Privacy Policy

We are pleased that you are visiting our website. The protection and security of your personal information when using our website is very important to us. We would therefore like to inform you at this point which of your personal data we collect when you visit our website and for what purposes it is used.

This data protection declaration applies to the website of the Small Improvements Software GmbH , which can be reached under the domain www.small-improvements.com as well as the various subdomains (“our website”).

Who is responsible and how do I contact you?

Responsible

for the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)

Small Improvements Software GmbH Rosa-Luxemburg-Straße 2010178 Berlin

Mail: support@small-improvements.com

 

Data protection officer

DataSolution LUD GmbH

Mail: mail@ds-lud.de

What is this about?

This data protection declaration meets the legal requirements for transparency in the processing of personal data. This is all information that relates to an identified or identifiable natural person. This includes, for example, information such as your name, your age, your address, your telephone number, your date of birth, your e-mail address, your IP address or user behavior when visiting a website. Information with which we cannot (or only with disproportionate effort) relate to you personally, e.g. through anonymization, are not personal data. The processing of personal data (e.g. the collection, querying, use, storage or transmission) always requires a legal basis and a defined purpose.

Stored personal data are deleted as soon as the purpose of the Processing has been achieved and there are no legitimate reasons for further retention of the data. We will inform you about the specific storage periods and criteria for storage in the individual processing operations. Regardless of this, we store your personal data in individual cases to assert, exercise or defend legal claims and if there are statutory retention requirements.

Who gets my data?

We only pass on your personal data that we process on our website to third parties if this is necessary for the fulfillment of the purposes and in individual cases is covered by the legal basis (e.g. consent or protection of legitimate interests). In addition, we pass on personal data to third parties in individual cases if this serves to assert, exercise or defend legal claims. Possible recipients can then e.g. Law enforcement authorities, lawyers, auditors, courts, etc.

Insofar as we use service providers for the operation of our website who, as part of order processing on our behalf, provide personal data in accordance with. Process Art. 28 GDPR, these recipients of your personal data can be. You can find more detailed information on the use of processors and web services in the overview of the individual processing operations.

What rights do I have?

Under the conditions of the statutory provisions of the General Data Protection Regulation (GDPR), you as a data subject have the following rights:

  • Information in accordance with Art. 15 GDPR about the data stored about you in the form of meaningful information on the details of the processing and a copy of your data;
  • Correction in accordance with Art. 16 GDPR of inaccurate or incomplete data stored by us;
  • Deletion in accordance with Art. 17 GDPR of the data stored by us, insofar as the processing is not necessary for the exercise of the right to freedom of expression and information, for the fulfilment of a legal obligation, for reasons of public interest or for the assertion, exercise or defence of legal claims;
  • Restriction of the processing in accordance with Art. 18 GDPR, insofar as the correctness of the data is disputed, the processing is unlawful, we no longer need the data and you refuse to delete it, because you need it to assert, exercise or defend legal claims or you have objected to the processing in accordance with Art. 21 GDPR.
  • Data portability in accordance with Art. 20 GDPR, insofar as you have provided us with personal data within the framework of consent pursuant to Art. 6 sec. 1 lit. a GDPR or on the basis of a contract pursuant to Art. 6 sec. 1 lit.b GDPR and these were processed by us by means of automated procedures. You receive your data in a structured, common and machine-readable format or we transmit the data directly to another responsible person, as far as this is technically feasible.
  • In accordance with Art. 21 GDPR, you object to the processing of your personal data, insofar as they are carried out on the basis of Art. 6 sec. 1 lit. e, f GDPR and there are reasons for doing so, which arise from your particular situation or if the objection is directed against direct marketing. The right to object does not exist if overriding, overriding reasons for processing are proven or if the processing is carried out for the assertion, exercise or defence of legal claims. Insofar as there is no right to object in individual processing operations, this is indicated therein.
  • Revocation in accordance with Art. 7 sec. 3 GDPR of your given consent with effect for the future.
  • Complaint under Art. 77 GDPR to a supervisory authority if you believe that the processing of your personal data violates the GDPR. As a rule, you can contact the supervisory authority of your usual place of residence, your workplace or our company headquarters.

Protection of minors

This service is mainly aimed at adults. We do not currently market any special areas for children. As a result, we do not knowingly collect age information, nor do we knowingly collect personal information from children under the age of 16. However, we advise all visitors to our website under the age of 16 not to disclose or provide any personal data via our service. In the event that we discover that a child under the age of 16 has provided us with personal information, we will delete the child’s personal information from our files to the extent technically feasible.

Safety

We implement technical and organizational security measures in accordance with Art. 32 GDPR in order to protect your data managed by us against accidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security measures are continuously improved in line with technological developments. Access to it is only possible for a few authorised persons and persons obliged to provide special data protection who are involved in the technical, administrative or editorial support of data.

For security reasons and to protect the transmission of confidential content that you send to us as the site operator, our website uses SSL or TLS encryption. This means that data that you transmit via this website cannot be read by third parties. You can recognize an encrypted connection by the “https://” address line of your browser and the lock symbol in the browser line.

Updating and modification

We reserve the right to change, update or amend this privacy policy at any time. Any revised data processing information will only apply to personal data collected or modified after the entry into force.

Are cookies used?

Cookies are small text files that are sent by us to the browser of your device during your visit to our website and stored there. As an alternative to the use of cookies, information can also be stored in the local storage of your browser. Some functions of our website cannot be offered without the use of cookies or local storage (technically necessary cookies). Other cookies, on the other hand, enable us to carry out various analyses, so that we are able, for example, to recognize the browser you are using when you visit our website again and to transmit various information to us (non-essential cookies). With the help of cookies, we can, among other things, make our website more user-friendly and effective for you, for example by tracking your use of our website and changing your preferred settings (e.g. country and language settings). If third parties process information via cookies, they collect the information directly via your browser. Cookies do not cause any damage to your device. They can’t run programs and they can’t contain viruses.

We provide information about the respective services for which we use cookies in the individual processing operations. Detailed information on the cookies used can be found in the cookie settings or in the Consent Manager of this website.

How will my data be processed in detail?

In the following we will inform you about the individual processing operations, the scope and purpose of the data processing, the legal basis, the obligation to provide your data and the respective storage period. An automated decision in individual cases, including profiling, does not take place.

Provision of the website

Type and scope of processing

When you visit and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL the retrieved file
  • website from which access is made (referrer URL)
  • browser used and, if applicable, the operating system of your computer, as well as the name of your access provider

[Our website is not hosted by us, but by a service provider who for the purpose of the aforementioned data on our behalf in accordance with. Art. 28 GDPR processed.]

 

Purpose and legal basis

The processing is carried out to safeguard our overriding legitimate interest in displaying our website and ensuring security and stability on the basis of the Art. 6 para. Lit. f GDPR. The collection of data and storage in log files is essential for the operation of the website. There is no right to object to the processing due to the exception according to Art. 21 Paragraph 1 GDPR. Insofar as the further storage of the log files is required by law, the processing takes place on the basis of Art. 6 Para. 1 lit. c GDPR. There is no legal or contractual obligation to provide the data, but it is technically not possible to call up our website without providing the data.

 

Storage duration

The aforementioned data are used for the duration of the display of the website and for technical reasons beyond that for a maximum of 7 days.

Contact Form

Type and scope of processing

On our website, we offer you the option of contacting us using a form provided. The information that is collected via mandatory fields is required to process the request. In addition, you can voluntarily provide additional information that you believe is necessary to process the contact request.

When using the contact form, your personal data will not be passed on to third parties.

Purpose and legal basis

The processing of your data by using our contact form takes place for the purpose of communication and processing of your request on the basis of your consent in accordance with. Art. 6 para. 1 lit. a GDPR. If your request relates to an existing contractual relationship with us, processing for the purpose of fulfilling the contract is based on Art. 6 Para. 1 lit. b GDPR. There is no legal or contractual obligation to provide your data, but it is not possible to process your request without providing the information in the mandatory fields. If you do not want to provide this data, please contact us by other means.

Storage period

If you use the contact form on the basis of your consent, we will save the data collected each request for a period of three years, starting with the handling of your request or until you withdraw your consent.

[If you use the contact form in the context of a contractual relationship, we will save the data collected for each request Duration of [three years] from the end of the contractual relationship.]

Newsletter

Type and scope of processing

If you register on our website to receive our newsletter, we collect your email address [and your name …] and save this information together with the date of Registration and your IP address. You will then receive an email in which you have to confirm your subscription to the newsletter (double opt-in). If you do not confirm your registration within [XX hours], it will automatically expire and the data will not be processed for sending the newsletter.

[We will send the newsletter directly. Your data will not be passed on to third parties or processors within the meaning of Art. 28 GDPR.]

[To send the newsletter, we use a service of the [service provider] who collects your personal data on our behalf in accordance with Process Art. 28 GDPR. Your data will not be passed on to third parties.]

 

Purpose and legal basis

We process your data for the purpose of sending the newsletter on the basis of your consent in accordance with. Art. 6 para. 1 lit. a GDPR. By unsubscribing from the newsletter, you can withdraw your consent at any time with future effect. Declare Art. 7 Para. 3 GDPR. There is no legal or contractual obligation to provide your data, but it is not possible to send the newsletter without providing your data.

 

Storage period

Save after registering for the newsletter we will provide the dates a maximum of 24 hours until the registration is confirmed. After successful confirmation, we will save your data until you withdraw your consent (unsubscribe from the newsletter).

Registration of a customer account

Type and scope of processing

As part of order processing, we collect your personal data for the registration of a customer account. You can choose to order as a guest or register a permanent user account. The information collected during registration via the mandatory fields is identical in both cases and is required for the processing of the order in the online shop. When registering a permanent user account, we also collect a password that you have set yourself. In addition, you may voluntarily provide additional information that you believe is necessary to process the order.

Your personal data will only be passed on to third parties (e.B. shipping service providers / forwarding agents) and processors in accordance with Art. 28 GDPR only to the extent necessary for the processing of the order.

Purpose and legal basis

We process your personal data for the purpose of registering a customer account for the performance of a contract with you in accordance with Art. 6 sec. 1 lit.b GDPR. There is a contractual obligation to provide your data as far as it relates to the mandatory fields, as this information is necessary for the identification of you and for the fulfilment of the contract on our part. There is no legal obligation to provide the data. Without the provision of this information, the order in our online shop and thus a contract is not possible. There is no obligation to provide the additional information provided voluntarily. The order in our online shop is also possible without the disclosure of the voluntary information.

The additional processing of your password for the registration of the permanent user account takes place for the purpose of providing a customer account and for the presentation of your previous purchases as well as for the storage of your purchase-related data (e..B. storage of billing address, various delivery addresses) on the basis of your consent in accordance with Art. 6 sec. 1 lit. a GDPR. By deleting your customer account, you can declare your revocation in accordance with Art. 7 sec. 3 GDPR at any time with effect for the future.

Storage time

When you order as a guest, your personal data is stored until the complete processing of your order (end of contract). When registering a permanent customer account, store the purchase-related data beyond the end of the contract until your consent is revoked (deletion of the customer account). In both cases, further storage of your data will only take place if there are legal retention obligations (e.g. tax and commercial law).

Presences on social media platforms

We maintain so-called fan pages or accounts or channels on the networks mentioned below in order to provide you with information and offers within social networks and to offer you further ways to contact us and to find out about our offers. In the following, we inform you about what data we or the respective social network process from you in connection with the access and use of our fan pages/accounts.

Data we process from you

If you wish to contact us via Messenger or Direct Message via the respective social network, we will normally process your username, through which you contact us and store any other data you provide if this is necessary to process/respond to your request.

The legal basis is Art. 6(1) sentence 1 f) GDPR (processing is necessary to safeguard the legitimate interests of the controller).

(Static) Usage data we receive from the social networks

We receive automatically provided statistics about our accounts through Insights functionalities. The statistics include the total number of page views, likes, page activity and post interactions, reach, video views/views, and the proportion of men/women among our fans/followers.

The statistics contain only aggregated data which cannot be related to individuals. They are not identifiable to us.

What data you process social networks

In order to view the content of our fan pages or accounts, you do not have to be a member of the respective social network and no user account is required for the respective social network.

Please note, however, that when the respective social network is accessed, the social networks also collect and store data from website visitors without a user account (e..B. technical data in order to be able to view the website to you) and use cookies and similar technologies, which we have no influence on. Details can be found in the privacy policy of the respective social network (see the corresponding links above)

If you wish to interact with the content on our fan pages/accounts, e.B.g. comment, share or like our postings/posts and/or contact us via Messenger functions, prior registration with the respective social network and the provision of personal data is required.

We have no influence on the data processing by the social networks in the context of your use. To our knowledge, your data will be stored and processed in particular in connection with the provision of the services of the respective social network, furthermore for the analysis of the usage behaviour (using cookies, pixel/web beacons and similar technologies) on the basis of which advertising based on your interests is played out both within and outside the respective social network. It cannot be excluded that your data will be stored by the social networks outside the EU/EEA and will be passed on to third parties.

Information on, among other things, the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines on the use of cookies and similar technologies in the context of the registration and use of social networks can be found in the social protection policy/cookie policy. There you will also find information about your rights and possibilities of objection.

Facebook page

When you visit our Facebook page, Facebook (Meta) collects, among other things, your IP address and other information that is available on your PC in the form of cookies. This information is used to provide us, as the operator of the Facebook pages, with statistical information about the use of the Facebook page. Facebook provides further information on this under the following link: https://facebook.com/help/pages/insights.

By means of the transmitted statistical information, it is not possible for us to draw conclusions about individual users. We only use these in order to be able to respond to the interests of our users and to continuously improve our online presence and to ensure the quality of it.

We collect your data via our fan page only in order to realize a possible provision for communication and interaction with us. This survey usually includes: Your name, message content, comment content, and the profile information you provide “publicly.”

The processing of your personal data for our above-mentioned purposes takes place on the basis of our legitimate business and communicative interest in offering an information and communication channel in accordance with Art. 6 para. 1 f) GDPR. If you as a user have given your consent to data processing to the respective provider of the social network, the legal basis of the processing extends to Art. 6 para. 1 a), Art. 7 GDPR.

Due to the fact that the actual data processing is carried out by the provider of the social network, our access options are limited to your data. Only the provider of the social network is authorized to have full access to your data. Due to this, only the provider can directly take and implement appropriate measures to fulfill your user rights (request for information, deletion request, objection, etc.). The assertion of corresponding rights is therefore most effectively asserted directly against the respective provider.

Together with Facebook, we are responsible for the personal content of the fan page. Data subject rights can be asserted with Meta Platforms Ireland Ltd. as well as with us.

According to the GDPR, the primary responsibility for the processing of Insights data lies with Facebook and Facebook fulfils all obligations under the GDPR with regard to the processing of Insights data, Meta Platforms Ireland Ltd. makes the essence of the Page Insights supplement available to the data subjects.

We do not make any decisions regarding the processing of Insights data and the storage period of cookies on user devices.

Further information can be found directly on Facebook (supplementary agreement with Facebook): https://www.facebook.com/legal/terms/page_controller_addendum.

Further information on the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines for the use of cookies and similar technologies in the context of registration and use can be found in Facebook’s privacy policy/cookie policy:https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0https://www.facebook.com/policies/cookies

Instagram page

When you visit our Instagram page, Instagram collects, among other things, your IP address and other information that is available in the form of cookies on your PC. This information is used to provide us, as the operator of the Instagram pages, with statistical information about the use of the Instagram page. For more information, please visit Instagram at the following link: https://facebook.com/help/pages/insights.

By means of the statistical information provided, it is not possible for us to draw conclusions about individual users. We only use them to respond to the interests of our users and to continuously improve our online presence and ensure the quality of these.

We only collect your data via our fan page in order to realize a possible provision for communication and interaction with us. This survey is typically carried out in the Your name, message content, comment content, and the profile information you provide “publicly.”

The processing of your personal data for our above-mentioned purposes is based on our legitimate business and communicative interest in the offer of an information and communication channel in accordance with Art. 6 sec. 1 f) GDPR. If you, as a user, have given consent to the respective provider of the social network in the processing of data, the legal basis of the processing extends to Art. 6 sec. 1 a), Art. 7 GDPR.

Due to the fact that the actual data processing is carried out by the provider of the social network, our access possibilities are limited to your data. Only the provider of the social network is entitled to full access to your data. As a result, only the provider can directly take and implement appropriate measures to fulfill your user rights (request for information, requests for deletion, objection, etc.). The assertion of corresponding rights is therefore most effectively carried out directly against the respective provider.

Together with Instagram, we are responsible for the personal content of the fan site. Affected parties may be asserted by Facebook Ireland as well as with us.

The primary responsibility for the processing of Insights data is in accordance with the GDPR at Instagram and Instagram fulfils all obligations under the GDPR with regard to the processing of Insights data, Facebook Ireland makes the essence of the Page Insights supplement available to the data subjects.

We do not make any decisions regarding the processing of Insights data and any other information resulting from Article 13 GDPR, including the legal basis, identity of the controller and storage period of cookies on user terminals.

For more information, visit Instagram (supplementary agreement with Facebook): https://www.facebook.com/legal/terms/page_controller_addendum.

Twitter page

Twitter is a social network of Twitter Inc. based in San Francisco, California, USA, which enables the creation of private profiles of natural persons (Personal Account) as well as professional profiles (Professional Account) of natural persons and companies. Via Twitter, users can, among other things, write spa messages (so-called “tweets”), interact with the content of other users, e.g. write so-called “retweets”, give likes to posts, share posts and reply when other users mention or tag you in content (“tag”).

When using or visiting the network and thus also when visiting our Twitter account, Twitter automatically collects data from users or visitors during use or visit, such as user name and IP address. This is done with the help of tracking technologies, in particular with the use of cookies. Twitter provides users with information, offers and recommendations on the basis of the data collected in this way, among other things. This information is used to provide us, as the operator of our Twitter page, with statistical information about the use of the Twitter page. Further information can be found in Twitter’s privacy policy: https://twitter.com/privacy#twitter-privacy-1.

By means of the transmitted statistical information, it is not possible for us to draw conclusions about individual users. We only use these in order to be able to respond to the interests of our users and to continuously improve our online presence and to ensure the quality of it.

We collect your data via our fan page only in order to realize a possible provision for communication and interaction with us. This survey usually includes: Your name, message content, comment content, and the profile information you provide “publicly.”

The processing of your personal data for our above-mentioned purposes takes place on the basis of our legitimate business and communicative interest in offering an information and communication channel in accordance with Art. 6 para. 1 f GDPR. If you as a user have given your consent to data processing to the respective provider of the social network, the legal basis for the processing extends to Art. 6 para. 1 a, Art. 7 GDPR.

Due to the fact that the actual data processing is carried out by the provider of the social network, our access options are limited to your data. Only the provider of the social network is authorized to have full access to your data. Due to this, only the provider can directly take and implement appropriate measures to fulfill your user rights (request for information, deletion request, objection, etc.). The assertion of corresponding rights is therefore most effectively asserted directly against the respective provider.

Together with Twitter, we are responsible for the personal content of the fan page. Data subject rights can be asserted at Twitter Inc. as well as with us.

The primary responsibility under the GDPR for the processing of Insights data lies with Twitter and Twitter fulfils all obligations under the GDPR with regard to the processing of Insights data. Twitter Inc. makes the essence of the Page Insights supplement available to the data subjects.

We do not make any decisions regarding the processing of Insights data and the storage period of cookies on user devices.

Further information on the exact scope and purposes of the processing of your personal data, the storage period/deletion as well as guidelines for the use of cookies and similar technologies in the context of registration and use can be found in Twitter’s privacy policy/cookie policy:Privacy Policy: https://twitter.com/privacy#twitter-privacy-1Cookie Policy: https://help.twitter.com/rules-and-policies/twitter-cookies

LinkedIn page

LinkedIn is a social network of LinkedIn Inc. based in Sunnyvale, California, USA, which enables the creation of private and professional profiles of natural persons and company profiles. Users can maintain their existing contacts within the social network and make new ones. Companies and other organizations can create profiles where photos and other company information are uploaded to present themselves as employers and hire employees. Other LinkedIn users have access to this information and can write their own articles and share this content with others. The focus of the network is on the professional exchange on specialist topics with people who have the same professional interests.

When using or visiting the network, LinkedIn automatically collects data from users or visitors during use or visit, such as user name, job title and IP address. This is done with the help of various tracking technologies. LinkedIn provides benefits based on the data collected in this way, among other things, information, offers and recommendations.

We collect your data via our company profile only in order to realize a possible provision for communication and interaction with us. This survey usually includes: Your name, message content, comment content, and the profile information you provide “publicly.”

The processing of your personal data for our above-mentioned purposes takes place on the basis of our legitimate business and communicative interest in offering an information and communication channel in accordance with Art. 6 para. 1 f GDPR. If you as a user have given your consent to data processing to the respective provider of the social network, the legal basis for the processing extends to Art. 6 para. 1 a, Art. 7 GDPR.

Due to the fact that the actual data processing is carried out by the provider of the social network, our access options are limited to your data. Only the provider of the social network is authorized to have full access to your data. Due to this, only the provider can directly take and implement appropriate measures to fulfill your user rights (request for information, deletion request, objection, etc.). The assertion of corresponding rights is therefore most effectively asserted directly against the respective provider.

Together with LinkedIn, we are responsible for the personal content of our company profile. Data subject rights can be asserted at LinkedIn Inc. as well as with us.

We do not make any decisions regarding the data collected on the LinkedIn site using tracking technologies.

For more information about LinkedIn, visit: https://about.linkedin.com.

Further information on data protection at LinkedIn can be found at: https://www.linkedin.com/legal/privacy-policy.

Further information on the storage period/deletion as well as guidelines for the use of cookies and similar technologies in the context of registration and use on LinkedIn can be found at: https://linkedin.com/legal/cookie-policy?trk=homepage-basic_footer-cookie-policy.

Use of the Platform

Type and scope of processing

As part of the use of our product, personal data of the customer and his employees are stored. The data stored about the employees is the responsibility of the customer. In the event of support, support staff may, with the customer’s consent, become aware of the stored data.

Your personal data will only be passed on to third parties and processors in accordance with Art. 28 GDPR insofar as this is necessary for the provision of services.

The platform is hosted by the service provider Google Ireland Ltd., Dublin, Ireland.

To improve our platform and for marketing purposes, we use analytics data from Google Analytics and merge it with data from the platform. This will only be done with your consent, which you give on the website in relation to Google Analytics. For the merger we use the service of dbt Labs, Inc. Delaware, USA. We have concluded the SCC with the service provider. The service provider’s privacy policy can be found here: https://www.getdbt.com/cloud/privacy-policy

 

Purpose and legal basis

We process your personal data for the performance of the contract with you in accordance with Art. 6 (1) (b) GDPR.

The additional processing of your password for the registration of the user account is carried out for the purpose of providing a customer account. Furthermore, as part of the product information, we send e-mails with information and product updates on the basis of the legitimate interest in accordance with Art. 6 (1) (f) GDPR.

The evaluation and analysis of the Google Analytics data in connection with the data of the platform is carried out on the basis of your consent in accordance with Art. 6 (1) (a) GDPR.

 

Storage period

If you register a permanent customer account, we store the purchase-related data beyond the end of the contract, until the expiry of the statutory retention periods.

You can revoke your consent to the merging of the data at any time in the cookie banner.

Comply Consent Manager

Type and scope of processing

We have integrated Comply Consent Manager on our website. Comply Consent Manager is a consent solution of the Hendrik Paulo Gaffo & Alexander Riegert GbR, Carl-Bremer-Ring 13, 22179 Hamburg, Deutschland, with which consent to the storage of cookies can be obtained and documented. Comply Consent Manager uses cookies or other web technologies to recognize users and to store the consent given or revoked.

Purpose and legal basis

The use of the service is based on the legally required consent to receive the use of cookies in accordance with Art. 6 sec. 1 lit.c. GDPR.

Storage time

The actual storage time of the processed data is not influenced by us, but is determined by Hendrik Paulo Gaffo & Alexander Riegert GbR. For more information, see the privacy policy for Comply Consent Manager: https://comply-app.com/privacy-policy.

Comply Privacy Policy Sync

Type and scope of processing

We use Comply Privacy Policy Sync to properly provide the privacy policy on our website. Comply Privacy Policy Sync is a service of the Hendrik Paulo Gaffo & Alexander Riegert GbR.

When you access this content, you establish a connection to servers of the Hendrik Paulo Gaffo & Alexander Riegert GbR, Carl-Bremer-Ring 13, 22179 Hamburg, Deutschland, whereby your IP address and, if applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes mentioned above and to maintain the security and functionality of Comply Privacy Policy Sync.

Purpose and legal basis

The use is based on our legitimate interests, i.e. interest in a secure and efficient provision as well as the optimization of our online offer in accordance with Art. 6 para. 1 lit. f. DSGVO.

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by Hendrik Paulo Gaffo & Alexander Riegert GbR. Further information can be found in the privacy policy for Comply Privacy Policy Sync: https://comply-app.com/de/privacy-policy.

Facebook Pixel

Type and scope of processing

We use Meta-Pixel from Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, to create so-called Custom Audiences, i.e. to segment visitor groups to our online offer, to determine conversion rates and then to optimize them. This happens in particular when you interact with advertisements that we have placed with Meta Platforms Ireland Limited.

Purpose and legal basis

The use of Meta-Pixel is based on your consent in accordance with Art. 6 para. 1 lit. a. DSGVO and § 25 para. 1 TDDDG.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. The data transfer to the USA takes place in accordance with Art. 45 para. 1 GDPR on the basis of the adequacy decision of the European Commission. The participating U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

In cases where there is no adequacy decision by the European Commission (including US companies that are not EU-U.S. DPF certified), we have agreed other appropriate safeguards with the recipients of the data within the meaning of Art. 44 et seq. GDPR. Unless otherwise stated, these are standard contractual clauses of the EU Commission in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. A copy of these Standard Contractual Clauses can be found at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE .

In addition, prior to such a third country transfer, we obtain your consent in accordance with Art. 49 para. 1 sentence 1 lit. a. DSGVO, which you give via the consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of transfers to third countries, there may be risks unknown in detail (e.g. data processing by security authorities of the third country, the exact scope and consequences of which we do not know for you, over which we have no influence and of which you may not become aware).

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by Meta Platforms Ireland Limited. Further information can be found in the privacy policy for Meta-Pixel: https://www.facebook.com/privacy/explanation.

Google Analytics

Type and scope of processing

We use Google Analytics from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland, as an analysis service for the statistical evaluation of our online offer. This includes, for example, the number of visits to our online offer, subpages visited and the length of stay of visitors.

Google Analytics uses cookies and other browser technologies to evaluate user behavior and recognize users.

This information is used, among other things, to compile reports on the activity of the website.

Purpose and legal basis

The use of Google Analytics is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR and § 25 para. 1 TDDDG.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. The transfer of data to the USA takes place in accordance with Art. 45 para. 1 GDPR on the basis of the adequacy decision of the European Commission. The participating U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

In cases where there is no adequacy decision by the European Commission (including US companies that are not EU-U.S. DPF certified), we have other appropriate safeguards with the recipients of the data within the meaning of Art. 44 et seq. GDPR. Unless otherwise stated, these are standard contractual clauses of the EU Commission in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. A copy of these Standard Contractual Clauses can be found at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE .

In addition, before such a third country transfer, we obtain your consent in accordance with Art. 49 para. 1 sentence 1 lit. a. GDPR, which you give via consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of transfers to third countries, there may be risks unknown in detail (e.g. data processing by security authorities of the third country, the exact scope and consequences of which we do not know for you, over which we have no influence and of which you may not become aware).

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google Analytics: https://policies.google.com/privacy.

Google Tag Manager

Type and scope of processing

We use the Google Tag Manager of the Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland. Google Tag Manager is used to manage website tags through an interface and allows us to control the precise integration of services on our website.

This allows us to flexibly integrate additional services in order to evaluate user access to our website.

Purpose and legal basis

The use of Google Tag Manager is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR and § 25 para. 1 TDDDG.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. The transfer of data to the USA takes place in accordance with Art. 45 para. 1 GDPR on the basis of the adequacy decision of the European Commission. The participating U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

In cases where there is no adequacy decision by the European Commission (including US companies that are not EU-U.S. DPF certified), we have other appropriate safeguards with the recipients of the data within the meaning of Art. 44 et seq. GDPR. Unless otherwise stated, these are standard contractual clauses of the EU Commission in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. A copy of these Standard Contractual Clauses can be found at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE .

In addition, before such a third country transfer, we obtain your consent in accordance with Art. 49 para. 1 sentence 1 lit. a. GDPR, which you give via consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of transfers to third countries, there may be risks unknown in detail (e.g. data processing by security authorities of the third country, the exact scope and consequences of which we do not know for you, over which we have no influence and of which you may not become aware).

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by Google Ireland Limited. Further information can be found in the privacy policy for Google Tag Manager: https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/.

HubSpot API

Type and scope of processing

We use HubSpot, Inc. HubSpot API, Cambridge, Massachusetts, US to access additional services and data from HubSpot, Inc.. Your IP address will be transmitted to HubSpot, Inc.. Please note that a single section of this Privacy Policy is for each additional service we use from HubSpot, Inc..

Purpose and legal basis

The use of HubSpot API is based on our legitimate interests, i.e. interest in optimising our online offer in accordance with Art. 6 sec. 1 lit. f. GDPR.

Storage time

The actual storage time of the processed data is not influenced by us, but is determined by HubSpot, Inc.. For more information, see the privacy policy for HubSpot API: https://legal.hubspot.com/privacy-policy.

HubSpot Analytics

Type and scope of processing

We use HubSpot Analytics from HubSpot, Inc., Cambridge, Massachusetts, US, as an analysis service for the statistical evaluation of our online offer. This includes, for example, the number of visits to our online offer, subpages visited and the length of stay of visitors.

HubSpot Analytics uses cookies and other browser technologies to evaluate user behavior and recognize users.

This information is used, among other things, to compile reports on the activity of the website.

Purpose and legal basis

The use of HubSpot Analytics is based on your consent in accordance with Art. 6 para. 1 lit. a. DSGVO and § 25 para. 1 TDDDG.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. The data transfer to the USA takes place in accordance with Art. 45 para. 1 GDPR on the basis of the adequacy decision of the European Commission. The participating U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

In cases where there is no adequacy decision by the European Commission (including US companies that are not EU-U.S. DPF certified), we have agreed other appropriate safeguards with the recipients of the data within the meaning of Art. 44 et seq. GDPR. Unless otherwise stated, these are standard contractual clauses of the EU Commission in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. A copy of these Standard Contractual Clauses can be found at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE .

In addition, prior to such a third country transfer, we obtain your consent in accordance with Art. 49 para. 1 sentence 1 lit. a. DSGVO, which you give via the consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of transfers to third countries, there may be risks unknown in detail (e.g. data processing by security authorities of the third country, the exact scope and consequences of which we do not know for you, over which we have no influence and of which you may not become aware).

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by HubSpot, Inc.. Further information can be found in the privacy policy for HubSpot Analytics: https://legal.hubspot.com/privacy-policy.

HubSpot CDN

Type and scope of processing

We use HubSpot CDN to properly provide the content of our website. HubSpot CDN is a HubSpot, Inc. service that acts as a Content Delivery Network (CDN) on our website to ensure the functionality of other HubSpot, Inc. services. For these services, you will find a separate section of this Privacy Policy. This section is only about using the CDN.

A CDN helps to deliver content from our online offering, especially files such as graphics or scripts, faster with the help of regionally or internationally distributed servers. When you access this content, you connect to HubSpot, Inc. servers, Cambridge, Massachusetts, US, transmitting your IP address and, if applicable, browser data such as your user agent. This data will be processed exclusively for the above purposes and for the maintenance of the security and functionality of HubSpot CDN.

Purpose and legal basis

The use of the Content Delivery Network is based on our legitimate interests, i.e. interest in a secure and efficient provision and the optimization of our online offer in accordance with Art. 6 sec. 1 lit. f. GDPR.

Storage time

The actual storage time of the processed data is not influenced by us, but is determined by HubSpot, Inc.. For more information, see the privacy policy for HubSpot CDN: https://legal.hubspot.com/de/privacy-policy.

HubSpot Chat

Type and scope of processing

We have integrated components of the customer communication platform HubSpot Chat on our website. HubSpot Chat is a service of the HubSpot, Inc. and offers us the opportunity to communicate with visitors to our website via chat and to provide targeted help with questions. HubSpot Chat uses cookies and other browser technologies to evaluate user behavior and recognize users. Furthermore, HubSpot Chat is used to store and transmit data entered in chats using cookies, including your IP address. In this case, your data will be passed on to the operator of HubSpot Chat, which HubSpot, Inc., Cambridge, Massachusetts, US.

Purpose and legal basis

The use of HubSpot Chat is based on your consent in accordance with Art. 6 para. 1 lit. a. DSGVO and § 25 para. 1 TDDDG.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. The data transfer to the USA takes place in accordance with Art. 45 para. 1 GDPR on the basis of the adequacy decision of the European Commission. The participating U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

In cases where there is no adequacy decision by the European Commission (including US companies that are not EU-U.S. DPF certified), we have agreed other appropriate safeguards with the recipients of the data within the meaning of Art. 44 et seq. GDPR. Unless otherwise stated, these are standard contractual clauses of the EU Commission in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. A copy of these Standard Contractual Clauses can be found at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE .

In addition, prior to such a third country transfer, we obtain your consent in accordance with Art. 49 para. 1 sentence 1 lit. a. DSGVO, which you give via the consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of transfers to third countries, there may be risks unknown in detail (e.g. data processing by security authorities of the third country, the exact scope and consequences of which we do not know for you, over which we have no influence and of which you may not become aware).

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by HubSpot, Inc.. Further information can be found in the privacy policy for HubSpot Chat: https://legal.hubspot.com/privacy-policy.

HubSpot Cookie Banner

Type and scope of processing

We have integrated HubSpot Cookie Banner on our website. HubSpot Cookie Banner is a consent solution of the HubSpot, Inc., Cambridge, Massachusetts, US, with which consent to the storage of cookies can be obtained and documented. HubSpot Cookie Banner uses cookies or other web technologies to recognize users and to store the consent given or revoked.

Purpose and legal basis

The use of the service is based on the legally required consent to receive the use of cookies in accordance with Art. 6 sec. 1 lit.c. GDPR.

Storage time

The actual storage time of the processed data is not influenced by us, but is determined by HubSpot, Inc.. For more information, see the privacy policy for HubSpot Cookie Banner: https://legal.hubspot.com/privacy-policy.

LinkedIn Ads

Type and scope of processing

We have integrated LinkedIn Ads on our website. LinkedIn Ads is a service provided by LinkedIn Corporation that displays targeted advertising to users. LinkedIn Ads uses cookies and other browser technologies to evaluate user behavior and recognize users. LinkedIn Ads collects information about visitor behavior on various websites. This information is used to optimize the relevance of advertising. Furthermore, LinkedIn Ads delivers targeted advertising based on behavioral profiles and geographic location. Your IP address and other identification features such as your user agent are transmitted to the provider. In this case, your data will be passed on to the operator of LinkedIn Ads, which LinkedIn Corporation, Sunnyvale, California, US.

Web tracking technologies are used to create pseudonymized user profiles. These profiles cannot be merged with you as a natural person, but are used, for example, for segmentation when displaying advertisements.

Purpose and legal basis

The use of LinkedIn Ads is based on your consent in accordance with Art. 6 para. 1 lit. a. DSGVO and § 25 para. 1 TDDDG.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. The data transfer to the USA takes place in accordance with Art. 45 para. 1 GDPR on the basis of the adequacy decision of the European Commission. The participating U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

In cases where there is no adequacy decision by the European Commission (including US companies that are not EU-U.S. DPF certified), we have agreed other appropriate safeguards with the recipients of the data within the meaning of Art. 44 et seq. GDPR. Unless otherwise stated, these are standard contractual clauses of the EU Commission in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. A copy of these Standard Contractual Clauses can be found at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE .

In addition, prior to such a third country transfer, we obtain your consent in accordance with Art. 49 para. 1 sentence 1 lit. a. DSGVO, which you give via the consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of transfers to third countries, there may be risks unknown in detail (e.g. data processing by security authorities of the third country, the exact scope and consequences of which we do not know for you, over which we have no influence and of which you may not become aware).

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by LinkedIn Corporation. Further information can be found in the privacy policy for LinkedIn Ads: https://www.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer-privacy-policy.

LinkedIn Insight-Tag

Type and scope of processing

We use LinkedIn Insight-Tag from LinkedIn Corporation, Sunnyvale, California, US to create target groups, segment visitor groups to our online offer, determine conversion rates and then optimize them. This happens in particular when you interact with advertisements that we have placed with LinkedIn Corporation. For this purpose, LinkedIn Corporation offers retargeting for website visitors in order to display targeted advertising outside of our website.

LinkedIn Insight-Tag collects data about visits to our website, including URL, referrer URL, IP address, device and browser properties (user agent) and timestamps. This data is used to provide anonymized reports about the website audience and ad performance.

Purpose and legal basis

The use of LinkedIn Insight-Tag is based on your consent in accordance with Art. 6 para. 1 lit. a. DSGVO and § 25 para. 1 TDDDG.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. The data transfer to the USA takes place in accordance with Art. 45 para. 1 GDPR on the basis of the adequacy decision of the European Commission. The participating U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

In cases where there is no adequacy decision by the European Commission (including US companies that are not EU-U.S. DPF certified), we have agreed other appropriate safeguards with the recipients of the data within the meaning of Art. 44 et seq. GDPR. Unless otherwise stated, these are standard contractual clauses of the EU Commission in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. A copy of these Standard Contractual Clauses can be found at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE .

In addition, prior to such a third country transfer, we obtain your consent in accordance with Art. 49 para. 1 sentence 1 lit. a. DSGVO, which you give via the consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of transfers to third countries, there may be risks unknown in detail (e.g. data processing by security authorities of the third country, the exact scope and consequences of which we do not know for you, over which we have no influence and of which you may not become aware).

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by LinkedIn Corporation. Further information can be found in the privacy policy for LinkedIn Insight-Tag: https://www.linkedin.com/legal/privacy-policy.

SoundCloud Widget

Type and scope of processing

We have integrated SoundCloud on our website. SoundCloud is a component of the music platform of the SoundCloud, Inc., on which everyone can create and exchange musical content. Users can use the platform to record, upload and exchange music over the Internet, as well as get detailed statistics.

SoundCloud allows us to integrate content from the platform into our website.

SoundCloud uses cookies and other browser technologies to evaluate user behaviour, recognize users and create user profiles. This information is used, among other things, to analyze the activity of the content being listened to and to generate reports. If a user is registered with SoundCloud, Inc., the listening samples can be assigned to the profile.

When you access this content, you connect to SoundCloud, Inc. servers, , transmitting your IP address and, if applicable, browser data such as your user agent. This data will be processed exclusively for the above purposes and for the maintenance of the security and functionality of SoundCloud.

Purpose and legal basis

The use of SoundCloud is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR.

Storage time

The actual storage time of the processed data is not influenced by us, but is determined by SoundCloud, Inc.. For more information, see the privacy policy for SoundCloud: https://soundcloud.com/pages/privacy.

Vimeo Video

Type and scope of processing

We have integrated Vimeo Video on our website. Vimeo Video is a component of Vimeo, LLC’s video platform where users can upload content, share it over the internet, and get detailed statistics.

Vimeo Video allows us to integrate content from the platform into our website.

Vimeo Video uses cookies and other browser technologies to evaluate user behavior, recognize users and create user profiles. This information is used, among other things, to analyze the activity of the content listened to and to create reports.

When you access this content, you establish a connection to servers of the Vimeo, LLC, 555 W 18th St, New York, New York 10011, whereby your IP address and, if applicable, browser data such as your user agent are transmitted.

Purpose and legal basis

The use of Vimeo Video is based on your consent in accordance with Art. 6 para. 1 lit. a. DSGVO and § 25 para. 1 TDDDG.

We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. The data transfer to the USA takes place in accordance with Art. 45 para. 1 GDPR on the basis of the adequacy decision of the European Commission. The participating U.S. companies and/or their U.S. subcontractors are certified under the EU-U.S. Data Privacy Framework (EU-U.S. DPF).

In cases where there is no adequacy decision by the European Commission (including US companies that are not EU-U.S. DPF certified), we have agreed other appropriate safeguards with the recipients of the data within the meaning of Art. 44 et seq. GDPR. Unless otherwise stated, these are standard contractual clauses of the EU Commission in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. A copy of these Standard Contractual Clauses can be found at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE .

In addition, prior to such a third country transfer, we obtain your consent in accordance with Art. 49 para. 1 sentence 1 lit. a. DSGVO, which you give via the consent in the Consent Manager (or other forms, registrations, etc.). We would like to point out that in the case of transfers to third countries, there may be risks unknown in detail (e.g. data processing by security authorities of the third country, the exact scope and consequences of which we do not know for you, over which we have no influence and of which you may not become aware).

Storage period

The specific storage period of the processed data cannot be influenced by us, but is determined by Vimeo, LLC. Further information can be found in the privacy policy for Vimeo Video: https://vimeo.com/privacy.

WordPress JetPack

Type and scope of processing

We have integrated WordPress JetPack on our website. WordPress JetPack is a Automattic Inc. service for marketing services and products and web analytics.

WordPress JetPack uses cookies and other browser technologies to evaluate user behaviour, recognize users and deliver targeted advertising based on behavioural profiles and geographical location. This information is used, among other things, to compile reports on the activity of the website.

In this case, your data will be passed on to the operator of WordPress JetPack that Automattic Inc. San Francisco, California, US.

Purpose and legal basis

The use of WordPress JetPack is based on your consent in accordance with Art. 6 para. 1 lit. a. GDPR.

Storage time

The actual storage time of the processed data is not influenced by us, but is determined by Automattic Inc.. For more information, see the privacy policy for WordPress JetPack: https://automattic.com/privacy/.

Please also see our terms of service.