Personal data (hereinafter usually referred to as "data") is processed by us only as necessary and for the purpose of providing a functional and user-friendly website, including its content and the services offered therein.
Pursuant to Article 4(1) of Regulation (EU) 2016/679, i.e. the EU General Data Protection Regulation (hereinafter referred to only as "GDPR"), "processing" means any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
With the following data protection policy, we inform you in particular about the nature, scope, purpose, duration and legal basis of the processing of personal data, insofar as we decide either alone or jointly with others on the purposes and means of processing. In addition, we inform you below about the third-party applications we use for optimization purposes and to increase the usability quality, insofar as third parties process data as independent controllers.
Our Data Protection Policy is structured as follows:
I. Information about us as controllers
II. Rights of data subjects and users
III. Information on processing
I
The data controller for data processing on thiswebsite within the meaning of the General Data Protection Regulation (GDPR) andother data protection provisions is:
Backbone Art Deutschland GmbH
Große Hamburger Str. 32
10115 Berlin
Germany
Link to imprint: https://www.bkbn.com/de/impressum
Data Protection Officer:
Bugl & Kollegen Gesellschaft für Datenschutzund Informationssicherheit mbH
Alexander Bugl
Eifelstraße 55
93057 Regensburg
Germany
Email: kontakt@buglundkollegen.de
II
As a data subject, you have the following rightsunder the EU General Data Protection Regulation (GDPR):
III
Hosting and Server Log Files
The hosting services we use (services for operating and providing the website) serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, security services and technical maintenance services that we use for the purpose of operating this online offer.In this context, we or our hosting provider process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, prospects and visitors to this online offer on the basis of our legitimate interests in the efficient and secure provision of this online offer in accordance with Art. 6 para. 1 lit. f GDPR in conjunction with Art. 28 GDPR (conclusion of data processing agreement).
Contact
You have the option to contact us by email, telephone, contact form or letter, whereby personal data may be processed. We process your data to handle and process your request. We will not pass on your data to third parties without your consent.The legal basis for processing is our legitimate interest in effectively handling your request in accordance with Art. 6 para. 1 lit. f GDPR.
When contacting us by email, we store your email address and the information contained in the email. In the case of the contact form, in addition to the information in the contact form, your IP address is recorded in pseudonymized form. In the case of contact by letter, your sender address and the content of the letter are stored. In the case of contact by telephone, we record personal data depending on the individual case.We store your data until you request us to delete it or until the purpose of processing (processing your request) has been fulfilled.
Applications
If you apply for a job with us, your personal data will be processed. The legal basis for processing is Art. 6 para. 1 lit. b GDPR in connection with the implementation of pre-contractual measures. If your data is required after completion of the application process to defend against legal claims, processing is based on our legitimate interest in evidence obligations in accordance with Art. 6 para. 1 lit. f GDPR, for example in connection with the Equal Treatment Act.
We process the data that you have transmitted to us as part of your application and that we need to verify your suitability for the position concerned.The purposes of processing are the management of your application, evaluation of your suitability for the open position, and contact with you in connection with your application or with possible alternative positions.We delete your data after six months. If you have consented to being included in the applicant pool, we will delete it after two years. If your application leads to an employment relationship, we will store your data for the duration of your employment with us.
Account / Registration Function
If you create an account with us via our website, we will collect and store the data you entered during registration (e.g., your name, address or email address) exclusively for pre-contractual services, for contract fulfillment or for the purpose of customer care (e.g., to provide you with an overview of your previous orders with us). At the same time, we store the IP address and the date of your registration along with the time. This data is not passed on to third parties.As part of the registration process, your consent to this processing may be obtained and reference is made to this privacy policy. The data we collect is used exclusively for the provision of the customer account.If you consent to this processing, Art. 6 para. 1 lit. a) GDPR is the legal basis for processing.If the opening of the customer account also serves pre-contractual measures or contract fulfillment, the legal basis for this processing is Art. 6 para. 1 lit. b) GDPR.You can revoke your consent to the opening and maintenance of the customer account at any time with effect for the future in accordance with Art. 7 para. 3 GDPR. You only need to inform us of your revocation.The data collected in this respect will be deleted as soon as processing is no longer necessary. However, we must observe tax and commercial retention periods.
Orders and payment
On our ordering platform, you have the option to pay by credit card or by SEPA direct debit. We do not collect, store or transmit financial account data. Instead, we use the third-party provider Stripe to process our payments. For further information, we refer you to Stripe's privacy policy.
Subscription to Our Newsletter
You have the option to subscribe to our email newsletter, which we use to inform you about offers from our company.
The legal basis for sending the newsletter is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future, for example by using the "unsubscribe" link in each newsletter email, or by contacting the responsible party for data processing.
When registering, we may send you a double opt-in email to verify your email address. In addition to the data entered in the registration form, we process your IP address and the time of registration.
The purpose of data processing is exclusively the sending of our newsletter.The data stored in connection with the newsletter dispatch will be stored until you unsubscribe from the newsletter. Data that we have stored for other purposes remains unaffected by this.I
f you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you information about similar goods or services to those already purchased by email, provided you have not objected to this. Data processing is based on our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR in conjunction with § 7 para. 3 UWG.
Duration of storage
When using our website purely for information purposes, we only store your personal data for the duration of your visit. After leaving the website, this data is automatically deleted.
In the case of active use, e.g., to contact us, we initially store your personal data for the duration of processing your request. In addition, we retain the data as long as necessary to protect or enforce possible legal claims. The regular limitation period is 12 to 36 months, but in individual cases can be up to 30 years.
After the limitation period has expired, your data will be deleted unless there is a legal retention obligation. Such obligations arise in particular from the Commercial Code (§§ 238, 257 para. 4 HGB) or the Fiscal Code (§ 147 para. 3, 4 AO) and are generally between two and ten years.
Categories of Recipients
As part of our business activities, we work with various external parties. Personal data is only passed on to these recipients if this is necessary to fulfill contractual obligations, if we are legally obligated to do so (e.g., to tax authorities), if there is a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR, if you have given your consent in accordance with Art. 6 para. 1 lit. a GDPR, or if another legal basis permits the data transmission.If we use service providers as processors, personal data is only passed on the basis of a valid contract for data processing. In the case of joint responsibility, a contract for joint processing in accordance with Art. 26 GDPR is concluded.
For more information on the recipients used, please refer to the course of this privacy policy or you can contact the contact option provided above.
IIII
Data Transfer to Third Countries
Personal data is only transferred to countries outside the European Union (EU) or the European Economic Area (EEA) if this is necessary or legally permissible, if you have given us your express consent or as part of order processing.
If service providers are used in a third country, we oblige them through suitable guarantees – usually the EU standard contractual clauses – to comply with the level of data protection applicable in the EU. If there is an adequacy decision by the European Commission, we base the data transfer on this. For further information, please contact us using the contact details provided above.
Processing in the Context of Business Relations
We may process the personal data of our customers, prospects, suppliers, sellers and partners for communication, planning, execution of the contractual relationship, marketing, administration and security purposes.The legal basis for processing the data provided is our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR and contract fulfillment in accordance with Art. 6 para. 1 lit. b GDPR.
As part of the business relationship, we process contact information, billing information and payment data, other necessary information in a project or contractual relationship, or information that is voluntarily made available to us.
Cookiebot
We use the "Cookiebot" service on our website to manage cookie consent and ensure compliance with data protection regulations. Provider is Usercentrics GmbH Sendlinger Straße 7 80331 Munich, Germany.
The legal basis for the use of Cookiebot is the fulfillment of a legal obligation in accordance with Art. 6 para. 1 lit. c GDPR.
The data processed by Cookiebot includes your IP address, browser information, URL of the visited website, date and time of consent, a unique anonymous identifier, consent status, and cookies are set in your browser.
The purpose of data processing is the management of user consent regarding cookies and ensuring compliance with data protection regulations.According to Cookiebot's official privacy policy, the standard storage period for data processed by Cookiebot is 12 months.For more information on Cookiebot's privacy policy, please visit: https://www.cookiebot.com/en/privacy-policy/
CloudFlare
We use the 'Cloudflare' service on our website to improve security, performance and reliability. Provider is Cloudflare, Inc. ("Cloudflare"), 101 Townsend St., San Francisco, CA 94107, USA.
The legal basis for the use of Cloudflare is our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR to improve website performance, increase security and protect our website from malicious attacks.The data processed by Cloudflare includes your IP address, browser and device information, time and location of your visit, information on interaction with the website, and Cloudflare may set cookies.
The purpose of data processing is to improve website security, optimize performance and protect against malicious traffic.Cloudflare states that logs are stored for up to 12 months by default. This information can be found in Cloudflare's privacy policy in the 'Data retention' section at: https://www.cloudflare.com/privacypolicy/
It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. Cloudflare is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA. We have concluded a data processing agreement (DPA) with Cloudflare, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR.
For more information on Cloudflare's privacy policy, please visit:
https://www.cloudflare.com/privacypolicy/
For information on cookies set, please visit:
https://www.cloudflare.com/cookie-policy/
fontawesome.com
We use the "Font Awesome" service on our website to uniformly integrate icons and visual elements. Provider is Fonticons, Inc. ("Fonticons"), 307 S Main St, Suite 202, Bentonville, AR 72712, USA.
The legal basis for the use of Font Awesome is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by Font Awesome includes your IP address, browser and device information, and information about your use of the website; Font Awesome does not set cookies.The purpose of data processing is the optimized provision and integration of icons and fonts to improve the user-friendliness and design of the website.
It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a data processing agreement (DPA) with Fonticons, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR.
For more information on Font Awesome's privacy policy, please visit: https://fontawesome.com/privacy
Google Ads Conversion Tracking
We use the "Google Ads Conversion Tracking" service on our website to measure the effectiveness of our advertising campaigns. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.The legal basis for the use of Google Ads Conversion Tracking is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.
The data processed by Google Ads Conversion Tracking includes your IP address, browser and device information, details of ad interactions, and sets cookies to track conversions.
If you are logged into a Google account, data from Google Ads Conversion Tracking may be linked to a user profile.
The purpose of data processing is to measure the effectiveness of advertising campaigns and track user interactions after clicking on advertisements.It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a data processing agreement (DPA) with Google, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR. Google is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA.
For more information on Google Ads Conversion Tracking's privacy policy, please visit: https://policies.google.com/privacy
Google Analytics
We use the "Google Analytics" service on our website to evaluate user behavior. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.The legal basis for the use of Google Analytics is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by Google Analytics includes your IP address, browser and device information, location data, time of visit, information on interaction with the website, and cookies are set.
If you are logged into a Google account, this data may be linked to a user profile.The purpose of data processing is the analysis and evaluation of user behavior to optimize the website and marketing measures.
The standard data retention period for Google Analytics is 14 months.It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. Google is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA. We have concluded a data processing agreement (DPA) with Google, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR.
For more information on Google Analytics'privacy policy, please visit: https://support.google.com/analytics/topic/2919631?hl=en&ref_topic=1008008,3544742,2986333,&sjid=1881441919987619365-EU
For information on cookies set, please visit:
https://policies.google.com/technologies/cookies
You can prevent the processing of your data byclicking this link: https://tools.google.com/dlpage/gaoptout
Google Universal Analytics
We use the "Google Analytics" service on our website to evaluate user behavior. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.The legal basis for the use of Google Universal Analytics is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.
The data processed by Google Analytics includes your IP address, browser and device information, location data, time of visit, information on interaction with the website, and cookies are set.
If you are logged into a Google account, this data may be linked to a user profile.The purpose of data processing is the analysis and evaluation of user behavior to optimize the website and marketing measures.
The standard data retention period for Google Analytics is 2 months.It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a data processing agreement (DPA) with Google, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR. Google is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA.
For more information on Google Universal Analytics' privacy policy, please visit: https://support.google.com/analytics/topic/2919631?hl=en&ref_topic=1008008,3544742,2986333,&sjid=1881441919987619365-EU
For information on cookies set, please visit: https://policies.google.com/technologies/cookies
You can prevent the processing of your data by clicking this link: https://tools.google.com/dlpage/gaoptout
Google Fonts
We use the "Google Fonts" service on our website to integrate external fonts for improved visual presentation. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
The legal basis for the use of Google Fonts is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by Google Fonts includes your IP address, browser and device information, and the time of the request.The purpose of data processing is the optimized and uniform presentation of fonts on the website.
It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. Google is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA.
For more information on Google Fonts' privacy policy, please visit: https://policies.google.com/privacy
For information on cookies set, please visit: https://policies.google.com/technologies/cookies
You can prevent the processing of your data by clicking this link: https://policies.google.com/privacy#infochoices
Google Maps
We use the "Google Maps" service on our website to visually display geographic information and provide directions. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.The legal basis for the use of Google Maps is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by Google Maps includes your IP address, location data, device information, browser details, usage data, and cookies may be set.If you are logged into a Google account, Google Maps data may be linked to a user profile.
The purpose of data processing is the display of interactive maps and the provision of location-based services for users.It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a data processing agreement (DPA) with Google, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR. Google is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA.
For more information on Google Maps' privacy policy, please visit: https://policies.google.com/privacy#infocollect
Google Tag Manager
We use the "Google Tag Manager" service on our website to efficiently manage website tags. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
The legal basis for the use of Google Tag Manager is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.
The data processed by Google Tag Manager includes your IP address, browser and device information, and information on interaction with the website; Google Tag Manager itself does not set cookies, but can trigger other services that set cookies.The purpose of data processing is the simplified integration and management of website tags and tracking codes for analyzing user interactions.
For more information on Google Tag Manager's privacy policy, please visit: https://policies.google.com/privacy
For information on cookies set, please visit: https://policies.google.com/technologies/cookiesYou can prevent the processing of your data by clicking this link: https://tools.google.com/dlpage/gaoptout
YouTube
We use the video service "Youtube" on our website. Provider of the service is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.The legal basis for the use of Youtube is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.Google collects and processes your IP address, browser and operating system information and location data, and actions such as watching videos or creating playlists are also processed. Additional cookies are also set. Youtube integrates other Google services such as Google Fonts, Google Photos and Google Ads (formerly Doubleclick).If you are logged into a Google account, this data can be linked to a user profile. Your user behavior is recorded and analyzed for advertising purposes.The purpose of data processing is the provision of video content and its integration on our website.
According to Google's privacy policy, the storage period for data processed by YouTube varies depending on the type of data and user settings. By default, activity data (such as watched videos, search history, etc.) for new accounts or users who have not previously set a storage period is automatically deleted after 36 months (3 years). Users can manually set this storage period to 3 months, 18 months, or permanently store the data.
For detailed information, please visit: https://policies.google.com/privacy?hl=de#inforetainingIt cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. Google is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA. We have concluded a data processing agreement (DPA) with Google, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR.
For more information on Youtube's privacy policy, please visit: https://policies.google.com/privacy
For information on cookies set, please visit: https://policies.google.com/technologies/cookiesYou can prevent the processing of your data by clicking this link: https://myaccount.google.com/data-and-privacy
Youtube NoCookie
We use the Youtube NoCookie service (also known as "YouTube in enhanced privacy mode") on our website to embed videos without using cookies that track user behavior. Provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
The legal basis for the use of Youtube NoCookie is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by Youtube NoCookie includes your IP address, device information and information on video interaction. Data is stored in the browser's web storage.The purpose of data processing is the embedding of videos while minimizing cookie use and improving user privacy.
It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a data processing agreement (DPA) with Google, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR. Google is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA.
For more information on Youtube NoCookie's privacy policy, please visit: https://policies.google.com/privacy#infocollect
For information on cookies set, please visit: https://policies.google.com/technologies/cookiesYou can prevent the processing of your data by clicking this link: https://policies.google.com/privacy#infochoices
Hotjar
We use the "Hotjar" service on our website to analyze user behavior and improve the user experience. Provider is Hotjar Ltd. ("Hotjar"), Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian's STJ 3141, Malta.
The legal basis for the use of Hotjar is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by Hotjar includes your IP address (stored anonymized), device information, browser information, geographic location (country only), language settings, referring URL, date and time of visit, and information on interaction with the website; Hotjar also sets cookies in your browser.Hotjar may collect data to create user profiles based on user interactions with the website.
The purpose of data processing is the statistical analysis of user behavior and the creation of anonymous user profiles.Hotjar stores user data for 365 days (12 months) by default.
For more information on Hotjar's privacy policy, please visit: https://www.hotjar.com/legal/policies/privacy/
You can prevent the processing of your data by clicking this link: https://www.hotjar.com/policies/do-not-track/
LinkedIn Insight Tag
We use the "LinkedIn Insight Tag" service on our website to analyze user behavior and measure the effectiveness of our advertising measures. Provider is LinkedIn Ireland Unlimited Company ("LinkedIn"), Wilton Plaza, Wilton Place, Dublin 2, Ireland.The legal basis for the use of LinkedIn Insight Tag is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by LinkedIn Insight Tag includes your IP address, device and browser information, page events and information on interaction with the website; the service also uses cookies.LinkedIn Insight Tag collects data that can be used to create user profiles for targeted advertising purposes.
The purpose of data processing is the analysis of advertising effectiveness, tracking conversions and creating anonymous user profiles for targeted marketing.The data from the LinkedIn Insight Tag is stored by LinkedIn for 180 days by default.It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. LinkedIn is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA. We have concluded a data processing agreement (DPA) with LinkedIn, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR.
For more information on LinkedIn Insight Tag's privacy policy, please visit: https://www.linkedin.com/legal/privacy-policy
For information on cookies set, please visit: https://www.linkedin.com/legal/cookie-policy
Bootstrap CDN
We use the 'Bootstrap CDN' service on our website to efficiently provide Bootstrap libraries and related resources. The provider is Volentio JSD Limited ("Volentio"), Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB, United Kingdom.The legal basis for the use of BootstrapCDN is our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR to ensure the efficient and reliable provision of website content and to improve the loading speed and user experience of our website.The data processed by Bootstrap CDN includes your IP address, browser type, operating system, and the time and date of your request; Bootstrap CDN may also set cookies to optimize content delivery.
The purpose of data processing is to provide website resources efficiently and securely by loading Bootstrap libraries via a content delivery network.
For more information on BootstrapCDN's privacy policy, please visit: https://www.bootstrapcdn.com/privacy-policy/
Amazon CloudFront
We use the "Amazon CloudFront" service on our website to efficiently provide content and improve website performance. Provider is Amazon EU S.à r.l. ("Amazon"), 38 avenue John F. Kennedy, L-1855 Luxembourg.The legal basis for the use of Amazon CloudFront is our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR to optimize the performance and loading speed of our website content and to improve the user experience.The data processed by Amazon CloudFront includes your IP address, location, time of visit, device information, information on interaction with the website, and cookies may be set to optimize content delivery.
The purpose of data processing is the efficient provision and optimization of website content via a global content delivery network (CDN).It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a data processing agreement (DPA) with Amazon, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR. Amazon is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA.
For more information on Amazon CloudFront's privacy policy, please visit: https://aws.amazon.com/compliance/data-privacy-faq/
Calendly
We use the "Calendly" service on our website to efficiently schedule appointments and meetings. Provider is Calendly LLC ("Calendly"), 271 17th Street NW, Suite 1000, Atlanta, GA 30363, USA.The legal basis for the use of Calendly is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by Calendly includes your IP address, browser information, device information, appointment scheduling data, and cookies are set to improve the user experience.
The purpose of data processing is the efficient scheduling of appointments and meetings through managing calendar availability and bookings.It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a Data Processing Addendum with Calendly, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR. Calendly is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA.
For more information on Calendly's privacy policy, please visit: https://calendly.com/privacy
Stripe
We use the "Stripe" service on our website to process payments. The provider is Stripe Payments Europe, Limited ("Stripe"), 1 Grand Canal Street Lower Grand Canal Dock, Dublin, D02 H210, Ireland.The legal basis for the use of Stripe is our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR for the secure and efficient processing of payments and transactions on our website.
The data processed by Stripe includes your IP address, payment data, transaction information, device information, browser type, operating system, and sets cookies for authentication and fraud prevention purposes.The purpose of data processing is the processing of secure payment transactions and the management of payment-related activities.Stripe stores your personal data for as long as necessary to provide the services. Even after the completion of a transaction or the closure of an account, certain data may continue to be stored, for example to comply with legal obligations, prevent fraud, or fulfill tax and accounting requirements. Stripe complies with applicable legal retention periods.
For more information on Stripe's privacy policy, please visit: https://stripe.com/en-de/privacy
For information on cookies set, please visit: https://stripe.com/en-de/legal/cookies-policy
unpkg
We use the 'unpkg' service on our website to provide JavaScript libraries and other static resources. unpkg is an open-source project operated by the companies Cloudflare (101 Townsend St., San Francisco, CA 94107, USA) and Heroku/Salesforce (One Market Street, Suite 300, San Francisco, CA 94105, USA). It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a data processing agreement (DPA) with Cloudflare and Salesforce, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR. Cloudflare and Salesforce are certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA.
The legal basis for the use of unpkg is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by unpkg includes your IP address, request details and browser information; unpkg does not set cookies.The purpose of data processing is the provision of JavaScript libraries and other static content via a content delivery network to improve website performance.
For more information on unpkg's privacy policy, please visit: https://www.unpkg.com/privacy-policy
Vimeo
We use the "Vimeo" service on our website to embed and display video content. The provider is Vimeo.com, Inc. ("Vimeo"), 555 West 18th Street, New York, New York 10011, USA.
The legal basis for the use of Vimeo is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by Vimeo includes your IP address, browser and device information, referring website, video call activities, and Vimeo uses cookies.If you are logged into your Vimeo account, Vimeo may link this data to your user profile.The purpose of data processing is the embedding of video content, analyzing user interactions with videos and improving the user experience.It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a data processing agreement (DPA) with Vimeo, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR. Vimeo is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA.
For more information on Vimeo's privacy policy, please visit: https://vimeo.com/privacy
For information on cookies set, please visit: https://vimeo.com/cookie_policy
jsDelivr
We use the 'jsDelivr' service on our website to provide and optimize static content such as JavaScript libraries and CSS files. The provider is Volentio JSD Limited ("Volentio"), Suite 2a1, Northside House, Mount Pleasant, Barnet, England, EN4 9EB, United Kingdom.The legal basis for the use of jsDelivr is our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR to ensure the fast and reliable provision of website resources and to improve the performance and user experience of our website.The data processed by jsDelivr includes your IP address, browser type, operating system, and request details such as the time and requested content; jsDelivr does not set cookies.The purpose of data processing is the efficient provision of website resources such as JavaScript libraries via a content delivery network (CDN).For more information on jsDelivr's privacy policy, please visit: https://www.jsdelivr.com/terms/privacy-policy
Webflow
We use the 'Webflow' service on our website to design, create and host our web pages. The provider is Webflow, Inc. ("Webflow"), 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA.
The legal basis for the use of Webflow is our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR to provide an attractive and user-friendly website through the use of modern web design and hosting services.The data processed by Webflow includes your IP address, device and browser information, usage data such as pages visited and actions taken, and may include cookies for functionality and analytics purposes.The purpose of data processing is the provision of website creation, hosting and content management services, including the storage and management of website data and user interactions.
It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. Webflow is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA. We have concluded a data processing agreement (DPA) with Webflow, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR.
For more information on Webflow's privacy policy, please visit: https://webflow.com/legal/privacy
For information on cookies set, please visit: https://webflow.com/legal/cookie-policy
Social Media Profiles
We maintain online profiles on the following social networks (hereinafter "Social Media") to communicate with customers, prospects and the public and to draw attention to our services:· Instagram (Meta Platforms, Inc.)
· Facebook (Meta Platforms, Inc.)
· X (formerly Twitter; X Corp.)
· LinkedIn (LinkedIn Ireland Unlimited Company)
· Xing (New Work SE)
For the scope and purpose of data processing, we refer to the applicable privacy policies of the networks:·
Instagram: (https://privacycenter.instagram.com/policy)
· Facebook: (https://www.facebook.com/privacy/policy/?entry_point=facebook_page_footer)
· X (Twitter): (https://x.com/de/privacy)
· LinkedIn: (https://de.linkedin.com/legal/privacy-policy?)
· Xing: (https://privacy.xing.com/de/datenschutzerklaerung)
Processing is based on Art. 6 para. 1 lit. f GDPR, as we have a legitimate interest in contemporary public relations. If consent is required, processing is based on Art. 6 para. 1 lit. a GDPR.
If you transmit additional data to the services (e.g., personal messages), your consent is usually required. Please note that we have no influence on data processing by social media providers. If you have questions or wish to exercise your rights as a data subject (e.g., information, deletion), please contact the respective platform operator directly.You can subscribe or unsubscribe from our social media profiles at any time. If you do not want social media service operators to collect data about your visit to our profiles, please use the deactivation options (e.g., logout, ad tracker blocking) in your user account or install corresponding browser add-ons.
Matterport
We use the 'Matterport' service on our website to provide interactive 3D tours of our spaces. The provider is Matterport, Inc. ("Matterport"), 352 East Java Drive, Sunnyvale, CA 94089, USA.
The legal basis for the use of Matterport is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can revoke your consent at any time with effect for the future.The data processed by Matterport includes your IP address, device and browser information, location data, usage data, and information about your interactions with 3D spaces; the service may also set cookies.
The purpose of data processing is to create and display interactive 3D tours of physical spaces and to analyze user interactions with these tours.It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. We have concluded a data processing agreement (DPA) with Matterport, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR. Matterport uses so-called standard contractual clauses, which are intended to ensure that your data also complies with European data protection standards when it is transferred to and stored in third countries.
For more information on Matterport's privacy policy, please visit: https://matterport.com/legal/privacy-policy
Pardot
We use the 'Pardot' service on our website to manage and analyze marketing campaigns and user interactions. The provider is Salesforce, Inc. ("Salesforce"), One Market Street, Suite 300, San Francisco, CA 94105, USA.The legal basis for the use of Pardot is our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR to analyze user interactions and improve the effectiveness of our marketing activities.
The data processed by Pardot includes your IP address, contact data, device information, website interactions and email interaction data; the service may set cookies to track user behavior.
Pardot collects data to create user profiles for marketing and lead generation purposes.The purpose of data processing is the management and analysis of marketing campaigns, tracking user interactions and creating lead profiles for targeted marketing.It cannot be ruled out that personal data may be transferred to unsafe third countries (USA) where there is a lower level of data protection than in the EU. Salesforce is certified under the EU-US Data Privacy Framework, which regulates the secure data processing of EU citizens in the USA. We have concluded a data processing agreement (DPA) with Salesforce, which ensures that personal data is only processed according to our instructions and in compliance with the GDPR.
For more information on Pardot's privacy policy, please visit: https://www.salesforce.com/company/legal/privacy/
For information on cookies set, please visit: https://help.salesforce.com/s/articleView?id=mktg.pardot_basics_cookies.htm&type=5
Finsweet
We use "Finsweet" – a collection of tools for Webflow – to extend website functionality (e.g., filters, CMS utilities). Provider: Finsweet LLC, 8 The Green, Suite 4000, Dover, DE 19901, USA. Legal basis for data transfer to the USA is your consent in accordance with Art. 6 para. 1 lit. a GDPR (revocable).
Processed data: IP address, browser/device information, technical usage data; retrieval of Finsweet assets (possibly via CDNs). Finsweet generally does not set cookies; individual modules may use cookies/web storage.Data transfer to the USA is possible; we use appropriate safeguards (in particular EU standard contractual clauses).
For more information: https://www.finsweet.com/privacy"Cookies (if used): see cookie overview/consent tool."
Use of Floorfy
We integrate content from Floorfy, S.L., Barcelona, Spain ("Floorfy") on our website to provide 360° tours, virtual staging and renderings. When accessing the relevant pages, a connection to Floorfy's servers is established to ensure fast and stable provision of the tour assets during use. Technically required data (e.g., IP address, browser and device information) may be transmitted. Floorfy may use cookies or similar technologies for this purpose.
The integration is based on our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR to provide high-quality and interactive presentations of our offer. If consent is required, processing is carried out exclusively in accordance with Art. 6 para. 1 lit. a GDPR.
IP Location API
We use "ipapi.co" for the technical processing of API requests that are necessary for certain functions of our website (e.g., localization/country utilities in forms), for reliable provision of functionality through API requests. When using our services, the following data is processed to provide stable and reliable functionality: IP address, browser and device information, timestamps and requested resources. The service ipapi.co (also known as "ipapi") is operated by Kloudend, Inc., a company based in Henderson, Nevada, USA (1887 Whitney Mesa Dr #4080)
The lawfulness of data transfer to the USA is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR.
Restcountries
We use "restcountries.com" to retrieve country/region information to correctly display forms and content and to provide reliable country metadata for the functionality of the website. The country data API restcountries.com is operated by apilayer Data Products GmbH, Oppolzergasse 6/1/4, 1010 Vienna, Austria.
Data processing is based on our legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR; if data is processed beyond what is technically necessary, it is based on consent in accordance with Art. 6 para. 1 lit. a GDPR.
decareto Privacy Widget
We use the "decareto Privacy Widget" service on our website to create and manage our privacy notices. Provider is decareto GmbH, Mittelweg 144, 20148 Hamburg, Germany ("decareto"). As part of the service provision, decareto uses the content delivery network bunny.net of the subcontractor BunnyWay d.o.o. (Slovenia) to deliver content reliably and quickly.
The legal basis for the use of decareto Privacy Widget is the fulfillment of a legal obligation in accordance with Art. 6 para. 1 lit. c GDPR.The legal basis for the use of bunny.net is decareto's legitimate interest in the error-free delivery of privacy notices. The data processed by decareto Privacy Widget and bunny.net includes your IP address and browser information. The services do not set cookies. Data is not stored in log files.The purpose of data processing is the reliable provision of our privacy notices.For more information on decareto Privacy Widget's privacy policy, please visit: https://decareto.com/privacy/