Privacybeleid Website
Inleiding
Hieronder geven we informatie over het verzamelen van persoonsgegevens bij het gebruik van
- onze website sonoro.com
- onze profielen op sociale media.
Persoonsgegevens zijn alle gegevens die aan een specifieke natuurlijke persoon kunnen worden gekoppeld, zoals hun naam of IP-adres.
Contactgegevens
De verwerkingsverantwoordelijke in de zin van artikel 4, lid 7, van de Algemene Verordening Gegevensbescherming (AVG) van de EU is sonoro audio GmbH, Hammer LandstraĆe 45, Neuss, Duitsland, e-mail: info@sonoro.com. Wij worden juridisch vertegenwoordigd door Marcell Faller.
Onze functionaris voor gegevensbescherming is bereikbaar via heyData GmbH, SchützenstraĆe 5, 10117 Berlijn, www.heydata.eu, e-mail: datenschutz@heydata.eu.
Omvang van de gegevensverwerking, verwerkingsdoeleinden en rechtsgrondslagen
Hieronder geven we een gedetailleerd overzicht van de omvang van de gegevensverwerking, de verwerkingsdoeleinden en de rechtsgrondslagen. In principe komen de volgende rechtsgrondslagen voor gegevensverwerking in aanmerking:
- 6, lid 1, punt 1, onder a) van de AVG dient als onze rechtsgrondslag voor verwerkingen waarvoor wij toestemming verkrijgen.
- 6, lid 1, punt 1, onder b) van de AVG vormt de rechtsgrondslag voor zover de verwerking van persoonsgegevens noodzakelijk is voor de uitvoering van een overeenkomst, bijvoorbeeld wanneer een bezoeker van de website een product bij ons koopt of wij een dienst voor hem verrichten. Deze rechtsgrondslag geldt ook voor verwerkingen die noodzakelijk zijn voor precontractuele maatregelen, zoals in het geval van vragen over onze producten of diensten.
- 6, lid 1, punt 1, onder c), van de AVG is van toepassing indien wij een wettelijke verplichting nakomen door persoonsgegevens te verwerken, zoals bijvoorbeeld het geval kan zijn in het belastingrecht.
- 6, lid 1, punt 1, onder f), van de AVG dient als rechtsgrondslag wanneer wij ons kunnen beroepen op gerechtvaardigde belangen om persoonsgegevens te verwerken, bijvoorbeeld voor cookies die noodzakelijk zijn voor de technische werking van onze website.
Gegevensverwerking buiten de EER
Voor zover wij gegevens doorgeven aan dienstverleners of andere derde partijen buiten de EER, wordt de veiligheid van de gegevens tijdens de overdracht gewaarborgd door adequaatheidsbesluiten van de Europese Commissie, voor zover deze bestaan (bijvoorbeeld voor Groot-Brittanniƫ, Canada en Israƫl) (art. 45, lid 3 AVG).
In het geval van gegevensoverdracht aan dienstverleners in de VS is de rechtsgrondslag voor de gegevensoverdracht een adequaatheidsbesluit van de Europese Commissie, indien de dienstverlener zich ook heeft gecertificeerd onder het EU-VS-kader voor gegevensbescherming.
In andere gevallen (bijvoorbeeld als er geen adequaatheidsbesluit bestaat) is de rechtsgrondslag voor de gegevensoverdracht meestal, tenzij anders aangegeven, standaardcontractbepalingen. Dit is een reeks regels die door de Europese Commissie is aangenomen en deel uitmaakt van het contract met de betreffende derde partij. Volgens art. 46, lid 2, onder b), van de AVG waarborgen zij de veiligheid van de gegevensoverdracht. Veel van de aanbieders hebben contractuele garanties gegeven die verder gaan dan de standaardcontractbepalingen om de gegevens te beschermen. Deze omvatten bijvoorbeeld garanties met betrekking tot de versleuteling van gegevens of met betrekking tot een verplichting van de derde partij om betrokkenen op de hoogte te stellen als wetshandhavingsinstanties toegang willen krijgen tot de betreffende gegevens.
Opslagduur
Tenzij uitdrukkelijk vermeld in dit privacybeleid, worden de door ons opgeslagen gegevens verwijderd zodra ze niet langer nodig zijn voor het beoogde doel en er geen wettelijke verplichtingen tot het bewaren van gegevens in strijd zijn met de verwijdering. Als de gegevens niet worden verwijderd omdat ze nodig zijn voor andere en wettelijk toegestane doeleinden, wordt de verwerking ervan beperkt, d.w.z. de gegevens worden geblokkeerd en niet voor andere doeleinden verwerkt. Dit geldt bijvoorbeeld voor gegevens die om commerciƫle of fiscale redenen moeten worden bewaard.
Rechten van betrokkenen
Betrokkenen hebben ten aanzien van hun persoonsgegevens de volgende rechten jegens ons:
- Recht op toegang,
- Recht op correctie of verwijdering,
- Recht om de verwerking te beperken,
- Recht om bezwaar te maken tegen de verwerking ,
- Recht op gegevensoverdraagbaarheid,
- Recht om een gegeven toestemming op elk moment in te trekken .
Betrokkenen hebben ook het recht om bij een toezichthoudende autoriteit voor gegevensbescherming een klacht in te dienen over de verwerking van hun persoonsgegevens. De contactgegevens van de toezichthoudende autoriteiten voor gegevensbescherming zijn te vinden op https://www.bfdi.bund.de/EN/Service/Anschriften/Laender/Laender-node.html.
Verplichting tot het verstrekken van gegevens
In het kader van de zakelijke of andere relatie moeten klanten, potentiƫle klanten of derden ons persoonsgegevens verstrekken die nodig zijn voor het aangaan, uitvoeren en beƫindigen van een zakelijke of andere relatie of die wij wettelijk verplicht zijn te verzamelen. Zonder deze gegevens zullen wij in het algemeen moeten weigeren het contract te sluiten of een dienst te verlenen, of zullen wij een bestaand contract of andere relatie niet langer kunnen uitvoeren.
Verplichte gegevens zijn als zodanig gemarkeerd.
Geen automatische besluitvorming in individuele gevallen
In principe maken wij geen gebruik van een volledig geautomatiseerd besluitvormingsproces in overeenstemming met artikel 22 AVG om de zakelijke of andere relatie tot stand te brengen en uit te voeren. Indien wij in individuele gevallen toch gebruik maken van deze procedures, zullen wij u hiervan afzonderlijk op de hoogte stellen indien dit wettelijk vereist is.
Contact leggen
Wanneer u contact met ons opneemt, bijvoorbeeld via e-mail of telefoon, worden de aan ons verstrekte gegevens (bijvoorbeeld namen en e-mailadressen) door ons opgeslagen om vragen te kunnen beantwoorden. De rechtsgrondslag voor de verwerking is ons gerechtvaardigd belang (art. 6, lid 1, zin 1, punt f AVG) om vragen die aan ons worden gericht te beantwoorden. Wij verwijderen de in dit verband verzamelde gegevens zodra de opslag niet langer nodig is, of beperken de verwerking indien er wettelijke bewaarplichten gelden.
Competities
Af en toe organiseren we wedstrijden via onze website of op andere manieren. We verwerken de gegevens die in deze wedstrijden worden gevraagd om de winnaars te bepalen en op de hoogte te stellen. Daarna verwijderen we de gegevens. Het kan ook zijn dat we alleen wedstrijden organiseren voor bestaande klanten. In dat geval verwerken we alleen de naam om de winnaars te bepalen en de contactgegevens om de winnaars op de hoogte te stellen. Het is ons gerechtvaardigd belang om wedstrijden aan te bieden om klanten aan te trekken of om met onze bestaande klanten te communiceren. De rechtsgrondslag voor de gegevensverwerking is art. 6, lid 1, zin 1, punt f AVG.
KlantenenquĆŖtes
Van tijd tot tijd houden we klantenenquêtes om onze klanten en hun wensen beter te leren kennen. Daarbij verzamelen we de gegevens die in elk geval worden gevraagd. Het is ons gerechtvaardigd belang om onze klanten en hun wensen beter te leren kennen, zodat de rechtsgrondslag voor de bijbehorende gegevensverwerking art. 6, lid 1, zin 1, punt f AVG is. We verwijderen de gegevens wanneer de resultaten van de enquêtes zijn geëvalueerd.
Nieuwsbrief
Wij behouden ons het recht voor om klanten die al gebruik hebben gemaakt van onze diensten of goederen hebben gekocht, van tijd tot tijd per e-mail of op andere wijze te informeren over onze aanbiedingen, indien zij hiertegen geen bezwaar hebben gemaakt. De rechtsgrondslag voor deze gegevensverwerking is art. 6, lid 1, zin 1, punt f AVG. Ons gerechtvaardigd belang is het voeren van directe reclame (overweging 47 AVG). Klanten kunnen te allen tijde zonder extra kosten bezwaar maken tegen het gebruik van hun e-mailadres voor reclamedoeleinden, bijvoorbeeld via de link aan het einde van elke e-mail of door een e-mail te sturen naar ons bovengenoemde e-mailadres.
GeĆÆnteresseerden hebben de mogelijkheid om zich te abonneren op een gratis nieuwsbrief. Wij verwerken de bij de registratie verstrekte gegevens uitsluitend voor het verzenden van de nieuwsbrief. Het abonnement wordt afgesloten door het betreffende veld op onze website aan te vinken, door het betreffende veld in een papieren document aan te vinken of door een andere duidelijke handeling, waarbij geĆÆnteresseerden hun toestemming geven voor de verwerking van hun gegevens, zodat de rechtsgrondslag art. 6, lid 1, punt a AVG is. De toestemming kan te allen tijde worden ingetrokken, bijvoorbeeld door op de betreffende link in de nieuwsbrief te klikken of door een bericht te sturen naar ons hierboven vermelde e-mailadres. De verwerking van de gegevens tot het moment van intrekking blijft ook in geval van intrekking rechtmatig.
Op basis van de toestemming van de ontvangers (art. 6, lid 1, zin 1, onder a) AVG) meten we ook het openings- en doorklikpercentage van onze nieuwsbrieven om te begrijpen wat relevant is voor ons publiek.
- We versturen nieuwsbrieven met de tool Omnisend van de aanbieder UAB Omnisend, Verkių g. 25C-1, LT-08223 Vilnius, Litouwen . De aanbieder verwerkt daarbij inhoud, gebruiks-, meta-/communicatiegegevens en contactgegevens in de EU. Meer informatie vindt u in het privacybeleid van de aanbieder op https://www.omnisend.com/privacy/ .
Gegevensverwerking op onze website
Kennisgeving voor bezoekers van de website uit Duitsland
Onze website slaat informatie op in de eindapparatuur van websitebezoekers (bijv. cookies) of heeft toegang tot informatie die al in de eindapparatuur is opgeslagen (bijv. IP-adressen). Welke informatie dit precies is, vindt u in de volgende paragrafen.
Deze opslag en toegang is gebaseerd op de volgende bepalingen:
- Voor zover deze opslag of toegang absoluut noodzakelijk is voor ons om de door websitebezoekers uitdrukkelijk gevraagde dienst van onze website te leveren (bijvoorbeeld om een door de websitebezoeker gebruikte chatbot uit te voeren of om de IT-beveiliging van onze website te waarborgen), wordt dit uitgevoerd op basis van artikel 25, lid 2 nr. 2 van de Duitse wet op de gegevensbescherming voor digitale telecommunicatiediensten (Telekommunikation-Digitale-Dienste-Datenschutzgesetz, "TDDDG").
- Anders vindt deze opslag of toegang plaats op basis van de toestemming van de bezoeker van de website (artikel 25, lid 1 TDDDG).
De daaropvolgende gegevensverwerking wordt uitgevoerd in overeenstemming met de volgende paragrafen en op basis van de bepalingen van de AVG.
Informatief gebruik van onze website
Tijdens het informatieve gebruik van de website, d.w.z. wanneer bezoekers van de website geen informatie afzonderlijk aan ons doorgeven, verzamelen wij de persoonsgegevens die de browser aan onze server doorgeeft om de stabiliteit en veiligheid van onze website te waarborgen. Dit is ons gerechtvaardigd belang, zodat de rechtsgrondslag artikel 6, lid 1, zin 1, punt f) van de AVG is.
Deze gegevens zijn:
- IP-adres
- Datum en tijdstip van het verzoek
- Tijdzoneverschil ten opzichte van Greenwich Mean Time (GMT)
- Inhoud van het verzoek (specifieke pagina)
- Toegangsstatus/HTTP-statuscode
- Hoeveelheid gegevens die in elk geval wordt overgedragen
- Website waar het verzoek vandaan komt
- Browser
- Besturingssysteem en de interface ervan
- Taal en versie van de browsersoftware.
Deze gegevens worden ook opgeslagen in logbestanden. Ze worden verwijderd wanneer hun opslag niet langer nodig is, uiterlijk na 14 dagen.
Webhosting en levering van de website
Onze website wordt gehost door DigitalOcean. De provider is Digitalocean LLC, 101 Avenue of the Americas 10th Floor, New York, NY 10013, VS. Daarbij verwerkt de provider de via de website verzonden persoonsgegevens, zoals inhoud, gebruiks-, meta-/communicatiegegevens of contactgegevens, in de EU. Meer informatie vindt u in het privacybeleid van de provider op https://www.digitalocean.com/legal/privacy-policy.
Het is ons gerechtvaardigd belang om een website aan te bieden, dus de rechtsgrondslag voor de beschreven gegevensverwerking is art. 6, lid 1, zin 1, punt f AVG.
Contactformulier
Wanneer u contact met ons opneemt via het contactformulier op onze website, slaan wij de daar gevraagde gegevens en de inhoud van het bericht op. De rechtsgrondslag voor de verwerking is ons gerechtvaardigd belang bij het beantwoorden van aan ons gerichte vragen. De rechtsgrondslag voor de verwerking is daarom art. 6, lid 1, zin 1, punt f AVG. Wij verwijderen de in dit verband verzamelde gegevens zodra de opslag niet langer nodig is, of beperken de verwerking indien er wettelijke bewaarplichten gelden.
Vacatures
We publiceren vacatures op onze website, op pagina's die aan de website zijn gekoppeld of op websites van derden.
De verwerking van de gegevens die in het kader van de sollicitatie worden verstrekt, vindt plaats met het oog op de uitvoering van de sollicitatieprocedure. Voor zover dit noodzakelijk is voor onze beslissing om een arbeidsrelatie aan te gaan, is de rechtsgrondslag artikel 88, lid 1, AVG in combinatie met artikel 26, lid 1, van de Duitse wet op de gegevensbescherming (Bundesdatenschutzgesetz). We hebben de gegevens die nodig zijn voor de uitvoering van de sollicitatieprocedure dienovereenkomstig gemarkeerd of verwijzen ernaar. Als sollicitanten deze gegevens niet verstrekken, kunnen we de sollicitatie niet in behandeling nemen. Verdere gegevens zijn vrijwillig en niet vereist voor een sollicitatie. Als sollicitanten verdere informatie verstrekken, is de basis hiervoor hun toestemming (art. 6, lid 1, zin 1, letter a AVG).
We vragen sollicitanten om geen informatie over politieke opvattingen, religieuze overtuigingen en soortgelijke gevoelige gegevens in hun cv en sollicitatiebrief te vermelden. Deze gegevens zijn niet vereist voor een sollicitatie. Als sollicitanten toch dergelijke informatie verstrekken, kunnen we niet voorkomen dat deze wordt verwerkt als onderdeel van de verwerking van het cv of de sollicitatiebrief. De verwerking ervan is dan ook gebaseerd op de toestemming van de sollicitanten (art. 9, lid 2, onder a) AVG).
Ten slotte verwerken wij de gegevens van sollicitanten voor verdere sollicitatieprocedures als zij ons daarvoor toestemming hebben gegeven. In dit geval is de rechtsgrondslag art. 6, lid 1, zin 1, onder a) AVG.
Wij geven de gegevens van sollicitanten door aan de verantwoordelijke medewerkers van de HR-afdeling, aan onze gegevensverwerkers op het gebied van werving en selectie en aan de medewerkers die anderszins bij het sollicitatieproces betrokken zijn.
Als we na de sollicitatieprocedure een arbeidsrelatie met de sollicitant aangaan, verwijderen we de gegevens pas nadat de arbeidsrelatie is beƫindigd. Anders verwijderen we de gegevens uiterlijk zes maanden na het afwijzen van een sollicitant.
Als sollicitanten ons toestemming hebben gegeven om hun gegevens ook voor verdere sollicitatieprocedures te gebruiken, zullen wij hun gegevens pas een jaar na ontvangst van de sollicitatie verwijderen.
Beoordelingen
Bezoekers van onze website kunnen beoordelingen achterlaten over onze producten, diensten of ons bedrijf in het algemeen. Voor dit doel verwerken wij naast de ingevoerde gegevens ook metadata of communicatiegegevens. Wij hebben een gerechtvaardigd belang bij het ontvangen van feedback van bezoekers van de website over ons aanbod. Daarom is de rechtsgrondslag voor de gegevensverwerking art. 6, lid 1, zin 1, punt f AVG. Voor zover wij voor de overeenkomst gebruikmaken van een tool van een derde partij, vindt u hierover informatie onder "Derde partijen".
Klantaccount
Bezoekers van de website kunnen op onze website een klantaccount aanmaken. Wij verwerken de in dit verband gevraagde gegevens op basis van de toestemming van de bezoeker van de website. Wij verwerken de in dit verband gevraagde gegevens om de voor het account gesloten gebruikersovereenkomst na te komen, zodat de rechtsgrondslag voor de verwerking artikel 6, lid 1, punt 1, onder b), van de AVG is.
Aanbod van goederen
Wij bieden goederen aan via onze website. Daarbij verwerken wij de volgende gegevens als onderdeel van het bestelproces:
E-mailadres
⢠Naam
⢠Adres
⢠Telefoonnummer
De verwerking van de gegevens vindt plaats voor de uitvoering van de overeenkomst die met de betreffende bezoeker van de website is gesloten (art. 6, lid 1, zin 1, punt b AVG).
Wij geven bovenstaande gegevens door aan de volgende dienstverleners, voor zover dit noodzakelijk is in het kader van de opdracht:
pfenning solutions GmbH, Walter-Gropius-Str. 19c, 50126, Bergheim, Duitsland
De rechtsgrondslag voor de verwerking is art. 6, lid 1, zin 1, punt b) AVG, aangezien dit noodzakelijk is voor de uitvoering van de overeenkomst.
Betalingsverwerkers
Voor de verwerking van betalingen maken wij gebruik van betalingsverwerkers die zelf gegevensverwerkers zijn in de zin van art. 4 nr. 7 AVG. Voor zover zij gegevens en betalingsgegevens ontvangen die door ons tijdens het bestelproces zijn ingevoerd, voldoen wij daarmee aan de met onze klanten gesloten overeenkomst (art. 6, lid 1, zin 1, onder b) AVG).
Deze betalingsverwerkers zijn:
- Amazon Payments Europe sca, Luxemburg
- American Express Europa SA
- Apple Inc., VS (voor Apple Pay)
- Google Ireland Limited, Ierland (voor Google Pay)
- Klarna Bank AB (publ), Zweden (voor "Klarna op rekening")
- Klarna Bank AB (publ), Zweden (voor "Klarna Sofort")
- Mollie BV, Nederland
- PayPal (Europa) S.Ć rl et Cie, SCA, Luxemburg
- Visa Europe Services Inc., Groot-Brittanniƫ
- Amazon betalen
Technically necessary cookies
Our website sets cookies. Cookies are small text files that are stored in the web browser on the end device of a site visitor. Cookies help to make the offer more user-friendly, effective and secure. Insofar as these cookies are necessary for the operation of our website or its functions (hereinafter "Technically Necessary Cookies"), the legal basis for the associated data processing is Art. 6 para. 1 s. 1 lit. f GDPR. We have a legitimate interest in providing customers and other site visitors with a functional website. Specifically, we set technically necessary cookies for the following purpose or purposes:
• Cookies, to save the shopping cart
• Cookies, to save login data
• Cookies, to remember search terms
• Cookies, to apply language settings
• Cookies, to enable payment providers to process payments and not to analyze user behavior
Third parties
Hotjar
We use Hotjar for analytics. The provider is Hotjar Ltd., Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian's, STJ 3141, Malta. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://www.hotjar.com/legal/policies/privacy/.
Criteo
We use Criteo for advertising. The provider is Criteo SA, 32 rue Blanche, 75009 Paris, France. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The data is stored for a maximum of 13 months from the date of collection. We are acting as joint controllers with the service provider to provide personalized ads. Further information is available in the provider's privacy policy at https://www.criteo.com/privacy/.
Usercentrics
We use Usercentrics to manage consents. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich. The provider processes meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR . We have a legitimate interest in managing the consent of website visitors to cookies in a simple manner.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://usercentrics.com/privacy-policy/.
Trustpilot
We use Trustpilot for customer reviews. The provider is Trustpilot A/S, Pilestræde 58, 5th floor, 1112 Copenhagen K, Denmark. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR . We have a legitimate interest in receiving feedback on our services from our customers through reviews.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://uk.legal.trustpilot.com/for-businesses/business-privacy-policy.
Weglot
We use Weglot for translations. The provider is Weglot, 138, rue Pierre Joigneaux in BOIS-COLOMBES (92270), France. The provider processes meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://weglot.com/de/privacy/.
Cookiebot
We use Cookiebot to manage consents. The provider is Usercentrics A/S, Havnegade 39, DK-1058, Copenhagen. The provider processes meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR . We have a legitimate interest in managing the consent of website visitors to cookies in a simple manner.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://www.cookiebot.com/en/privacy-policy/.
Zendesk
We use Zendesk for a live chat. The provider is Zendesk, Inc., 1019 Market St., San Francisco, CA 94103, USA. The provider processes content data (e.g. entries in online forms), contact data (e.g. e-mail addresses, telephone numbers), meta/communication data (e.g. device information, IP addresses), master data (e.g. names, addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://www.zendesk.com/company/customers-partners/privacy-policy/.
Mouseflow
We use Mouseflow for analytics. The provider is Mouseflow, ApSFlaesketorvet 68, 1711 Copenhagen V, Denmark. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses), contact data (e.g. e-mail addresses, telephone numbers) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://mouseflow.com/privacy/.
Elfsight
We use Elfsight to integrate widgets. The provider is Elfsight, LLC, 0015, Armenia, Yerevan, Paronyana str., 19/3, 201. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://elfsight.com/privacy-policy/.
WP rocket
We use WP rocket for the website performance. The provider is SAS WP MEDIA, 4 rue de la République, 69001 LYON, France. The provider processes meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR . We have a legitimate interest in reducing the loading time on our website.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://wp-rocket.me/de/impressum/.
Zendesk
We use Zendesk for quizzes and forms. The provider is Zendesk, Inc., 1019 Market St., San Francisco, CA 94103, USA. The provider processes content data (e.g. entries in online forms), meta/communication data (e.g. device information, IP addresses), contact data (e.g. e-mail addresses, telephone numbers) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR . We have a legitimate interest in creating forms in a simple way.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://www.zendesk.com/company/customers-partners/privacy-policy/#how-we-use-information-that-we-collect.
Stape
We use Stape for data analytics, for analytics. The provider is Stape Europe OÜ, Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://stape.io/privacy-notice.
Microsoft Dynamics 365
We use Microsoft Dynamics 365 for customer relationship management. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. The provider processes contract data (e.g. subject matter of the contract, term), contact data (e.g. e-mail addresses, telephone numbers), master data (e.g. names, addresses), meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR . We have a legitimate interest in managing our customer data in a simple way.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://privacy.microsoft.com/en-gb/privacystatement.
Google Analytics
We use Google Analytics for analytics. The provider is Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
Google Tag Manager
We use Google Tag Manager for advertising, for analytics. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
We delete the data when the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
Meta Pixel
We use Meta Pixel for analytics. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://www.facebook.com/policy.php.
Facebook Custom Audiences
We use Facebook Custom Audiences for advertising. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
We delete the data when the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://www.facebook.com/policy.php.
YouTube Videos
We use YouTube Videos for videos on the website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes meta/communication data (e.g. device information, IP addresses), usage data (e.g. web pages visited, interest in content, access times) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis consents.
Further information is available in the provider's privacy policy at https://policies.google.com/privacy.
Zapier
We use Zapier to automate between applications. The provider is Zapier, Inc., 548 Market St. #62411, San Francisco, CA 94104-5401, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR . We have a legitimate interest in easily connecting the applications in our company to optimize the way we work.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
We delete the data when the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://zapier.com/privacy.
Google Maps
We use Google Maps for maps on our website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Dublin, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses), location data in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
We delete the data when the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
Outbrain
We use Outbrain for advertising. The provider is Outbrain Inc., 222 Broadway 19th Floor, New York, NY 10038, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis standard contractual clauses. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed by standard data protection clauses (Art. 46 para. 2 lit. c GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93 para. 2 of the GDPR, which we have agreed to with the provider.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://www.outbrain.com/legal/privacy#privacy-policy.
Google Conversion Tag
We use Google Conversion Tag for conversion tracking. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
Facebook Conversion API
We use Facebook Conversion API for analytics. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://www.facebook.com/policy.php.
Microsoft Advertising (Bing Ads)
We use Microsoft Advertising (Bing Ads) for conversion tracking, for analytics. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://privacy.microsoft.com/en-gb/privacystatement.
VWO
We use VWO for analytics. The provider is Wingify Software Private Limited, 1104, 11th Floor, KLJ Tower North B-5, Netaji Subhash Place, Pitampura, Delhi - 110034, India. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. f GDPR . We have a legitimate interest in adequately monitoring the performance of our applications.
The transfer of personal data to a country outside the EEA takes place on the legal basis standard contractual clauses. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed by standard data protection clauses (Art. 46 para. 2 lit. c GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93 para. 2 of the GDPR, which we have agreed to with the provider.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://vwo.com/privacy-policy/#locale_lang.
Pinterest Conversion Tag
We use Pinterest Conversion Tag for conversion tracking. The provider is Pinterest Inc., 505 Brannan Street San Francisco, CA 94107, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses), contact data (e.g. e-mail addresses, telephone numbers) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis standard contractual clauses. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed by standard data protection clauses (Art. 46 para. 2 lit. c GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93 para. 2 of the GDPR, which we have agreed to with the provider.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://policy.pinterest.com/en/privacy-policy.
Google Merchant Center
We use Google Merchant Center to maintain an online store. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes meta/communication data (e.g. device information, IP addresses) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
later
We use later for marketing campaigns, in order to organise our social media platforms better. The provider is Victory Square Media Inc., Vancouver, British Columbia, Canada. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in Canada in Canada.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
The data will be deleted when the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://later.com/privacy/.
Google Ads
We use Google Ads for advertising. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
We delete the data when the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://business.safety.google/privacy/.
Meta Ads
We use Meta Ads for advertising. The provider is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times), meta/communication data (e.g. device information, IP addresses) in the USA in the USA.
The legal basis for the processing is Art. 6 para. 1 s. 1 lit. a GDPR . The processing is based on consent. Data subjects may revoke their consent at any time by contacting us, for example, using the contact details provided in our privacy policy. The revocation does not affect the lawfulness of the processing until the revocation.
The transfer of personal data to a country outside the EEA takes place on the legal basis adequacy decision. The security of the data transferred to the third country (i.e. a country outside the EEA) is guaranteed because the EU Commission has decided as part of an adequacy decision in accordance with Art. 45 para. 3 GDPR that the third country ensures an adequate level of protection.
We delete the data when the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://www.facebook.com/policy.php.
heyData
We have integrated a data protection seal on our website. The provider is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany. The provider processes meta/communication data (e.g. IP addresses) in the EU.
The legal basis of the processing is Art. 6 para. 1 s. 1 lit. f GDPR. We have a legitimate interest in providing website visitors with confirmation of our data privacy compliance. At the same time, the provider has a legitimate interest in ensuring that only customers with existing contracts use its seals, which is why a mere image copy of the certificate is not a viable alternative as confirmation.
As the data is masked after collection, there is no possibility to identify website visitors. Further information is available in the privacy policy of the provider at https://heydata.eu/en/privacy-policy .
Data processing on social media platforms
We are represented in social media networks in order to present our organization and our services there. The operators of these networks regularly process their users' data for advertising purposes. Among other things, they create user profiles from their online behavior, which are used, for example, to show advertising on the pages of the networks and elsewhere on the Internet that corresponds to the interests of the users. To this end, the operators of the networks store information on user behavior in cookies on the users' computers. Furthermore, it cannot be ruled out that the operators merge this information with other data. Users can obtain further information and instructions on how to object to processing by the site operators in the data protection declarations of the respective operators listed below. It is also possible that the operators or their servers are located in non-EU countries, so that they process data there. This may result in risks for users, e.g. because it is more difficult to enforce their rights or because government agencies access the data.
If users of the networks contact us via our profiles, we process the data provided to us in order to respond to the inquiries. This is our legitimate interest, so that the legal basis is Art. 6 para. 1 s. 1 lit. f GDPR.
Facebook
We maintain a profile on Facebook. The operator is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available here: https://www.facebook.com/policy.php. A possibility to object to data processing arises via settings for advertisements: https://www.facebook.com/settings?tab=ads.We are joint controllers for processing the data of visitors to our profile on the basis of an agreement within the meaning of Art. 26 GDPR with Facebook. Facebook explains exactly what data is processed at https://www.facebook.com/legal/terms/information_about_page_insights_data. Data subjects can exercise their rights both against us and against Facebook. However, according to our agreement with Facebook, we are obliged to forward requests to Facebook. Data subjects will therefore receive a faster response if they contact Facebook directly.
Instagram
We maintain a profile on Instagram. The operator is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available here: https://help.instagram.com/519522125107875.
YouTube
We maintain a profile on YouTube. The operator is Google Ireland Limited Gordon House, Barrow Street Dublin 4. Ireland. The privacy policy is available here: https://policies.google.com/privacy?hl=de.
LinkedIn
We maintain a profile on LinkedIn. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The privacy policy is available here: https://https://www.linkedin.com/legal/privacy-policy?_l=de_DE. One way to object to data processing is via the settings for advertisements: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Changes to this privacy policy
We reserve the right to change this privacy policy with effect for the future. A current version is always available here.
Questions and comments
If you have any questions or comments regarding this privacy policy, please feel free to contact us using the contact information provided above.

