Privacy Policy (Datenschutzerklärung)

Our privacy notice for clients of POINTNER finanz is available here (PDF, currently available in German only).

1. Data protection at a glance

General information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on the subject of data protection can be found in the privacy policy set out below this text.

Data collection on this website

Who is responsible for the data collection on this website?

Data processing on this website is carried out by the website operator. You will find the operator’s contact details in the section “Information on the controller” in this privacy policy.

How do we collect your data?

Your data is collected, on the one hand, when you provide it to us. This may, for example, be data you enter into a contact form.

Other data is collected automatically, or with your consent, by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or time of the page view). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected in order to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour. Insofar as contracts can be concluded or initiated via the website, the transmitted data is also processed for contract offers, orders or other enquiries.

What rights do you have regarding your data?

You have the right at any time to obtain information free of charge about the origin, recipients and purpose of your stored personal data. You also have a right to request the rectification or erasure of this data. If you have given consent to data processing, you may withdraw this consent at any time with effect for the future. In addition, you have the right, under certain circumstances, to request the restriction of the processing of your personal data. You also have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time regarding this and any further questions on the subject of data protection.

Analysis tools and third-party tools

When you visit this website, your browsing behaviour may be evaluated statistically. This is done primarily by means of so-called analysis programmes.

Detailed information on these analysis programmes can be found in the privacy policy below.

2. Hosting

We host the content of our website with the following provider:

External hosting

This website is hosted externally. The personal data collected on this website is stored on the servers of the host(s). This may primarily involve IP addresses, contact enquiries, meta and communication data, contract data, contact details, names, website access data and other data generated via a website.

External hosting is carried out for the purpose of contract performance towards our potential and existing clients (Art. 6(1)(b) of the General Data Protection Regulation, GDPR/DSGVO) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6(1)(f) GDPR). Insofar as corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 165(3) of the Austrian Telecommunications Act 2021 (§ 165 Abs. 3 TKG 2021), where the consent covers the storage of cookies or access to information on the user’s terminal equipment (e.g. device fingerprinting) within the meaning of the TKG 2021. Consent may be withdrawn at any time.

Our host(s) will process your data only to the extent necessary to fulfil its performance obligations and will follow our instructions with regard to this data.

We use the following host:

ALL-INKL.COM
Hauptstraße 68
D-02742 Friedersdorf, Germany

Data processing agreement

We have concluded a data processing agreement (Auftragsverarbeitungsvertrag, AVV) for the use of the above-mentioned service. This is a contract required by data protection law which ensures that the processor processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Cloudflare (planned)

We use the service “Cloudflare”. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter “Cloudflare”).

Cloudflare offers a globally distributed content delivery network with DNS. Technically, the transfer of information between your browser and our website is routed through Cloudflare’s network. This enables Cloudflare to analyse the data traffic between your browser and our website and to act as a filter between our servers and potentially malicious traffic from the internet. In doing so, Cloudflare may also use cookies or other technologies for the recognition of internet users, which are, however, used solely for the purpose described here.

The use of Cloudflare is based on our legitimate interest in providing our web offer as error-free and securely as possible (Art. 6(1)(f) GDPR).

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details and further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/.

The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5666.

3. General information and mandatory disclosures

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection provisions and this privacy policy.

When you use this website, various items of personal data are collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We point out that data transmission over the internet (e.g. when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.

Information on the controller

The controller responsible for data processing on this website is:

AP Pointner Finanz Ltd. & Co KG
Molkereistraße 4
A-4910 Ried im Innkreis, Austria
Telephone: +43 7752 26614-15
Email: info@pointnerfinanz.com

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses or similar).

Storage period

Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose of the data processing no longer applies. If you assert a justified request for erasure or withdraw your consent to data processing, your data will be deleted, unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, deletion takes place once those grounds no longer apply.

General information on the legal bases for data processing on this website

Insofar as you have consented to the data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, where special categories of data pursuant to Art. 9(1) GDPR are processed. In the case of express consent to the transfer of personal data to third countries, the data processing is additionally based on Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your terminal equipment (e.g. via device fingerprinting), the data processing is additionally based on § 165 Abs. 3 TKG 2021. Consent may be withdrawn at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data where this is necessary for compliance with a legal obligation, on the basis of Art. 6(1)(c) GDPR. Data processing may also be based on our legitimate interest pursuant to Art. 6(1)(f) GDPR. Information on the legal bases relevant in each individual case is provided in the following paragraphs of this privacy policy.

Note on data transfer to third countries that are not secure under data protection law, and on transfer to US companies that are not DPF-certified

Among other things, we use tools from companies based in third countries that are not secure under data protection law, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in these countries. We point out that in third countries that are not secure under data protection law, a level of data protection comparable to that in the EU cannot be guaranteed.

We point out that the USA, as a secure third country, generally has a level of data protection comparable to that of the EU. A data transfer to the USA is therefore permissible if the recipient holds a certification under the “EU-US Data Privacy Framework” (DPF) or has appropriate additional safeguards in place. Information on transfers to third countries, including the data recipients, can be found in this privacy policy.

Recipients of personal data

In the course of our business activities we work together with various external bodies. In some cases this also requires the transfer of personal data to these external bodies. We only pass personal data on to external bodies where this is necessary within the scope of contract performance, where we are legally obliged to do so (e.g. transfer of data to tax authorities), where we have a legitimate interest in the transfer pursuant to Art. 6(1)(f) GDPR, or where another legal basis permits the data transfer. Where processors are used, we only pass on the personal data of our clients on the basis of a valid data processing agreement. In the case of joint processing, a joint controllership agreement is concluded.

Withdrawal of your consent to data processing

Many data processing operations are only possible with your express consent. You may withdraw consent already given at any time. The lawfulness of the data processing carried out up to the point of withdrawal remains unaffected by the withdrawal.

Right to object to data collection in particular cases and to direct marketing (Art. 21 GDPR)

IF THE DATA PROCESSING IS BASED ON ART. 6(1)(e) OR (f) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS CONNECTED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.

The competent supervisory authority for us is:

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna, Austria
Email: dsb@dsb.gv.at
https://www.dsb.gv.at/

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.

Information, rectification and erasure

Within the framework of the applicable statutory provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients and the purpose of the data processing and, where applicable, a right to rectification or erasure of this data. You may contact us at any time regarding this and any further questions on the subject of personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You may contact us at any time for this purpose. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of the personal data we hold about you, we generally require time to verify this. For the duration of the verification, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was or is unlawful, you may request the restriction of the data processing instead of erasure.
  • If we no longer need your personal data but you require it for the exercise, defence or establishment of legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
  • If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of your interests and ours must be carried out. As long as it has not been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data may — apart from being stored — only be processed with your consent or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State.

SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the padlock symbol in your browser line.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Objection to promotional emails

The use of contact data published within the framework of the imprint obligation for the purpose of sending advertising and information material that has not been expressly requested is hereby prohibited. The operators of these pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by means of spam emails.

4. Data collection on this website

Cookies

Our web pages use so-called “cookies”. Cookies are small data packages and do no damage to your terminal equipment. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.

Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services of third-party companies within web pages (e.g. cookies for handling payment services).

Cookies have various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping basket function or the display of videos). Other cookies may be used to evaluate user behaviour or for advertising purposes.

Cookies that are necessary to carry out the electronic communication process, to provide certain functions you have requested (e.g. the shopping basket function) or to optimise the website (e.g. cookies for measuring the web audience) — necessary cookies — are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is stated. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimised provision of its services. Insofar as consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of that consent (Art. 6(1)(a) GDPR and § 165 Abs. 3 TKG 2021); consent may be withdrawn at any time.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when the browser is closed. If cookies are deactivated, the functionality of this website may be limited.

You can find out which cookies and services are used on this website in this privacy policy.

Consent with Borlabs Cookie

Our website uses the consent technology of Borlabs Cookie in order to obtain your consent to the storage of certain cookies in your browser or to the use of certain technologies, and to document this in compliance with data protection law. The provider of this technology is Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany (hereinafter “Borlabs”).

When you enter our website, a Borlabs cookie is stored in your browser in which the consent you have given, or the withdrawal of that consent, is recorded. This data is not passed on to the provider of Borlabs Cookie.

The data collected is stored until you ask us to delete it, until you delete the Borlabs cookie yourself, or until the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected. Details of the data processing by Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/.

The Borlabs Cookie consent technology is used in order to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6(1)(c) GDPR.

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • browser type and browser version
  • operating system used
  • referrer URL
  • host name of the accessing computer
  • time of the server request
  • IP address

This data is not merged with other data sources.

The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and the optimisation of its website — for this purpose, the server log files must be recorded.

Contact and enquiry forms (Fluent Forms)

For the contact and enquiry forms on this website we use the software Fluent Forms from the provider WPManageNinja LLC. The software is installed locally on our web server (see the section “Hosting”); no external form service is integrated, and no transfer to the manufacturer of the software takes place.

If you send us enquiries via a form, your details from the enquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on this data without your consent. Where your enquiry is transferred to our customer relationship management system, please see the section “Transfer of form and booking data to our CRM system” below.

The processing of this data is based on Art. 6(1)(b) GDPR, insofar as your enquiry is connected with the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent may be withdrawn at any time.

The data you enter in the form remains with us until you ask us to delete it, until you withdraw your consent to storage, or until the purpose for storing the data no longer applies (e.g. after your enquiry has been dealt with). Mandatory statutory provisions — in particular retention periods — remain unaffected.

Enquiry by email, telephone or fax

If you contact us by email, telephone or fax, your enquiry, including all personal data arising from it (name, enquiry), will be stored and processed by us for the purpose of dealing with your request. We do not pass on this data without your consent.

The processing of this data is based on Art. 6(1)(b) GDPR, insofar as your enquiry is connected with the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if this has been requested; consent may be withdrawn at any time.

The data you send us via contact enquiries remains with us until you ask us to delete it, until you withdraw your consent to storage, or until the purpose for storing the data no longer applies (e.g. after your request has been dealt with). Mandatory statutory provisions — in particular statutory retention periods — remain unaffected.

Appointment booking with FluentBooking

On our website you have the option of arranging appointments with us. For appointment booking we use the software FluentBooking from the provider WPManageNinja LLC. The software is installed locally on our web server (see the section “Hosting”); no external booking service provider is integrated.

For the purpose of booking an appointment, you enter the requested data (e.g. name, email address, telephone number, and where applicable your request) and your preferred appointment into the form provided. The data entered is used for the planning, conduct and, where applicable, the follow-up of the appointment. It is stored on our own server; no transfer to the manufacturer of the software takes place. For appointment management we transfer the appointment data to our Google Calendar (see the section “Google Calendar”). For online consultations we use Google Meet (see the section “Audio and video conferences”).

The data you enter remains with us until you ask us to delete it, until you withdraw your consent to storage, or until the purpose for storing the data no longer applies. Mandatory statutory provisions — in particular retention periods — remain unaffected.

The legal basis for the data processing is Art. 6(1)(b) GDPR, insofar as the appointment arrangement is connected with the initiation or performance of a contract, and otherwise Art. 6(1)(f) GDPR. The website operator has a legitimate interest in arranging appointments with prospective and existing clients as simply as possible.

Google Calendar

For the planning of appointments we use Google Calendar. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”).

The appointment data is stored for us on the servers of Google Calendar; you can view Google’s privacy policy here: https://policies.google.com/privacy.

The data you enter remains with us until you ask us to delete it, until you withdraw your consent to storage, or until the purpose for storing the data no longer applies. Mandatory statutory provisions — in particular retention periods — remain unaffected.

The legal basis for the data processing is Art. 6(1)(f) GDPR. The website operator has a legitimate interest in arranging appointments with prospective and existing clients as simply as possible. Insofar as corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 165 Abs. 3 TKG 2021, where the consent covers the storage of cookies or access to information on the user’s terminal equipment (e.g. for device fingerprinting) within the meaning of the TKG 2021. Consent may be withdrawn at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://workspace.google.com/terms/dpa_terms.html and here: https://cloud.google.com/terms/sccs.

The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

Transfer of form and booking data to our CRM system

This website (pointnerfinanz.com) and our German-language website pointnerfinanz.at are both operated by AP Pointner Finanz Ltd. & Co KG as the controller. Enquiries and appointment bookings that reach us via this website are transferred to our customer relationship management system (FluentCRM, provider WPManageNinja LLC), which is installed locally on the web server of pointnerfinanz.at, so that we can process, document and follow up your enquiry in one place.

The data transferred consists of the details you have provided in the form or in the booking (in particular name, email address, telephone number and the content of your enquiry) together with the date of the enquiry. This is not a transfer to a third party: both websites and the CRM system are operated by the same controller, and both run on the servers of our host (see the section “Hosting”). The software runs locally on our own server; no transfer to the manufacturer of the software takes place.

The legal basis is Art. 6(1)(b) GDPR, insofar as the processing serves the implementation of pre-contractual measures at your request or the performance of a contract, and otherwise Art. 6(1)(f) GDPR. We have a legitimate interest in managing enquiries from both of our websites in a single, orderly system and in being able to respond to them reliably.

The data remains with us until you ask us to delete it, until you withdraw your consent to storage, or until the purpose for storing the data no longer applies. If a contract is subsequently concluded, the statutory retention periods and our privacy notice for clients apply.

Links to our cooperation partner Care Concept AG

On some pages of this website we link to the offers of our cooperation partner Care Concept AG, Bonn, Germany. These links are set up as forwarding links on our own domain (path /go/…) and are implemented technically with the BetterLinks plugin, which runs locally on our web server.

No data is transmitted to Care Concept AG before you click such a link. When you click the link, you are forwarded to the website of Care Concept AG. From the moment of forwarding, your data — in particular your IP address, your browser information and a partner identifier which allows Care Concept AG to attribute the enquiry to us — is transmitted to Care Concept AG and processed there under the responsibility of Care Concept AG. Any details you enter on the Care Concept AG website (e.g. for a quotation or an application) are processed by Care Concept AG as the controller.

The use of these links is based on our legitimate interest in being able to offer you suitable insurance solutions from our cooperation partner and in the proper settlement of our commission (Art. 6(1)(f) GDPR). Information on the data processing by Care Concept AG can be found in its privacy policy at care-concept.de/wir_ueber_uns/datenschutz_eng.php.

5. Analysis tools

Google Site Kit and Google Analytics 4

This website uses the WordPress plugin Google Site Kit in order to integrate and evaluate the services Google Analytics 4 and Google Search Console. The provider of these services is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyse the behaviour of website visitors. In doing so, the website operator receives various usage data, such as page views, time spent on the site, the operating systems used and the origin of the user. This data is combined in a user ID and assigned to the respective device of the website visitor.

Google Analytics uses technologies that enable the recognition of the user for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Google about the use of this website is generally transmitted to a Google server in the USA and stored there. IP addresses are shortened by Google before storage and are not stored in full; the IP address transmitted by your browser is not merged with other Google data.

Cross-domain measurement. We operate two websites: this one (pointnerfinanz.com) and our German-language website pointnerfinanz.at. Both are recorded in the same Google Analytics property using cross-domain measurement. This means that if you move from one of our domains to the other, the visit is recorded as a single, continuous session rather than as two separate visits. For this purpose, an identifier stored on one domain is passed to the other domain when you follow a link between them. The purpose is solely to obtain a correct picture of how our two websites are used together; the data is not merged with any other data sources.

The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and § 165 Abs. 3 TKG 2021. Consent may be withdrawn at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/controllerterms/mccs/.

The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

Browser plugin. You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout.

More information on the handling of user data by Google Analytics can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245.

6. Plugins and tools

Google Fonts (local hosting)

This site uses so-called Google Fonts, provided by Google, for the uniform display of fonts. The Google Fonts are installed locally. No connection to Google servers takes place in this process.

Further information on Google Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy.

WP Rocket (caching)

To speed up the delivery of our pages we use the caching software WP Rocket from the provider WP Media SAS, 8 rue Saint-Antoine du T, 31000 Toulouse, France. The software is installed locally on our web server and stores pre-generated versions of our pages there so that they can be delivered more quickly. No personal data is collected, stored or transmitted to the provider for this purpose, and no cookies are set for the caching function.

The use of WP Rocket is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the fast and resource-efficient delivery of its website.

Login protection (Kadence Security Pro)

We use Kadence Security Pro (formerly iThemes Security / Solid Security) on this website. The provider is SolidWP / StellarWP, 1720 South Kelly Avenue, Edmond, OK 73013, USA (hereinafter “SolidWP”).

Kadence Security Pro serves to protect our website against unwanted access or malicious cyberattacks, in particular against automated login attempts. For this purpose it records, among other things, your IP address, the time and source of login attempts and log data (e.g. the browser used). Kadence Security Pro is installed locally on our servers.

Kadence Security Pro transmits the IP addresses of repeat attackers to a central SolidWP database in the USA (network brute force protection) in order to prevent such attacks in future.

Kadence Security Pro is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its website against cyberattacks as effectively as possible. Insofar as corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and § 165 Abs. 3 TKG 2021, where the consent covers the storage of cookies or access to information on the user’s terminal equipment (e.g. device fingerprinting) within the meaning of the TKG 2021. Consent may be withdrawn at any time.

7. Client and contract data

Processing of client and contract data

We collect, process and use personal client and contract data for the establishment, content design and amendment of our contractual relationships. We only collect, process and use personal data relating to the use of this website (usage data) insofar as this is necessary to enable the user to make use of the service or to bill for it. The legal basis for this is Art. 6(1)(b) GDPR.

The client data collected is deleted after completion of the assignment or termination of the business relationship and after the expiry of any applicable statutory retention periods. Statutory retention periods remain unaffected.

Transfer of data upon conclusion of a contract for services and digital content

We transfer personal data to third parties only where this is necessary in the course of contract processing, for example to the credit institution commissioned with payment processing.

Any further transfer of the data does not take place, or only takes place if you have expressly consented to the transfer. Your data will not be passed on to third parties without express consent, for example for advertising purposes.

The basis for the data processing is Art. 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or of pre-contractual measures.

8. Audio and video conferences

Data processing

For communication with our clients we use, among other things, online conference tools. The tools we use in detail are listed below. If you communicate with us by video or audio conference via the internet, your personal data will be collected and processed by us and by the provider of the respective conference tool.

The conference tools collect all data that you provide or use in order to use the tools (email address and/or your telephone number). The conference tools also process the duration of the conference, the start and end (time) of participation in the conference, the number of participants and other “contextual information” in connection with the communication process (metadata).

Furthermore, the provider of the tool processes all technical data required to handle the online communication. This includes in particular IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or loudspeaker and the type of connection.

If content is exchanged, uploaded or otherwise made available within the tool, this is also stored on the servers of the tool providers. Such content includes in particular cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards and other information shared during the use of the service.

Please note that we do not have full influence over the data processing operations of the tools used. Our options are largely determined by the corporate policy of the respective provider. Further information on the data processing by the conference tools can be found in the privacy policies of the tools used, which we have listed below this text.

Purpose and legal bases

The conference tools are used in order to communicate with prospective or existing contractual partners or to offer certain services to our clients (Art. 6(1)(b) GDPR). Furthermore, the use of the tools serves to simplify and speed up communication with us and our company in general (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Insofar as consent has been requested, the tools concerned are used on the basis of that consent; consent may be withdrawn at any time with effect for the future.

Storage period

The data collected directly by us via the video and conference tools will be deleted from our systems as soon as you ask us to delete it, withdraw your consent to storage, or the purpose for storing the data no longer applies. Stored cookies remain on your terminal equipment until you delete them. Mandatory statutory retention periods remain unaffected.

We have no influence over the storage period of your data that is stored by the operators of the conference tools for their own purposes. For details, please contact the operators of the conference tools directly.

Conference tools used

Google Meet. We use Google Meet. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For details of the data processing, please refer to Google’s privacy policy: https://policies.google.com/privacy.

The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this is available from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.