Skip to main content

Humanis Institute

Privacy Policy

preamble

With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online services").

The terms used are not gender-specific.

As of January 26, 2024

Rechtstext von Dr. Schwenke - für weitere Informationen bitte anklicken.

Inhaltsübersicht

Responsible person

Dr. phil. Claudia-Patricia Burger
Am Teich 17
61200 Wölfersheim
germany

E-Mail Adress mail@drclaudiaburger.com

Overview of processing

The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects.

Types of data processed

  • Bestandsdaten.
  • Payment details.
  • Contact details.
  • Content details
  • Contract data.
  • User data
  • Meta and communication details

Special Categories of Data

  • Healthdata
  • Sexual orientation
  • Religious believes
  • Ethnical heritage

Categories of data subjects

  • Clients
  • Selfemployed
  • Leads
  • Communicationpartners
  • Users
  • Businesspartners
  • Professionals

Purposes of processing

  • Provision of contractual services and fulfillment of contractual obligations.
  • Contact requests and communication.
  • Security measures.
  • Directmarketing
  • Range measurement.
  • Office and organizational procedures.
  • Conversion measurement.
  • Managing and responding to inquiries.
  • Feedback.
  • Marketing.
  • Profiles containing user-related information.
  • Provision of our online services and user-friendliness.
  • Information technology infrastructure.

Relevant legal bases

Relevant legal bases under the GDPR:Below you will find an overview of the legal bases under the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or establishment. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.

  • Einwilligung (Art. 6 Abs. 1 S. 1 lit. a) DSGVO) – Die betroffene Person hat ihre Einwilligung in die Verarbeitung der sie betreffenden personenbezogenen Daten für einen spezifischen Zweck oder mehrere bestimmte Zwecke gegeben.
  • Contractual performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR) – The processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR) – The processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

National Data Protection Regulations in Germany: In addition to the data protection regulations of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Act on the Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, special provisions regarding the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, state data protection laws of the individual federal states may apply. Translated with DeepL.com (free version)

Applicable Legal Bases Under the Swiss Data Protection Act: If you are located in Switzerland, we process your data in accordance with the Federal Act on Data Protection (the “Swiss DPA” for short). This also applies if our processing of your data otherwise affects you in Switzerland and you are affected by such processing. Unlike the GDPR, for example, the Swiss Data Protection Act does not generally require that a legal basis for the processing of personal data be specified. We process personal data only if the processing is lawful, carried out in good faith, and proportionate (Art. 6, paras. 1 and 2 of the Swiss Data Protection Act). Furthermore, we collect personal data only for specific purposes that are identifiable to the data subject and process it only in a manner consistent with those purposes (Art. 6(3) of the Swiss DSG). Translated with DeepL.com (free version)

Note on the Applicability of the GDPR and the Swiss Data Protection Act (DSG): This privacy notice serves to provide information in accordance with both the Swiss Federal Act on Data Protection (Swiss DSG) and the General Data Protection Regulation (GDPR). For this reason, please note that the terms used in the GDPR are employed here due to its broader geographical scope and clarity. In particular, instead of the terms “processing” of “personal data,” “overriding interest,” and “personal data requiring special protection” used in the Swiss Data Protection Act, the terms “processing” of “personal data,” “legitimate interest,” and “special categories of data” used in the GDPR are employed. However, the legal meaning of these terms continues to be determined in accordance with the Swiss Data Protection Act (DSG) within the scope of its application.

Securitymeasures

In accordance with legal requirements, and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

In Übereinstimmung mit den gesetzlichen Anforderungen und unter Berücksichtigung des Stands der Technik, der Implementierungskosten sowie der Art, des Umfangs, des Kontexts und der Zwecke der Verarbeitung sowie der unterschiedlichen Wahrscheinlichkeit und Schwere von Bedrohungen für die Rechte und Freiheiten natürlicher Personen ergreifen wir geeignete technische und organisatorische Maßnahmen, um ein dem Risiko angemessenes Sicherheitsniveau zu gewährleisten.

TLS/SSL Encryption (https): To protect user data transmitted through our online services, we use TLS/SSL encryption. Secure Sockets Layer (SSL) is the standard technology for securing Internet connections by encrypting the data transmitted between a website or app and a browser (or between two servers). Transport Layer Security (TLS) is an updated and more secure version of SSL. Hyper Text Transfer Protocol Secure (HTTPS) appears in the URL when a website is secured by an SSL/TLS certificate.

Transfer of personal data

As part of our processing of personal data, the data may be transferred to or disclosed to other entities, companies, legally independent organizational units, or individuals. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with legal requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.

International data transfers

Data Processing in Third Countries: If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if processing takes place in connection with the use of third-party services or the disclosure or transfer of data to other individuals, entities, or companies, this is done only in accordance with legal requirements. If the level of data protection in the third country has been recognized by means of an adequacy decision (Art. 45 GDPR), this serves as the basis for the data transfer. In all other cases, data transfers take place only if the level of data protection is otherwise ensured, in particular through standard contractual clauses (Art. 46(2)(c) GDPR), explicit consent, or in the case of transfers required by contract or law (Art. 49(1) GDPR). In addition, we will inform you of the legal basis for transfers to third countries for each individual provider located in a third country, whereby adequacy decisions take precedence as the legal basis. Information on transfers to third countries and existing adequacy decisions can be found on the European Commission’s website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

EU-U.S. Transatlantic Data Privacy Framework: Under the so-called “Data Privacy Framework” (DPF), the European Commission has also recognized the level of data protection provided by certain U.S. companies as adequate pursuant to the Adequacy Decision of July 10, 2023. You can find the list of certified companies as well as further information on the DPF on the U.S. Department of Commerce’s website at https://www.dataprivacyframework.gov/ (in English). We provide information in our Privacy Policy regarding which service providers we use that are certified under the Data Privacy Framework.

Disclosure of Personal Data Abroad: In accordance with the Swiss Data Protection Act (DSG), we disclose personal data abroad only if adequate protection for the data subjects is guaranteed (Art. 16 of the Swiss DSG). Unless the Federal Council has determined that adequate protection exists (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we implement alternative security measures. These may include international treaties, specific guarantees, data protection clauses in contracts, standard data protection clauses approved by the Federal Data Protection and Information Commissioner (FDPIC), or internal company data protection policies that have been pre-approved by the FDPIC or a competent data protection authority in another country.

According to Article 16 of the Swiss Data Protection Act (DSG), exceptions to the transfer of data abroad may be permitted if certain conditions are met, including the consent of the data subject, the performance of a contract, the public interest, the protection of life or physical integrity, data that has been made public, or data from a register established by law. Such transfers are always carried out in accordance with legal requirements.

Deletion of Data

The data we process is deleted in accordance with legal requirements as soon as the consent authorizing its processing is revoked or other legal grounds for processing no longer apply (e.g., if the purpose for processing this data no longer exists or the data is no longer necessary for that purpose). If the data is not deleted because it is required for other legally permissible purposes, its processing is limited to those purposes. This means that the data will be blocked and not processed for any other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons, or whose storage is necessary to assert, exercise, or defend legal claims, or to protect the rights of another natural or legal person. As part of our privacy policy, we may provide users with further information regarding the deletion and retention of data that applies specifically to the respective processing operations.

rights of affected persons

Rights of Data Subjects Under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 through 21 of the GDPR:

  • Right to Object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out pursuant to Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing.
  • Right to Withdraw Consent: You have the right to withdraw your consent at any time.
  • Right of Access: You have the right to request confirmation as to whether your personal data is being processed, as well as access to that data, additional information, and a copy of the data in accordance with legal requirements.
  • Right to Rectification: In accordance with legal requirements, you have the right to request that data concerning you be completed or that inaccurate data concerning you be corrected.
  • Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that data concerning you be erased without delay or, alternatively, to request a restriction on the processing of such data in accordance with legal requirements.
  • Right to Data Portability: You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, in accordance with legal requirements, or to request that it be transmitted to another data controller.
  • Complaint to a supervisory authority: In accordance with legal requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority—in particular, a supervisory authority in the Member State where you habitually reside— the supervisory authority of your place of work or the location of the alleged violation, if you believe that the processing of your personal data violates the GDPR.

Rights of data subjects under the Swiss Data Protection Act (DSG):

As a data subject, you have the following rights in accordance with the provisions of the Swiss Data Protection Act (DSG):

  • Right of Access: You have the right to request confirmation as to whether personal data concerning you is being processed, and to receive the information necessary to enable you to exercise your rights under this law and to ensure transparent data processing.
  • Right to Data Disclosure or Transfer: You have the right to request that we provide you with the personal data you have provided to us in a commonly used electronic format.
  • Right to Rectification: You have the right to request the rectification of inaccurate personal data concerning you.
  • Right to Object, Deletion, and Destruction: You have the right to object to the processing of your data and to request that your personal data be deleted or destroyed.

use of cookies

Cookies are small text files or other storage mechanisms that store information on end devices and retrieve information from them. For example, they are used to store a user’s login status in an account, the contents of a shopping cart in an online store, the content accessed, or the features used on a website. Cookies can also be used for various purposes, such as ensuring the functionality, security, and convenience of online services, as well as analyzing visitor traffic.

Information on Consent: We use cookies in accordance with legal requirements. Therefore, we obtain prior consent from users unless such consent is not required by law. In particular, consent is not required if the storage and retrieval of information—including cookies—are strictly necessary to provide users with a telemedia service (i.e., our online offering) that they have expressly requested. Strictly necessary cookies generally include cookies with functions that serve to display and ensure the operability of the online service, load balancing, security, the storage of user preferences and selections, or similar purposes related to the provision of the primary and secondary functions of the online service requested by users. The revocable consent is clearly communicated to users and includes information regarding the specific use of cookies.

Information on the legal basis for data protection: The legal basis under data protection law on which we process users’ personal data using cookies depends on whether we ask users for their consent. If users give their consent, the legal basis for processing their data is their expressed consent. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (e.g., in the business operation of our online service and improving its usability) or, if this occurs in the context of fulfilling our contractual obligations, when the use of cookies is necessary to fulfill our contractual obligations. We explain the purposes for which we process cookies in this Privacy Policy or as part of our consent and processing procedures.

Storage duration: With regard to storage duration, the following types of cookies are distinguished:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest after a user leaves an online service and closes their device (e.g., browser or mobile app).
  • Persistent cookies: Persistent cookies remain stored even after the device is shut down. This allows, for example, the login status to be saved or preferred content to be displayed immediately when the user visits a website again. Likewise, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage duration of cookies (e.g., when obtaining consent), users should assume that cookies are persistent and may be stored for up to two years.

General Information on Withdrawal of Consent and Objection (so-called “opt-out”): Users may withdraw the consent they have provided at any time and object to the processing of their data in accordance with legal requirements. To do so, users may, among other things, restrict the use of cookies in their browser settings (although this may also limit the functionality of our online service). You can also object to the use of cookies for online marketing purposes via the websites https://optout. aboutads.info and https://www.youronlinechoices.com/.

  • Rechtsgrundlagen: Legitimate interests (Art. 6(1), first sentence, subparagraph (f) of the GDPR). Consent (Art. 6(1), first sentence, subparagraph (a) of the GDPR).

Additional information on processing procedures, methods, and services:

  • Processing of Cookie Data Based on Consent:We use a consent management procedure: a procedure for obtaining, logging, managing, and withdrawing consent, in particular for the use of cookies and similar technologies for storing, reading, and processing information on users' devices, as well as for the processing of this information. Within this framework, users' consent to the use of cookies, or the processing and providers mentioned in the consent management procedure, can be obtained, managed, and withdrawn by the users. The consent declaration is stored to avoid having to request it again and to be able to prove consent in accordance with legal obligations. Storage can take place server-side and/or in a cookie (so-called opt-in cookie, or using comparable technologies) to assign the consent to a user or their device. Subject to individual specifications regarding the providers of cookie management services, the following information applies: The storage period for consent can be up to two years. A pseudonymous user identifier is created and stored along with the time of consent, information on the scope of the consent (e.g., which categories of cookies and/or service providers), as well as the browser, operating system, and device used; Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).
  • BorlabsCookie: Consent Management: Procedures for obtaining, logging, managing, and revoking consent, particularly regarding the use of cookies and similar technologies for storing, reading, and processing information on users’ end devices, as well as the processing of such information; Service Provider: Execution on servers and/or computers under its own responsibility under data protection law; Website: https://de.borlabs.io/borlabs-cookie/. Further information: An individual user ID, language, types of consent, and the time they were granted are stored on the server and in a cookie on the user’s device.

Business services

We process data from our contractual and business partners, such as customers and prospective customers (collectively referred to as “contractual partners”), in connection with contractual and similar legal relationships, as well as related measures, and in the course of communicating with contractual partners (or on a pre-contractual basis), for example, to respond to inquiries.

We process this data to fulfill our contractual obligations. These include, in particular, the obligations to provide the agreed-upon services, any obligations to update the data, and to remedy warranty claims and other service disruptions. In addition, we process the data to safeguard our rights and for the purposes of administrative tasks associated with these obligations, as well as for corporate organization. Furthermore, we process the data based on our legitimate interests in proper and sound business management, as well as in security measures to protect our contractual partners and our business operations from misuse, and threats to their data, confidential information, and rights (e.g., involving telecommunications, transportation, and other support services, as well as subcontractors, banks, tax and legal advisors, payment service providers, or tax authorities). Within the framework of applicable law, we disclose the data of contractual partners to third parties only to the extent necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners are informed about other forms of processing, e.g., for marketing purposes, in this Privacy Policy.

We inform our contractual partners of which data is required for the aforementioned purposes either before or during the data collection process—for example, in online forms, through special markings (e.g., colors) or symbols (e.g., asterisks or similar), or in person.

We delete the data after the expiration of statutory warranty obligations and comparable obligations, i.e., generally after 4 years, unless the data is stored in a customer account—for example, as long as it must be retained for legal archiving purposes. The statutory retention period is ten years for documents relevant under tax law, as well as for ledgers, inventories, opening balance sheets, annual financial statements, the work instructions necessary for understanding these documents, and other organizational documents and accounting vouchers; and six years for received commercial and business correspondence and copies of sent commercial and business correspondence. The period begins at the end of the calendar year in which the last entry was made in the book, the inventory, opening balance sheet, annual financial statements, or management report was prepared, the commercial or business letter was received or sent, or the accounting document was created; furthermore, the record was made or the other documents were created.

To the extent that we use third-party providers or platforms to provide our services, the terms and conditions and privacy policies of the respective third-party providers or platforms apply to the relationship between users and those providers.

  • Types of data processed: Customer information (e.g., names, addresses); payment information (e.g., bank account information, invoices, payment history); contact information (e.g., email, phone numbers); contract information (e.g., subject matter of the contract, term, customer category).
  • Special categories of personal data: Health data; data regarding sexual life or sexual orientation; religious or philosophical beliefs; data revealing racial or ethnic origin.
  • Data subjects: Prospective customers. Business and contractual partners.
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; contact requests and communication; office and organizational procedures; management and response to inquiries.
  • Legal Basis: Performance of a contract and pre-contractual inquiries (Art. 6(1), first sentence, lit. b) of the GDPR); Legal obligation (Art. 6(1), first sentence, lit. c) of the GDPR). Legitimate interests (Art. 6(1), first sentence, lit. f) of the GDPR).

Additional information on processing procedures, methods, and services:

  • Coaching: Wir verarbeiten die Daten unserer Klienten sowie Interessenten und anderer Auftraggeber oder Vertragspartner (einheitlich bezeichnet als „Klienten“), um ihnen gegenüber unsere Leistungen erbringen zu können. Die verarbeiteten Daten, die Art, der Umfang, der Zweck und die Erforderlichkeit ihrer Verarbeitung bestimmen sich nach dem zugrundeliegenden Vertrags- und Klientenverhältnis.

    In Rahmen unserer Tätigkeit können wir ferner besondere Kategorien von Daten, hier insbesondere Angaben zur Gesundheit der Klienten, ggf. mit Bezug zu deren Sexualleben oder der sexuellen Orientierung, sowie Daten, aus denen die rassische und ethnische Herkunft, politische Meinungen, religiöse oder weltanschauliche Überzeugungen oder die Gewerkschaftszugehörigkeit hervorgehen, verarbeiten. Hierzu holen wir, sofern erforderlich, eine ausdrückliche Einwilligung der Klienten ein und verarbeiten die besonderen Kategorien von Daten ansonsten sofern dies der Gesundheit der Klienten dient, die Daten öffentlich sind oder andere gesetzliche Erlaubnisse vorliegen.

    Sofern es für unsere Vertragserfüllung, zum Schutz lebenswichtiger Interessen oder gesetzlich erforderlich ist, bzw. eine Einwilligung der Klienten vorliegt, offenbaren oder übermitteln wir die Daten der Klienten unter Beachtung der berufsrechtlichen Vorgaben an Dritte oder Beauftragte, wie z. B. Behörden, Abrechnungsstellen sowie im Bereich der IT, der Büro- oder vergleichbarer Dienstleistungen; Rechtsgrundlagen: Vertragserfüllung und vorvertragliche Anfragen (Art. 6 Abs. 1 S. 1 lit. b) DSGVO).

Use of online platforms

We offer our services on online platforms operated by other service providers. In this context, the privacy policies of the respective platforms apply in addition to our privacy policy. This applies in particular to the processing of payments and the methods used on the platforms for audience measurement and interest-based marketing.

  • Types of data processed: Inventory data (e.g., names, addresses); Payment data (e.g., bank details, invoices, payment history); Contact data (e.g., email addresses, telephone numbers); Contract data (e.g., subject matter of the contract, term, customer category); Usage data (e.g., websites visited, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Affected persons: Customers; prospective customers; business and contractual partners.
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; marketing; conversion measurement (measuring the effectiveness of marketing measures). Provision of our online services and user-friendliness.
  • Legal basis: Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • CopeCart: Online marketplace for e-commerce; Service provider: CopeCart GmbH, Ufnaustraße 10, 10553 Berlin, Germany; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.copecart.com/. Privacy policy: https://www.copecart.com/de/datenschutz.
  • Digistore24:Online marketplace; Service provider: Digistore24 GmbH, St.-Godehard-Straße 32, 31139 Hildesheim, Germany; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.digistore24.com/. Privacy Policy: https://www.digistore24.com/de/home/extern/cms/page/frontend/legal/privacy.

Provision of the online service and web hosting

We process user data to provide our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.

  • Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status); content data (e.g., entries in online forms).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user-friendliness; Information technology infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • Provision of online services on rented storage space:For the provision of our online services, we use storage space, computing capacity, and software that we rent from a corresponding server provider (also known as a "web host") or otherwise obtain; Legal basis:Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Collection of Access Data and Log Files:Access to our online services is logged in the form of so-called "server log files." Server log files may include the address and name of the accessed web pages and files, the date and time of access, the amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider. Server log files may be used for security purposes, e.g., to prevent server overload (especially in the case of malicious attacks, so-called DDoS attacks), and to ensure server capacity and stability; Legal Basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Data Deletion: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data that needs to be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully resolved.
  • Email Sending and Hosting:The web hosting services we use also include sending, receiving, and storing emails. For these purposes, the addresses of the recipients and senders, as well as other information relating to email transmission (e.g., the providers involved) and the content of the respective emails, are processed. The aforementioned data may also be processed for spam detection purposes. Please note that emails are generally not encrypted when sent over the internet. While emails are usually encrypted during transmission, they are not encrypted on the servers from which they are sent and received (unless end-to-end encryption is used). Therefore, we cannot assume any responsibility for the transmission path of emails between the sender and their receipt on our server. Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • ALL-INKL:Services in the field of providing information technology infrastructure and related services (e.g., storage space and/or computing capacity); Service provider: ALL-INKL.COM – Neue Medien Münnich, Owner: René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website:https://all-inkl.com/; Privacy policy: https://all-inkl.com/datenschutzinformationen/. Data Processing Agreement: Provided by the service provider.

Blogs and publication media

We use blogs or similar online communication and publication tools (hereinafter referred to as "publication medium"). Reader data is processed for the purposes of the publication medium only to the extent necessary for its presentation and communication between authors and readers, or for security reasons. For further information regarding the processing of visitor data to our publication medium, please refer to the privacy policy.

  • Types of data processed: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, telephone numbers); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; feedback (e.g., collecting feedback via online form); provision of our online services and user-friendliness; security measures.
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • UpdraftPlus: Backup software and backup storage; Service provider: Simba Hosting Ltd., 11, Barringer Way, St. Neots, Cambs., PE19 1LW, UK; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://updraftplus.com/. Privacy policy: https://updraftplus.com/data-protection-and-privacy-centre/.

Contact and inquiry management

When you contact us (e.g. by mail, contact form, email, telephone or via social media) and within the framework of existing user and business relationships, the information provided by the requesting persons is processed to the extent necessary to answer the contact requests and any requested measures.

  • Types of data processed: Contact data (e.g., email address, telephone numbers); Content data (e.g., entries in online forms); Usage data (e.g., websites visited, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Affected persons: Communication partners.
  • Purposes of data processing: Contact requests and communication; managing and responding to inquiries; feedback (e.g., collecting feedback via online form). Provision of our online services and user-friendliness.
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).

Additional information on processing procedures, methods, and services:

  • Contact Form:When users contact us via our contact form, email, or other communication channels, we process the data provided to us in this context to handle the stated request; Legal Basis:Contractual performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Communication via messenger

We use messengers for communication purposes and therefore ask you to take note of the following information regarding the functionality of the messengers, encryption, the use of communication metadata and your options to object.

You can also contact us via alternative methods, such as by phone or email. Please use the contact options provided to you or those listed within our online services.

In the case of end-to-end encryption of content (i.e., the content of your message and attachments), please note that the communication content (i.e., the message content and attached images) is encrypted end-to-end. This means that the content of the messages is not visible, not even to the messenger providers themselves. You should always use an up-to-date version of the messenger with encryption enabled to ensure the encryption of message content.

However, we would also like to point out to our communication partners that while the messenger providers cannot see the content, they can find out that and when communication partners communicate with us, and that technical information about the communication partners' devices and, depending on their device settings, location information (so-called metadata) are processed.

Legal Basis Information:If we request permission from communication partners before communicating with them via messenger, the legal basis for processing their data is their consent. Otherwise, if we do not request consent and they contact us on their own initiative, for example, we use messengers in relation to our contractual partners and during contract negotiations as a contractual measure. In the case of other interested parties and communication partners, we use them based on our legitimate interests in fast and efficient communication and in fulfilling the needs of our communication partners for communication via messenger. Furthermore, we would like to point out that we will not transmit the contact details you provide to the messenger service for the first time without your consent.

Revocation, Objection and Deletion: You can revoke your consent at any time and object to communication with us via Messenger at any time. In the case of communication via Messenger, we delete the messages in accordance with our general deletion policy (i.e., as described above, after the end of contractual relationships, in the context of archiving requirements, etc.) and otherwise as soon as we can assume that we have answered any inquiries from the communication partners, if no reference to a previous conversation is to be expected and no legal retention obligations prevent deletion.

Reservation of the right to refer to other communication channels: Finally, we would like to point out that, for your security, we reserve the right not to answer inquiries via messenger. This is the case, for example, if contractual details require special confidentiality or if a response via messenger does not meet formal requirements. In such cases, we will refer you to more appropriate communication channels.

  • Types of data processed: Contact data (e.g., email address, telephone numbers); Usage data (e.g., websites visited, interest in content, access times); Meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Affected persons: Communication partners.
  • Purposes of processing: Contact requests and communication; direct marketing (e.g., by email or post).
  • Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • Telegram: Messenger with end-to-end encryption; Service provider: Representative in the European Union: European Data Protection Office (EDPO), Avenue Huart Hamoir 71, 1030 Brussels, Belgium; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://telegram.org/. Privacy policy: https://telegram.org/privacy/de.

Video conferences, online meetings, webinars and screen sharing

We use third-party platforms and applications (hereinafter referred to as "conference platforms") for the purpose of conducting video and audio conferences, webinars, and other types of video and audio meetings (hereinafter collectively referred to as "conferences"). We comply with legal requirements when selecting conference platforms and their services.

Data processed by conference platforms: When participating in a conference, the conference platforms process the following personal data of the participants. The scope of processing depends, firstly, on which data is required for a specific conference (e.g., providing access data or full names) and, secondly, on which optional information is provided by the participants. In addition to processing for the purpose of conducting the conference, the conference platforms may also process participants' data for security purposes or service optimization. The processed data includes personal data (first name, last name), contact information (email address, telephone number), access data (access codes or passwords), profile pictures, information on professional position/function, the IP address of the internet connection, information on the participants' devices, their operating system, browser and its technical and language settings, information on the content of communication processes, i.e., entries in chats as well as audio and video data, and the use of other available functions (e.g., surveys). The content of communications is encrypted to the extent technically provided by the conference providers. If participants are registered as users on the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.

Logging and recordings: If text entries, participation results (e.g., from surveys), and video or audio recordings are logged, participants will be informed transparently in advance and asked for their consent if necessary.

Participant Data Protection Measures: Please refer to the data protection notices of the conference platforms for details on how your data is processed and select the optimal security and data protection settings for you within the platform's settings. Furthermore, please ensure data and privacy protection in the background of your recording for the duration of the video conference (e.g., by informing roommates, locking doors, and using the background blur function where technically possible). Links to the conference rooms and access data must not be shared with unauthorized third parties.

Legal Basis Information: If, in addition to the conference platforms, we also process user data and request users' consent to the use of the conference platforms or specific functions (e.g., consent to conference recordings), the legal basis for the processing is this consent. Furthermore, our processing may be necessary for the fulfillment of our contractual obligations (e.g., in participant lists, in the case of processing meeting results, etc.). Otherwise, user data is processed based on our legitimate interests in efficient and secure communication with our communication partners.

  • Types of data processed: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, telephone numbers); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Affected persons: Communication partners; users (e.g., website visitors, users of online services). Depicted persons.
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations; handling contact requests and communication. Office and organizational procedures.
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • Zoom: Conference and communication software; Service provider: Zoom Video Communications, Inc., 55 Almaden Blvd., Suite 600, San Jose, CA 95113, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://zoom.us; Privacy policy: https://explore.zoom.us/docs/de-de/privacy-and-legal.html Data Processing Agreement: (referred to as Global DPA). Basis for Third-Country Transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://zoom.us/docs/de-de/privacy-and-legal.html (referred to as Global DPA)).

Audio content

We use hosting and analytics services from service providers to offer our audio content for listening or downloading and to obtain statistical information on the access of the audio content.

  • Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Audience measurement (e.g., access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles). Provision of our online services and user-friendliness.
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • letscast.fm:Podcast hosting and statistical analysis of podcast downloads; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Service provider: Produktgenuss GmbH, Vereinsstraße 51, 20357 Hamburg, Germany; Website: https://letscast.fm/. Privacy policy: https://letscast.fm/privacy.

Cloudservices

We use software services accessible via the Internet and running on the servers of their providers (so-called "cloud services", also referred to as "Software as a Service") for storing and managing content (e.g. document storage and management, exchange of documents, content and information with specific recipients or publication of content and information).

Within this framework, personal data may be processed and stored on the providers' servers, insofar as this data is part of communication processes with us or is otherwise processed by us as set out in this privacy policy. This data may include, in particular, master data and contact details of users, data relating to transactions, contracts, other processes, and their content. The cloud service providers also process usage data and metadata, which they use for security purposes and service optimization.

If we use cloud services to provide forms or other documents and content to other users or publicly accessible websites, the providers may store cookies on users' devices for web analytics purposes or to remember user settings (e.g., in the case of media control).

  • Types of data processed: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, telephone numbers); content data (e.g., entries in online forms); usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Affected persons: Customers; employees (e.g., staff, applicants, former employees); prospective customers. Communication partners.
  • Purposes of processing: Office and organizational procedures. Information technology infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)).
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

Newsletters and electronic notifications

We only send newsletters, emails, and other electronic notifications (hereinafter "newsletters") with the recipient's consent or where legally permitted. If the content of a newsletter is specifically described during the registration process, this description is decisive for the user's consent. Otherwise, our newsletters contain information about our services and our company.

To subscribe to our newsletters, you generally only need to provide your email address. However, we may ask you to provide a name for personalized addressing in the newsletter, or other information if required for the purposes of the newsletter.

Double Opt-In Procedure: Registration for our newsletter is always carried out using a double opt-in procedure. This means that after registering, you will receive an email asking you to confirm your registration. This confirmation is necessary to prevent anyone from registering with someone else's email address. Newsletter registrations are logged to document the registration process in accordance with legal requirements. This includes storing the registration and confirmation times as well as the IP address. Changes to your data stored with the email service provider are also logged.

Erasure and Restriction of Processing:We may store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them, in order to be able to prove previously given consent. The processing of this data is limited to the purpose of defending against potential claims. An individual deletion request is possible at any time, provided that the prior existence of consent is confirmed. In the case of obligations to permanently respect objections, we reserve the right to store the email address solely for this purpose in a suppression list (so-called "blocklist").

The registration process is logged based on our legitimate interests for the purpose of documenting its proper execution. If we engage a service provider to send emails, this is done based on our legitimate interests in an efficient and secure email delivery system.

Content:Information about us, our services, promotions and offers.

  • Types of data processed: Inventory data (e.g., names, addresses); contact data (e.g., email addresses, telephone numbers); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status); usage data (e.g., websites visited, interest in content, access times).
  • Affected persons: Communication partners; users (e.g., website visitors, users of online services).
  • Purposes of processing: Direct marketing (e.g., by email or post). Provision of contractual services and fulfillment of contractual obligations.
  • Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Opt-out option:You can unsubscribe from our newsletter at any time, i.e., withdraw your consent or object to receiving further newsletters. You will find a link to unsubscribe at the end of each newsletter, or you can use one of the contact options listed above, preferably email.

Additional information on processing procedures, methods, and services:

  • Messung von Öffnungs- und Klickraten: Die Newsletter enthalten einen sogenannte „web-beacon“, d. h., eine pixelgroße Datei, die beim Öffnen des Newsletters von unserem Server, bzw., sofern wir einen Versanddienstleister einsetzen, von dessen Server abgerufen wird. Im Rahmen dieses Abrufs werden zunächst technische Informationen, wie Informationen zum Browser und Ihrem System, als auch Ihre IP-Adresse und der Zeitpunkt des Abrufs, erhoben.

    Diese Informationen werden zur technischen Verbesserung unseres Newsletters anhand der technischen Daten oder der Zielgruppen und ihres Leseverhaltens auf Basis ihrer Abruforte (die mit Hilfe der IP-Adresse bestimmbar sind) oder der Zugriffszeiten genutzt. Diese Analyse beinhaltet ebenfalls die Feststellung, ob die Newsletter geöffnet werden, wann sie geöffnet werden und welche Links geklickt werden. Diese Informationen werden den einzelnen Newsletterempfängern zugeordnet und in deren Profilen bis zu deren Löschung gespeichert. Die Auswertungen dienen uns dazu, die Lesegewohnheiten unserer Nutzer zu erkennen und unsere Inhalte an sie anzupassen oder unterschiedliche Inhalte entsprechend den Interessen unserer Nutzer zu versenden.

    Die Messung der Öffnungsraten und der Klickraten sowie Speicherung der Messergebnisse in den Profilen der Nutzer sowie deren weitere Verarbeitung erfolgen auf Grundlage einer Einwilligung der Nutzer.

    Ein getrennter Widerruf der Erfolgsmessung ist leider nicht möglich, in diesem Fall muss das gesamte Newsletterabonnement gekündigt, bzw. muss ihm widersprochen werden. In diesem Fall werden die gespeicherten Profilinformationen gelöscht; Rechtsgrundlagen:Einwilligung (Art. 6 Abs. 1 S. 1 lit. a) DSGVO).

  • Conditions for using free services:Consent to receive mailings may be a condition for using free services (e.g., access to certain content or participation in certain promotions). If users wish to use the free service without subscribing to the newsletter, please contact us.
  • ActiveCampaign:Email delivery and automation services; Service provider: ActiveCampaign, Inc., 1 N Dearborn, 5th Floor Chicago, Illinois 60602, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.activecampaign.com; Privacy policy: https://www.activecampaign.com/privacy-policy/. Basis for third-country transfers: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.activecampaign.com/legal/newscc).

Web analytics, monitoring and optimization

Web analytics (also known as "reach measurement") is used to evaluate visitor traffic to our online services and can include pseudonymous data on visitor behavior, interests, or demographic information such as age or gender. Reach analysis allows us, for example, to identify when our online services, their features, or content are most frequently used or encourage repeat visits. It also helps us understand which areas require optimization.

In addition to web analytics, we can also use testing procedures to, for example, test and optimize different versions of our online offering or its components.

Unless otherwise stated below, profiles—that is, data aggregated from a usage session—may be created for these purposes, and information may be stored in and retrieved from a browser or device. The data collected includes, in particular, visited websites and elements used therein, as well as technical information such as the browser and operating system used, and usage times. If users have consented to the collection of their location data by us or by the providers of the services we use, location data may also be processed.

Users' IP addresses are also stored. However, we use an IP masking procedure (i.e., pseudonymization by shortening the IP address) to protect users. Generally, no clear user data (such as email addresses or names) is stored for web analytics, A/B testing, and optimization; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.

  • Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta, communication and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Audience measurement (e.g., access statistics, recognition of returning visitors). Profiles with user-related information (creation of user profiles).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • Matomo (without cookies):Matomo is a privacy-friendly web analytics software that is used without cookies and recognizes returning users using a so-called "digital fingerprint," which is stored anonymously and changed every 24 hours. The "digital fingerprint" records user movements within our online services using pseudonymized IP addresses in combination with user-side browser settings, so that it is not possible to draw conclusions about the identity of individual users. The user data collected through the use of Matomo is processed only by us and is not shared with third parties. Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).Website: https://matomo.org/.

Presences in social networks (social media)

We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about ourselves.

Please note that user data may be processed outside the European Union. This may pose risks for users, as it could, for example, make it more difficult to enforce their rights.

Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, user profiles can be created based on usage patterns and the resulting user interests. These user profiles can then be used to display advertisements, both within and outside the networks, that are presumably relevant to the users' interests. For these purposes, cookies are typically stored on users' computers, recording their usage patterns and interests. Additionally, user profiles can also store data independently of the devices used by the users (especially if the users are members of the respective platforms and are logged in).

For a detailed description of the respective processing methods and the options for objecting (opt-out), we refer to the privacy policies and information provided by the operators of the respective networks.

Regarding requests for information and the assertion of data subject rights, we would like to point out that these can be most effectively addressed directly with the service providers. Only the providers have access to user data and can take appropriate action and provide information directly. However, should you require assistance, you can contact us.

  • Types of data processed: Contact data (e.g., email address, telephone numbers); Content data (e.g., entries in online forms); Usage data (e.g., websites visited, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Contact requests and communication; feedback (e.g., collecting feedback via online form). Marketing.
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • Instagram: Social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://www.instagram.com/. Privacy policy: https://instagram.com/about/legal/privacy.
  • Vimeo: Social network and video platform; Service provider: Vimeo Inc., Attention: Legal Department, 555 West 18th Street, New York, NY 10011, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://vimeo.com/. Privacy policy: https://vimeo.com/privacy.
  • YouTube: Social network and video platform;  Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;  Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR);  Privacy policy: https://policies.google.com/privacy; Basis for third-country transfer: EU-US Data Privacy Framework (DPF). Opt-out option: https://adssettings.google.com/authenticated.

Plugins and embedded functions as well as content

We integrate functional and content elements into our online services that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may include, for example, graphics, videos, or city maps (hereinafter collectively referred to as "content").

The integration of third-party content always requires that these providers process users' IP addresses, as they cannot send the content to users' browsers without them. The IP address is therefore necessary for displaying this content or these functions. We strive to use only content from providers who use IP addresses solely for content delivery. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. These pixel tags allow for the analysis of information such as visitor traffic on the pages of this website. The pseudonymized information can also be stored in cookies on users' devices and may include, among other things, technical information about the browser and operating system, referring websites, the time of visit, and other information about the use of our online services, as well as be combined with such information from other sources.

  • Types of data processed: Usage data (e.g., websites visited, interest in content, access times); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status); contact data (e.g., email addresses, telephone numbers); content data (e.g., entries in online forms).
  • Affected persons: Users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user-friendliness. Profiles with user-related information (creation of user profiles).
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • Vimeo video player: Integration of a video player; Service provider: Vimeo Inc., Attention: Legal Department, 555 West 18th Street, New York, NY 10011, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://vimeo.com; Privacy policy: https://vimeo.com/privacy Data Processing Agreement: https://vimeo.com/enterpriseterms/dpa. Basis for Third-Country Transfer: Standard Contractual Clauses (https://vimeo.com/enterpriseterms/dpa).

Management, organization and support tools

We use services, platforms, and software from other providers (hereinafter referred to as "third-party providers") for the purposes of organizing, managing, planning, and delivering our services. We comply with legal requirements when selecting third-party providers and their services.

Within this framework, personal data may be processed and stored on the servers of third-party providers. This may involve various types of data, which we process in accordance with this privacy policy. This data may include, in particular, master data and contact details of users, data relating to transactions, contracts, other processes, and their content.

If users are referred to third-party providers or their software or platforms in the course of communication, business, or other relationships with us, these third-party providers may process usage data and metadata for security, service optimization, or marketing purposes. We therefore ask you to review the privacy policies of the respective third-party providers.

  • Types of data processed: Content data (e.g., entries in online forms); Usage data (e.g., websites visited, interest in content, access times); Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, consent status); Contact data (e.g., email addresses, telephone numbers).
  • Affected persons: Communication partners; users (e.g., website visitors, users of online services).
  • Purposes of processing: Provision of contractual services and fulfillment of contractual obligations. Office and organizational procedures.
  • Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

Additional information on processing procedures, methods, and services:

  • Calendly: Online appointment scheduling and management; Service provider: Calendly LLC., 271 17th St NW, Ste 1000, Atlanta, Georgia, 30363, USA; Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); Website: https://calendly.com/de; Privacy policy: https://calendly.com/privacy Data Processing Agreement: https://calendly.com/dpa. Basis for Third-Country Transfers: Standard Contractual Clauses (https://calendly.com/dpa).

Changes and updates to the privacy policy

We ask that you regularly review the content of our privacy policy. We will update the privacy policy as soon as changes to our data processing activities make this necessary. We will inform you if any changes require action on your part (e.g., consent) or any other individual notification.

If we provide addresses and contact information for companies and organizations in this privacy policy, please note that the addresses may change over time and ask you to check the information before contacting them.