consistent process execution
  • Improved operational productivity

Retention Criteria

Retention periods depend on:

  • The contractual relationship between us and Microsoft
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if personal data are not provided, our services or Microsoft’s services may not be fully available.

Further information and Microsoft’s privacy policy can be found at:

https://www.microsoft.com

28. Privacy Policy Regarding the Use of Nextcloud

We use Nextcloud as a cloud solution for the storage, synchronization, and sharing of files, calendars, contacts, and other information within our organization.

Nextcloud enables us to operate a self-hosted cloud infrastructure in which all data are stored on servers controlled either by us or by commissioned hosting providers.

As part of the use of Nextcloud, personal data may be processed, particularly in connection with:

  • Creating and managing user accounts
  • Sharing files
  • Calendar management
  • Contact management
  • Integrated functions such as comments, tasks, and video conferencing

The following personal data may be processed:

  • Names
  • Usernames
  • Email addresses
  • Profile pictures
  • IP addresses
  • Timestamps
  • Uploaded or synchronized files
  • Calendar events
  • Contacts
  • Communication content

In addition, Nextcloud processes technical information regarding:

  • End-user devices
  • Web browsers
  • Operating systems
  • Service usage patterns

Processing is carried out to:

  • Manage user access
  • Secure transmitted content
  • Maintain file versioning
  • Enable real-time collaboration on shared content

Depending on the configuration of the Nextcloud instance, logs relating to user activities, file modifications, and system errors may also be stored.

Processing takes place entirely within our controlled environment or that of a contracted hosting partner.

Service Provider

Nextcloud GmbH
Albrechtstraße 14b
10117 Berlin
Germany

Purpose and Legal Basis

The purposes of processing are:

  • Secure storage of files and information
  • Synchronization of content
  • Sharing of information and documents
  • Team collaboration
  • Centralized management of digital work resources

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Secure and efficient collaboration
  • Control over our own data infrastructure
  • Control over stored and processed content

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Nextcloud
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, without providing such data, our services or the services provided through Nextcloud may not be fully available.

Further information and Nextcloud’s privacy policy are available at:


29. Privacy Policy Regarding the Use of SugarCRM

SugarCRM is a customer relationship management (CRM) platform that helps organizations manage and optimize customer relationships.

The platform enables the automation and integration of:

  • Sales processes
  • Marketing processes
  • Customer service processes

This supports a better understanding of customer needs and improves customer satisfaction.

When using SugarCRM, the following personal data may be processed:

  • Names
  • Email addresses
  • Telephone numbers
  • Professional information
  • Interaction data (e.g., communication histories and purchase histories)

These data are required for:

  • Delivery of CRM services
  • User account management
  • Personalized user experiences
  • Customer support

Service Provider

SugarCRM, Inc.
548 Market Street, PMB 59423
San Francisco, CA 94104-5401
USA

EU/EEA Representative:

SugarCRM S.R.L.
Strada Ștefan cel Mare Nr. 12, Office No. 7
Dolj County
Romania

United Kingdom Representative:

SugarCRM UK Limited
Fourth Floor, St James House
St James’ Square
Cheltenham GL50 3PR
United Kingdom

Purpose and Legal Basis

The purpose of processing is the use, provision, and optimization of the CRM software.

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Use of an efficient CRM platform
  • Improvement of our services
  • Effective customer support

International Data Transfers

SugarCRM is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

SugarCRM may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and SugarCRM
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for contract formation

You are not obliged to provide personal data.

However, if such data are not provided, our services or SugarCRM’s services may not be fully available.

Further information and SugarCRM’s privacy policy are available at:


30. Privacy Policy Regarding the Use of Facebook Messenger

Facebook Messenger is an instant messaging service that enables users to:

  • Send and receive messages
  • Share photos and videos
  • Exchange voice messages
  • Conduct voice and video calls

Messenger is available both as a standalone application and as part of Facebook. It additionally offers:

  • Group chats
  • Stickers and GIFs
  • Integration with third-party services and applications

When using Facebook Messenger, personal data may be processed, including:

  • Names
  • Contact details
  • Message content
  • Call and video chat data
  • Location information (where shared)
  • Usage data

These data are processed to:

  • Provide communication services
  • Ensure user security
  • Prevent misuse
  • Develop new features

Service Provider

Meta Platforms, Inc.
1 Meta Way
Menlo Park, CA 94025
USA

EU/EEA Representative:

Meta Platforms Ireland Ltd.
Merrion Road
Dublin D04 X2K5
Ireland

United Kingdom Representative:

Meta Platforms Technologies UK Ltd
10 Brock Street
Regent’s Place
London NW1 3FG
United Kingdom

Purpose and Legal Basis

The purpose of processing is the use and improvement of the instant messaging service.

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Providing a secure communication service
  • Efficient communications
  • User-friendly messaging functions

International Data Transfers

Meta is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Meta may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Meta
  • Applicable legal retention periods
  • Applicable contractual retention periods

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Messenger services may not be available.

Further information and Facebook Messenger’s privacy policy are available at:

https://www.facebook.com

31. Privacy Policy Regarding the Use of Microsoft Teams

Microsoft Teams is a communication and collaboration platform within the Microsoft 365 suite that is specifically designed for business use.

The platform enables teams to collaborate effectively regardless of location through features such as:

  • Chat
  • Video calls
  • Meetings
  • File sharing
  • Integration with Microsoft services and applications

Microsoft Teams supports teamwork through digital workspaces that facilitate seamless communication and collaboration whether participants are located in the same office or across multiple locations worldwide.

When using Microsoft Teams, personal data may be processed, including:

  • Names
  • Email addresses
  • Telephone numbers
  • Usage data (e.g., meeting times and durations, chat logs)
  • Content data (e.g., files, notes, messages)
  • Location information

These data are required for:

  • Provision of the services
  • Improving the user experience
  • Customer support
  • Security and compliance management

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

EU/EEA Representative:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

United Kingdom Representative:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

Purpose and Legal Basis

The purpose of processing is the use, provision, management, and improvement of Microsoft Teams for communication and collaboration.

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Improving our services
  • Providing modern communication tools
  • Enhancing collaboration and productivity

International Data Transfers

Microsoft is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Microsoft may be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Microsoft
  • Applicable legal retention requirements
  • Applicable contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if personal data are not provided, our services or Microsoft’s services may not be fully available.

Further information and Microsoft’s privacy policy are available at:

https://privacy.microsoft.com

32. Privacy Policy Regarding the Use of WhatsApp

WhatsApp LLC provides a widely used instant messaging service that allows users to send and receive:

  • Text messages
  • Voice messages
  • Images
  • Videos
  • Documents

In addition, users can make:

  • Voice calls
  • Video calls

WhatsApp features end-to-end encryption, which helps ensure the security and privacy of communications between users.

When using WhatsApp, personal data may be processed, including:

  • Telephone numbers
  • Profile names
  • Profile pictures
  • Online status information
  • Location data

In addition, information regarding interactions between users, such as messages and call data, is transmitted in encrypted form and may be used by WhatsApp to improve the service and maintain security.

Service Provider

WhatsApp Ireland Limited
Merrion Road
Dublin 4, D04 X2K5
Ireland

United Kingdom Representative:

WhatsApp Ltd.
57 Garth Road
London NW2 2NH
United Kingdom

Purpose and Legal Basis

The purpose of processing is the use of the messaging service and its associated features.

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Use of an efficient communication platform
  • Improvement of our services
  • Protection of users and their data

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and WhatsApp
  • Applicable legal retention requirements
  • Applicable contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if the data are not provided, our services or WhatsApp services may not be fully available.

Further information and WhatsApp’s privacy policy are available at:

https://www.whatsapp.com

33. Privacy Policy Regarding the Use of Zoom

Zoom is a provider of video conferencing software that enables organizations and individuals to host and participate in:

  • Virtual meetings
  • Webinars
  • Live chats
  • Collaborative workspaces

With features such as video conferencing, audio conferencing, screen sharing, and encryption, Zoom has become an important tool for remote work, remote learning, and virtual collaboration.

When using Zoom services, personal data may be processed, including:

  • Names
  • Email addresses
  • Telephone numbers
  • Profile pictures
  • Device information

During meetings, additional content data may also be processed, such as:

  • Video streams
  • Audio streams
  • Chat logs
  • Shared content

These data are necessary to:

  • Provide communication services
  • Administer user accounts
  • Operate the platform securely and efficiently
  • Deliver personalized experiences

Service Provider

Zoom Video Communications, Inc.
55 Almaden Boulevard, 6th Floor
San Jose, CA 95113
USA

EU/EEA Representative:

Lionheart Squared (Europe) Limited
2 Pembroke House
Upper Pembroke Street 28–32
Dublin D02 EK84
Ireland

United Kingdom Representative:

Lionheart Squared Limited
17 Glasshouse Studios
Fryern Court Road
Fordingbridge, Hampshire SP6 1QX
United Kingdom

Purpose and Legal Basis

The purpose of processing is the use of video communication services.

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Use of an efficient communication platform
  • Improvement of our services
  • Ensuring IT security

International Data Transfers

Zoom is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses (SCCs)
  • Other appropriate safeguards under Article 46(2) GDPR

Zoom may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Zoom
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Zoom services may not be fully available.

Further information and Zoom’s privacy policy are available at:

https://zoom.us

34. Privacy Policy Regarding the Use of Microsoft Azure

Microsoft Azure is a cloud computing platform that enables organizations to host and manage applications and services through Microsoft’s global network of data centers.

Azure offers a wide range of cloud services, including:

  • Infrastructure as a Service (IaaS)
  • Platform as a Service (PaaS)
  • Software as a Service (SaaS)

These services include computing power, storage solutions, databases, networking services, analytics tools, and much more.

When using Microsoft Azure, personal data may be processed, including:

  • Names
  • Email addresses
  • Telephone numbers
  • Service usage data
  • Configuration data
  • Content data contained within hosted applications and services

These data are necessary to:

  • Provide cloud services
  • Deliver customer support
  • Ensure service security
  • Improve products and services

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

EU/EEA Representative:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

United Kingdom Representative:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

Purpose and Legal Basis

The purpose of processing is the use and management of cloud computing services.

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Improvement of our services
  • Ensuring security
  • Provision of our IT infrastructure

International Data Transfers

Microsoft is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Microsoft may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Microsoft
  • Applicable legal retention requirements
  • Applicable contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for contract formation

You are not obliged to provide personal data.

However, if personal data are not provided, our services or Microsoft’s services may not be fully available.

Further information and Microsoft’s privacy policy are available at:

https://privacy.microsoft.com

35. Privacy Policy Regarding the Use of Microsoft SharePoint

We use Microsoft SharePoint to efficiently organize:

  • Internal collaboration
  • Cross-departmental collaboration
  • Document management
  • Team sites
  • Intranet functions
  • Information sharing

The platform enables us to store, edit, and share documents, calendars, task lists, and other content in a structured manner.

As part of our use of SharePoint, personal data may be processed, particularly data contained in:

  • Documents
  • User profiles
  • Sharing permissions
  • Comments

The following categories of personal data may be processed:

  • Names
  • Email addresses
  • User profile information
  • Document contents
  • Metadata (e.g., uploads, versions, sharing information)
  • IP addresses
  • Timestamps
  • Device data
  • User actions
  • Participant-related communication data

The processing is carried out automatically through the Microsoft 365 cloud infrastructure.

SharePoint centrally stores and manages data within online libraries and supports real-time collaboration and workflow automation. Access is controlled through role-based permissions, and all data transmissions are encrypted.

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

EU/EEA Representative:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

United Kingdom Representative:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

International Data Transfers

Microsoft is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Microsoft is certified under:

  • EU–U.S. Data Privacy Framework
  • UK Extension to the EU–U.S. Data Privacy Framework
  • Swiss–U.S. Data Privacy Framework

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Purpose and Legal Basis

The purposes of processing are:

  • Providing a secure collaboration environment
  • Managing document and content workflows
  • Sharing organizational knowledge
  • Supporting teamwork and communication

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract or pre-contractual measures)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Efficient organization of internal processes
  • High-quality collaboration
  • Protection of sensitive information through technical and organizational measures

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Microsoft
  • Applicable legal retention requirements
  • Applicable contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if personal data are not provided, our services or Microsoft’s services may not be fully available.

Further information and Microsoft’s privacy policy are available at:

https://www.microsoft.com

36. Privacy Policy Regarding the Use of netcup

netcup GmbH is a German provider of web hosting, servers, domains, and other internet services. The company is known for high-quality products, comprehensive service offerings, and a strong focus on IT security.

When using netcup services, personal data may be processed, including:

  • Names
  • Email addresses
  • Physical addresses
  • Telephone numbers
  • Payment information
  • Technical data such as IP addresses and log files

These data are necessary to:

  • Provide the requested services
  • Manage customer accounts
  • Process support requests
  • Ensure system security

Service Provider

netcup GmbH
Daimlerstraße 25
76185 Karlsruhe
Germany

Purpose and Legal Basis

The purpose of the processing is the use and administration of hosting and internet services.

The processing is based on:

  • Article 6(1)(b) GDPR (performance of a contract)
  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Improvement of our services
  • Ensuring network and information security
  • Use of external hosting providers

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and netcup
  • Applicable legal retention periods
  • Applicable contractual retention periods

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or netcup’s services may not be fully available.

Further information and netcup’s privacy policy are available at:

https://www.netcup.de

37. Privacy Policy Regarding the Use of Cloudflare

Cloudflare provides a broad range of services designed to improve the security, performance, and reliability of websites and web applications.

Core services include:

  • DDoS protection
  • Web Application Firewall (WAF)
  • Content Delivery Network (CDN) services
  • Secure DNS services
  • Traffic optimization services

By using Cloudflare, we can protect our online presence against cyberattacks, improve website loading speeds, and increase service availability.

When Cloudflare services are used, the following data may be processed:

  • IP addresses
  • System configuration information
  • Network traffic data

These data are necessary for:

  • Defending against threats
  • Optimizing data traffic
  • Providing insights into website usage

Service Provider

Cloudflare, Inc.
101 Townsend Street
San Francisco, CA 94107
USA

EU/EEA Representative:

Cloudflare Netherlands B.V.
Keizersgracht 62
1015 CS Amsterdam
The Netherlands

United Kingdom Representative:

Cloudflare Ltd.
County Hall / The Riverside Building
Belvedere Road
London SE1 7PB
United Kingdom

Purpose and Legal Basis

The purpose of processing is the use of services that secure and optimize websites and web applications.

The processing is based on:

  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Security of our online services
  • Website performance
  • Reliability and availability of our online presence

International Data Transfers

Cloudflare is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses (SCCs)
  • Other safeguards under Article 46(2) GDPR

Cloudflare may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Cloudflare
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Cloudflare’s services may not be fully available.

Further information and Cloudflare’s privacy policy are available at:

https://www.cloudflare.com

38. Privacy Policy Regarding the Use of Bing Maps

Bing Maps, provided by Microsoft, is an important mapping service that enables us to visually display geographic information and provide location-based services to users.

By integrating Bing Maps into our websites or applications, we can provide:

  • Detailed maps
  • Directions and route planning
  • Location-based information

Bing Maps collects data such as:

  • IP addresses
  • Searches for locations and routes
  • Location information

These data are used to optimize the service and provide relevant content.

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

EU/EEA Representative:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

United Kingdom Representative:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

Purpose and Legal Basis

The purpose of processing is the use of mapping services and location-based information in order to improve the user experience on our websites and applications.

The processing is based on:

  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Improvement of our services
  • Provision of useful location-based information
  • Enhanced user experience

International Data Transfers

Microsoft is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Microsoft may be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Microsoft
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Bing Maps services may not be fully available.

Further information and Microsoft’s privacy policy can be found at:

https://privacy.microsoft.com

39. Privacy Policy Regarding the Use of Font Awesome

Font Awesome provides a large collection of scalable vector icons and social media logos that web developers and designers can use to make user interfaces more intuitive and visually appealing.

As one of the most widely used icon toolkits, Font Awesome can be integrated through:

  • CSS
  • JavaScript
  • Web fonts

Both free and commercial (“Pro”) versions are available.

When using Font Awesome, personal data such as the following may be processed:

  • IP addresses
  • Usage data

This occurs particularly when users visit the website or subscribe to a Pro account.

These data are necessary to:

  • Provide the services
  • Analyze website usage
  • Handle support inquiries
  • Ensure platform security

Service Provider

Fonticons, Inc.
307 S Main St Ste 202
Bentonville, AR 72712-9214
USA

Purpose and Legal Basis

The purpose of processing is the use of the icon toolkit and related services.

The processing is based on:

  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Improving user experience
  • Efficient provision of an attractive website design

International Data Transfers

Fonticons is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Fonticons may be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Fonticons
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Font Awesome services may not be fully available.

Further information and Font Awesome’s privacy policy are available at:

https://fontawesome.com

40. Privacy Policy Regarding the Use of Google Fonts

Google Fonts is a free service provided by Google LLC that offers web developers a wide variety of fonts to enhance the design and appearance of websites.

By integrating Google Fonts, website operators can ensure that text is displayed consistently across different devices and browsers.

Google Fonts are delivered via Google’s servers, providing high availability and fast loading times.

When Google Fonts are used, personal data may be processed, including:

  • IP addresses
  • Browser information

This occurs because requests are made to Google servers when fonts are loaded.

These data are used to:

  • Deliver the font service
  • Optimize performance
  • Prevent misuse

Service Provider

Google LLC
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA

EU/EEA Representative:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

United Kingdom Representative:

Google UK Limited
Belgrave House
76 Buckingham Palace Road
London SW1W 9TQ
United Kingdom

Swiss Representative:

Google Switzerland GmbH
Brandschenkestrasse 110
8002 Zurich
Switzerland

Purpose and Legal Basis

The purpose of processing is the use and optimization of web font services.

The processing is based on:

  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Improved website usability
  • Availability of a wide range of fonts
  • Faster page loading performance

International Data Transfers

Google is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Google may be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Google
  • Applicable legal retention requirements
  • Applicable contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Google Fonts services may not be fully available.

Further information and Google’s privacy policy are available at:

https://policies.google.com/privacy

41. Privacy Policy Regarding the Use of Google Maps

Google Maps is a comprehensive mapping and navigation service provided by Google LLC. It enables users to view maps, plan routes, and locate businesses and services. Through the provision of detailed geographic information, Google Maps supports orientation and navigation in everyday life. Features include:

  • Satellite imagery
  • Street View
  • Real-time traffic information
  • Location ratings and reviews

When using Google Maps, personal data may be processed, including:

  • Location data
  • Search queries
  • Usage statistics

These data are necessary for providing the service, offering personalized recommendations, and improving the user experience.

Service Provider

Google LLC
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA

EU/EEA Representative:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

United Kingdom Representative:

Google UK Limited
Belgrave House
76 Buckingham Palace Road
London SW1W 9TQ
United Kingdom

Swiss Representative:

Google Switzerland GmbH
Brandschenkestrasse 110
8002 Zurich
Switzerland

Purpose and Legal Basis

The purpose of processing is the use and optimization of mapping and navigation services.

The processing is based on:

  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Providing an efficient and user-friendly navigation service
  • Improving user experience
  • Delivering accurate location-based information

International Data Transfers

Google is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses (SCCs)
  • Other safeguards under Article 46(2) GDPR

Google may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Google
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Google Maps services may not be fully available.

Further information and Google’s privacy policy are available at:

https://policies.google.com/privacy

42. Privacy Policy Regarding the Use of jQuery

jQuery is a widely used JavaScript library employed by web developers to simplify and accelerate:

  • HTML document manipulation
  • Event handling
  • Animations
  • AJAX interactions

The use of jQuery on our website helps create a smoother and more interactive user experience.

When visiting our website, jQuery may be used to collect certain information, such as user behavior and interactions on the site.

This processing is indirect and primarily serves to improve website performance and usability.

As a client-side library, jQuery itself does not store or process personal data on its own servers. Instead, it runs within the user’s browser and may facilitate dynamic content updates that involve transmitting data to external servers.

Service Provider

jQuery Foundation
c/o OpenJS Foundation
1 Letterman Drive, Suite D4700
San Francisco, CA 94129
USA

Purpose and Legal Basis

The purpose of using jQuery is to improve user interaction and the overall website experience.

The processing is based on:

  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Providing a functional website
  • Enhancing usability
  • Delivering a visually appealing online experience

International Data Transfers

The service provider is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

The provider may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and the provider
  • Applicable legal retention obligations
  • Applicable contractual retention obligations

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not required to provide personal data.

However, if such data are not provided, our services or the functionality enabled by jQuery may not be fully available.

The jQuery privacy policy is available at:


43. Privacy Policy Regarding the Use of Avast

Avast provides comprehensive security solutions designed to protect devices and networks against viruses, malware, and other threats.

The service includes:

  • Antivirus software
  • Firewalls
  • Security tools for devices and networks

When using Avast, personal data may be processed, including:

  • IP addresses
  • Device information
  • Usage data

These data are necessary to:

  • Deliver security services
  • Detect threats
  • Notify users of potential security incidents

Service Provider

Avast Software s.r.o.
Pikrtova 1737/1a
140 00 Prague 4
Czech Republic

United Kingdom Representative:

NortonLifeLock UK Limited
100 New Bridge Street
London EC4V 6JA
United Kingdom

Purpose and Legal Basis

The purpose of processing is protection against:

  • Viruses
  • Malware
  • Other online threats

The processing is based on:

  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Ensuring security
  • Protecting devices and networks
  • Maintaining operational integrity

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Avast
  • Applicable legal retention requirements
  • Applicable contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Avast services may not be fully available.

Further information and Avast’s privacy policy are available at:

https://www.avast.com

44. Privacy Policy Regarding the Use of Microsoft Defender XDR

We use Microsoft Defender XDR for the centralized detection, analysis, response to, and prevention of threats within our IT environment.

The service collects, correlates, and analyzes security-related information from multiple sources, including:

  • Endpoints
  • Email systems
  • User identities
  • Cloud applications
  • IT infrastructure

Its purpose is to identify threats at an early stage, automate responses, and continuously improve our overall security posture.

As part of this process, personal data may be processed whenever they are contained within security-related events or communication content.

The data processed may include:

  • Usernames
  • Email addresses
  • IP addresses
  • Device identifiers
  • Timestamps
  • Login information
  • File information
  • Process data
  • Network connections
  • Location data
  • Security incident logs
  • Additional metadata

Processing Activities

Processing is performed automatically through Microsoft’s cloud-based security platform.

Microsoft Defender XDR uses:

  • Machine learning
  • Threat intelligence technologies

to identify threats and prioritize risks.

The platform also provides centralized tools for:

  • Security analysis
  • Incident response
  • Vulnerability management

Security administrators can:

  • Review security alerts
  • Initiate remediation measures
  • Generate audit and compliance reports

The service is tightly integrated into Microsoft’s security ecosystem and can be connected with products such as:

  • Microsoft Defender for Endpoint
  • Microsoft Sentinel

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

EU/EEA Representative:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

United Kingdom Representative:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

Purpose and Legal Basis

The purpose of processing is:

  • Detection of threats
  • Security analysis
  • Threat mitigation
  • Protection of IT infrastructure

The processing is based on:

  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Strengthening IT security
  • Preventing data loss
  • Protecting sensitive information
  • Meeting legal and organizational security requirements

International Data Transfers

Microsoft is located in the United States.

Transfers may be based on:

  • Standard Contractual Clauses
  • Other safeguards under Article 46(2) GDPR

Microsoft may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the applicable safeguards may be requested from us.

Retention Criteria

Retention periods are determined by:

  • The contractual relationship between us and Microsoft
  • Applicable legal retention requirements
  • Applicable contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data.

However, if such data are not provided, our services or Microsoft’s services may not be fully available.

Further information and Microsoft’s privacy policy are available at:

https://privacy.microsoft.com

45. Privacy Policy Regarding the Use of Microsoft Defender for Cloud

We use Microsoft Defender for Cloud to monitor, evaluate, and secure our cloud infrastructures and cloud services.

The service assists us in:

  • Identifying security risks
  • Analyzing threat scenarios
  • Meeting security and compliance requirements in multi-cloud environments

Microsoft Defender for Cloud collects and analyzes security-related information from:

  • Virtual machines
  • Databases
  • Storage systems
  • Network components
  • Cloud platform services

Personal data may be processed where such data are part of monitored systems or logs, including:

  • Usernames
  • IP addresses
  • Device information
  • Roles and group memberships
  • Authentication information
  • Access information
  • Configuration data
  • Location data
  • Event logs
  • Usage logs

46. Privacy Policy Regarding the Use of Microsoft Defender for Endpoint

We use Microsoft Defender for Endpoint for the detection, analysis, and prevention of threats affecting endpoint devices.

The service provides comprehensive capabilities for:

  • Endpoint Detection and Response (EDR)
  • Behavioral analysis
  • Automated investigation of security-related events
  • Threat mitigation and response measures

When using Microsoft Defender for Endpoint, personal data generated by operating systems or security events on devices may be processed. This includes, among other things:

  • Usernames
  • Device models
  • Operating system versions
  • IP addresses
  • Device IDs
  • Login information
  • Activity timestamps
  • Process information
  • Network connections
  • File paths
  • Location data

These data are used to:

  • Identify security-related incidents
  • Classify threats
  • Initiate automated countermeasures
  • Document security incidents

Defender for Endpoint creates a security assessment for each device, performs behavior-based analyses, and enables administrators to manage and monitor endpoint security through a centralized dashboard.

The processing is carried out automatically through Microsoft’s cloud infrastructure and is closely integrated with Microsoft 365 and Azure security services.

Service Provider

Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399
USA

For data subjects in the EU and EEA:

Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18, D18 P521
Ireland

Representative in the United Kingdom:

Microsoft Limited
Microsoft Campus
Thames Valley Park
Reading RG6 1WG
United Kingdom

Swiss Representative:

Microsoft Schweiz GmbH
Seestrasse 356
8038 Zurich
Switzerland

Purpose and Legal Basis

The purpose of processing is:

  • Comprehensive protection of endpoint devices against malware, ransomware, phishing attacks, and other cyber threats
  • Detection of attack patterns
  • Analysis of suspicious behavior
  • Enforcement of security policies

The processing is based on:

  • Article 6(1)(f) GDPR (legitimate interests)

Legitimate interests:

  • Prevention of security incidents
  • Ensuring secure IT operations
  • Detection and containment of potential attacks
  • Compliance with internal and legal security requirements

International Data Transfers

Microsoft is located in the United States.

Transfers to third countries may be based on:

  • Standard Contractual Clauses (SCCs)
  • Other appropriate safeguards referred to in Article 46(2) GDPR

Microsoft may also be certified under one or more Data Privacy Frameworks.

Further information is available at:

https://www.dataprivacyframework.gov/list

A copy of the applicable safeguards may be requested from us.

Retention Criteria

The period for which personal data are retained is determined by:

  • The contractual relationship between us and Microsoft
  • Applicable statutory retention requirements
  • Applicable contractual retention requirements

Provision of Data

The provision of personal data is:

  • Not legally required
  • Not contractually required
  • Not necessary for entering into a contract

You are not obliged to provide personal data to us or to Microsoft.

However, if such data are not provided, our services or Microsoft’s services may not be fully available.

Further information and Microsoft’s privacy policy can be found at:

https://privacy.microsoft.com