Privacy policy
Foreword
We, the on:DesignVibes LLC (hereinafter also referred to as: “the company„, „we“ or “us“We take the protection of your personal data seriously and would like to take this opportunity to inform you about our company’s data protection practices.”
Under our data protection obligations, we are required to protect the personal data of the data subject (hereinafter, we will also refer to you as the data subject) “Customer,” “User”, “You”, “You” or “Affected person“ to ensure that …
To the extent that we determine the purposes and means of data processing either on our own or jointly with others, this includes, in particular, the obligation to inform you transparently about the nature, scope, purpose, duration, and legal basis of the processing (see Articles 13 and 14 of the GDPR). With this statement (hereinafter: “Privacy Policy“We are providing you with information about how we process your personal data.”
Our privacy policy is structured in a modular format. It consists of a general section covering all processing of personal data and processing situations that apply whenever our website is accessed and a business relationship exists (A. General) and a specific section, the content of which relates only to the processing situation specified therein, including the name of the respective offer or product, in particular the visit to websites described in more detail here (B. Visit to Websites), as well as in the event that a business relationship exists between you and us (C. Business Partners).
A. General Information
(1) Definitions
In accordance with Article 4 of the GDPR, this privacy notice is based on the following definitions:
- “Personal data” (Art. 4(1) of the GDPR) refers to any information relating to an identified or identifiable natural person (“data subject”). A person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, an online identifier, location data, or by reference to information relating to their physical, physiological, genetic, mental, economic, cultural, or social identity. Identifiability may also result from combining such information with other additional knowledge. The origin, form, or medium of the information is irrelevant (photos, video recordings, and audio recordings may also contain personal data).
- “Processing” (Art. 4(2) of the GDPR) means any operation or set of operations performed on personal data, whether or not by automated (i.e., technology-based) means. This includes, in particular, the collection (i.e., the acquisition), recording, organization, structuring, storage, adaptation or alteration, retrieval, retrieval, use, disclosure by transmission, dissemination or otherwise making available, comparison, linking, restriction, erasure, or destruction of personal data, as well as a change in the purpose or objective originally underlying the data processing.
- “Controller” (Art. 4(7) of the GDPR) means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.
- “Third party” (Art. 4(10) of the GDPR) means any natural or legal person, public authority, agency, or other body other than the data subject, the controller, the processor, and the persons authorized to process the personal data under the direct responsibility of the controller or processor; this also includes other legal entities belonging to the same corporate group.
- “Processor” (Art. 4(8) of the GDPR) means a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller, in particular in accordance with the controller’s instructions (e.g., an IT service provider). For the purposes of data protection law, a processor is, in particular, not a third party.
- “Consent” (Art. 4(11) of the GDPR) of the data subject means any freely given, specific, in an informed and unambiguous manner, in the form of a statement or other clear affirmative action, by which the data subject indicates that he or she consents to the processing of personal data relating to him or her.
(2) Name and address of the data controller
The entity responsible for the processing of your personal data within the meaning of Article 4(7) of the GDPR is:
by: DesignVibes UG\\\\n(limited liability)\\\\n Holstenhofweg 54\\\\n 22043 Hamburg\\\\n Germany
Phone: +49 (40) 70 2929 97\\n Email: [email protected]
For more information about our company, please refer to the legal notice on our website [https://onnetwork.agency/impressum].
(3) Legal basis for data processing
By law, the processing of personal data is generally prohibited and is permitted only if it falls under one of the following grounds for justification:
- Art. 6(1), sentence 1, subparagraph (a) of the GDPR (“Consent”): Where the data subject has freely, in an informed manner, and unambiguously indicated, by a statement or by another clear affirmative action, that he or she consents to the processing of personal data concerning him or her for one or more specific purposes;
- Art. 6(1), sentence 1, subparagraph (b) of the GDPR: Where processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of precontractual measures taken at the data subject’s request;
- Art. 6(1), sentence 1, subparagraph (c) of the GDPR: If processing is necessary for compliance with a legal obligation to which the controller is subject (e.g., a statutory retention requirement);
- Art. 6(1), sentence 1, subparagraph (d) of the GDPR: Where processing is necessary to protect the vital interests of the data subject or of another natural person;
- Art. 6(1), sentence 1, subparagraph (e) of the GDPR: Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or
- Art. 6(1), sentence 1, subparagraph (f) of the GDPR (“Legitimate Interests”): Where processing is necessary to safeguard the legitimate (in particular legal or economic) interests of the controller or a third party, unless the interests or rights of the data subject prevail (in particular where the data subject is a minor).
The storage of information on the end user’s terminal equipment or access to information already stored on the terminal equipment is permitted only if it is covered by one of the following justifications:
- § 25(1) TTDSG: If the end user has given consent based on clear and comprehensive information. Consent must be given in accordance with Art. 6(1), sentence 1, subparagraph (a) of the GDPR;
- § 25(2)(1) TTDSG: If the sole purpose is to transmit a message via a public telecommunications network, or
- § 25(2)(2) TTDSG: If the storage or access is absolutely necessary for the provider of a telemedia service to make available a telemedia service expressly requested by the user.
For each of the processing operations we carry out, we specify the applicable legal basis below. Processing may be based on more than one legal basis.
(4) Data Deletion and Retention Period
For each of the processing operations we perform, we specify below how long we will retain the data and when it will be deleted or blocked. Unless an explicit retention period is specified below, your personal data will be deleted or blocked as soon as the purpose or legal basis for storage no longer applies. Your data is generally stored only on our servers in Germany, subject to any transfer that may occur in accordance with the provisions in A. (6) and A. (7).
However, data may be retained beyond the specified period in the event of a (potential) legal dispute with you or other legal proceedings, or if retention is required by legal provisions to which we, as the data controller, are subject (e.g., Section 257 of the German Commercial Code (HGB), § 147 AO). Once the retention period prescribed by law expires, the personal data will be blocked or deleted, unless further storage by us is necessary and there is a legal basis for doing so.
(5) Data Security
We use appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction, or unauthorized access by third parties (e.g., SSL or TLS encryption for our website) taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purpose of the processing, as well as the existing risks of a data breach (including its likelihood and impact) for the data subject. Our security measures are continuously improved in line with technological developments.
We will be happy to provide you with further information upon request. Please contact our designated representative (see A. (2)).
(6) Cooperation with data processors
As is the case with other companies, we also use external domestic and foreign service providers to conduct our business (e.g., in the areas of IT, logistics, telecommunications, sales and marketing, and billing and invoicing). These service providers act solely in accordance with our instructions and are contractually obligated, pursuant to Article 28 of the GDPR, to comply with data protection regulations.
(7) Conditions for the transfer of personal data to third countries
In the course of our business relationship, your personal data may be transferred to or disclosed to third-party companies. These companies may be located outside the European Economic Area (EEA), i.e., in third countries. Such processing is carried out exclusively to fulfill contractual and business obligations and to maintain your business relationship with us (the legal basis is Art. 6(1)(b) or (f) in conjunction with Art. 44 et seq. of the GDPR). We will inform you of the specific details of the transfer below in the relevant sections.
Through so-called adequacy decisions, the European Commission certifies that certain third countries have data protection standards comparable to those of the EEA (a list of these countries and a copy of the adequacy decisions are available here:
However, in other third countries to which personal data may be transferred, there may not be a consistently high level of data protection due to a lack of legal provisions. Where this is the case, we ensure that adequate data protection is guaranteed. This can be achieved through binding corporate rules, the European Commission’s standard contractual clauses for the protection of personal data pursuant to Art. 46(1)(c) of the GDPR (the 2021 standard contractual clauses are available at
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0915&locale-en),
Certifications or recognized codes of conduct. Please contact our designated representative (see A.(2)) if you would like more information on this.
(8) No automated decision-making (including profiling)
We do not intend to use the personal data we collect from you for automated decision-making (including profiling).
(9) No obligation to provide personal data
We do not make the conclusion of contracts with us contingent on your prior provision of personal data. As a customer, you are generally under no legal or contractual obligation to provide us with your personal data; however, we may only be able to provide certain offers to a limited extent or not at all if you do not provide the necessary data. Should this be the case in exceptional circumstances with regard to the products we offer as described below, you will be notified separately.
(10) Legal obligation to disclose certain information
We may be subject to a specific legal obligation to disclose lawfully processed personal data to third parties, in particular public authorities (Art. 6(1)(c) of the GDPR).
(11) Your rights
You may exercise your rights as a data subject regarding your processed personal data at any time by contacting us using the contact information provided in section A.(2) above. As a data subject, you have the right to:
- pursuant to Article 15 of the GDPR, to request information about the data we process about you. In particular, you may request information regarding the purposes of processing, the categories of data, the categories of recipients to whom your data has been or will be disclosed, the planned retention period, the existence of a right to rectification, erasure, restriction of processing, or objection; the existence of a right to lodge a complaint; the origin of your data, if it was not collected by us; and the existence of automated decision-making, including profiling, and, where applicable, meaningful information regarding its details;
- in accordance with Article 16 of the GDPR, to request without delay the correction of inaccurate data or the completion of your data stored by us;
- to request the erasure of your data stored by us in accordance with Article 17 of the GDPR, unless the processing is necessary for the exercise of the right to freedom of expression and information, to comply with a legal obligation, for reasons of public interest, or to assert, exercise, or defense of legal claims;
- to request the restriction of the processing of your data pursuant to Article 18 of the GDPR, provided that you contest the accuracy of the data or the processing is unlawful;
- In accordance with Article 20 of the GDPR, you have the right to receive the data you have provided to us in a structured, commonly used, and machine-readable format, or to request that it be transferred to another controller (“data portability”);
- to object to the processing pursuant to Article 21 of the GDPR, provided that the processing is based on Article 6(1), first sentence, subparagraph (e) or (f) of the GDPR. This is particularly the case if the processing is not necessary for the performance of a contract with you. Unless the objection is directed against direct marketing, we ask that, when exercising such an objection, you explain the reasons why we should not process your data in the manner we have been doing. In the event of a justified objection, we will review the circumstances and either cease or adjust the data processing, or explain to you our compelling legitimate grounds on the basis of which we will continue the processing;
- In accordance with Article 7(3) of the GDPR, you may withdraw the consent you previously provided (even before the GDPR took effect, i.e., before May 25, 2018)—that is, your voluntary, expressed in an informed and unambiguous manner through a statement or other clear affirmative action, indicating that you consent to the processing of the relevant personal data for one or more specific purposes—at any time, provided you have given such consent. As a result, we may no longer continue the data processing that was based on this consent in the future, and
- In accordance with Article 77 of the GDPR, you have the right to file a complaint with a data protection supervisory authority regarding the processing of your personal data by our company, such as the data protection supervisory authority with jurisdiction over us:
The Hamburg Commissioner for Data Protection and Freedom of Information of the Free and Hanseatic City of Hamburg – a public-law corporation
22 Ludwig-Erhard-Str, 7th Floor\\\\n 20459 Hamburg
Phone: 040 / 428 54 – 4040\\\\n Fax: 040 / 428 54 – 4000\\\\n Email: [email protected]
(12) Changes to the Privacy Policy
As data protection laws evolve and technological or organizational changes occur, we regularly review our privacy policy to determine whether it needs to be updated or expanded. You can find information about any changes, in particular, on our website at https://onnetwork.agency/datenschutz taught.
This privacy policy is current as of March 2025.
B. Visiting our website
(1) Description of the function
You can find information about our company and the services we offer, in particular, at https://onnetwork.agency/, https://onhoster.de and https://kevin-winter.deincluding the associated subpages (hereinafter collectively referred to as “Websites”). When you visit our Websites and/or contact us through them, your personal data may be processed.
(2) Processed personal data
When you use our website for informational purposes, we collect, store, and process the following categories of personal data:
a)Log data
When you visit our website, a so-called log record (also known as a server log file) is stored temporarily and anonymously on our web server. This consists of:
- the page from which the page was requested (known as the referrer URL)
- the name and URL of the requested page
- the date and time of the request
- a description of the type, language, and version of the web browser being used
- the IP address of the requesting computer, which is truncated so that it can no longer be linked to a specific individual
- the amount of data transferred
- dem Betriebssystem
- a message indicating whether the request was successful (access status/HTTP status code)
- der GMT-Zeitzonendifferenz
b) Contact form data
If you have any questions, we offer you the option of contacting us via a form provided on the website. You are required to provide a valid email address, a title, and your first and last name so that we know who the inquiry is from and can respond to it. Additional information (e.g., mailing address, company name, and the time of submission) may be provided voluntarily.
c) Customer Portal
You can contact our customer support at any time. We need your information to address your concerns when you communicate with our customer support.
For this purpose, we process the following personal data about you:
- Kontaktdaten
- Identification and Authentication Data
- Contract Information
- Details of Your Inquiries
- Bezahldaten
(3) Purpose and legal basis of data processing
We process the personal data specified above in accordance with the provisions of the GDPR, other relevant data protection regulations, and only to the extent necessary. To the extent that the processing of personal data is based on Article 6(1)(f) of the GDPR, the stated purposes also constitute our legitimate interests.
The processing of log data is used for statistical purposes and to improve the quality of our website, particularly the stability and security of the connection (the legal basis is Article 6(1)(a) or (f) of the GDPR).
Contact form data is processed for the purpose of handling customer inquiries (the legal basis is Article 6(1)(b) or (f) of the GDPR).
Customer portal data is processed for the purpose of providing support services (the legal basis is Article 6(1)(b) or (f) of the GDPR).
Applicant data is processed solely for the purpose of conducting the application and selection process and assessing your professional qualifications.
By submitting or sending your application to us, you consent to your information being stored and processed for the duration of the application process and used to contact you during that process. This applies in particular if you yourself disclose “special categories of personal data” as defined in Article 9 of the GDPR in your cover letter or other documents submitted during the application process (e.g., a photo revealing your ethnic origin, information regarding severe disability status, etc.). Your consent also applies to this data.
(The legal basis is Article 6(1)(a) or (f) of the GDPR).
If the processing of the data requires the storage of information on your terminal device or access to information already stored on the terminal device, § 25(1), (2) of the TTDSG serves as the legal basis for this.
(4) Duration of data processing
Your data will be processed only for as long as is necessary to achieve the processing purposes stated above; the legal bases specified in connection with those processing purposes apply accordingly. Regarding the use and retention period of cookies, please refer to Section A. (4) and the Cookie Policy [https://onnetwork.agency/datenschutz#cookie].
The third parties we engage will store your data on their systems for as long as is necessary to provide services to us in accordance with the relevant agreement.
For more information on the storage period, please see section A. (4) and the Cookie Policy [https://onnetwork.agency/datenschutz#cookie].
(5) Disclosure of personal data to third parties; legal basis
The following categories of recipients, who are generally data processors (see A. (6) for more information), may have access to your personal data:
- Service providers responsible for operating our website and processing the data stored or transmitted by the systems (e.g., for data center services, payment processing, and IT security). The legal basis for the disclosure is then Article 6(1)(b) or (f) of the GDPR, provided that the parties involved are not data processors;
- Government agencies/authorities, to the extent necessary to fulfill a legal obligation. The legal basis for the disclosure is then Article 6(1), sentence 1, subparagraph (c) of the GDPR;
- Persons involved in the conduct of our business operations (e.g., auditors, banks, insurance companies, legal advisors, regulatory authorities, parties involved in corporate acquisitions or the formation of joint ventures). The legal basis for the disclosure is then Article 6(1), first sentence, subparagraph (b) or (f) of the GDPR.
For information on the safeguards ensuring an adequate level of data protection when data is transferred to third countries, see A. (7).
In addition, we will only disclose your personal data to third parties if you have given your explicit consent in accordance with Article 6(1)(a) of the GDPR.
(6) Use of cookies, plugins, and other services (tools) on our website
a) Cookie
We use cookies on our website. Cookies are small text files that are stored on your hard drive and associated with the browser you are using via a unique string of characters, and through which certain information is transmitted to the entity that sets the cookie. Cookies cannot run programs or transfer viruses to your computer and therefore cannot cause any damage. They serve to make the website more user-friendly and effective overall, and thus more convenient for you.
Cookies may contain data that makes it possible to recognize the device being used. However, in some cases, cookies contain only information about specific settings that are not personally identifiable. Cookies cannot directly identify a user.
A distinction is made between session cookies, which are deleted as soon as you close your browser, and persistent cookies, which are stored beyond the scope of a single session. In terms of their function, cookies are further categorized as follows:
- Technical Cookies: These are strictly necessary to navigate the website, use basic features, and ensure the website’s security; they neither collect information about you for marketing purposes nor track which web pages you have visited;
- Performance Cookies: These collect information about how you use our website, which pages you visit, and, for example, whether any errors occur while using the website; they do not collect any information that could identify you—all information collected is anonymous and is used only to improve our website and determine what interests our users;
- Advertising Cookies, Targeting Cookies: These are used to provide website users with personalized advertising on the website or offers from third parties, and to measure the effectiveness of these offers.
- Third-party cookies: These types of cookies enable services and features on the website that have been developed by “third parties.” Third-party cookies are created, for example, through the use of services such as Google Analytics or Google Maps. Third-party cookies are generated by embedded plugins or technologies from the respective organizations. We have no control over the cookies or privacy settings of these services or organizations, and we expressly note that the third-party services we use are subject solely to their respective cookie and privacy policies.
The legal basis for cookies that are strictly necessary to provide you with the service you have expressly requested is Section 25(2)(2) of the TTDSG. Any use of cookies that is not strictly technically necessary for this purpose constitutes data processing that is permitted only with your explicit and active consent pursuant to Section 25(1) of the TTDSG in conjunction with Article 6(1)(a) of the GDPR. This applies in particular to the use of performance, advertising, or targeting cookies. Furthermore, we will only disclose your personal data processed via cookies to third parties if you have given your explicit consent to do so in accordance with Article 6(1)(a) of the GDPR.
b) Cookie Policy, Cookies Used, and Tools
You can find more information about the cookies we use below. For information on how to manage your cookie settings and disable certain types of tracking, please see our Cookie Policy [https://onnetwork.agency/datenschutz#cookie].
Borlabs Cookie
Our website uses Borlabs Cookie’s cookie consent technology to obtain your consent to the storage of certain cookies in your browser and to document this in compliance with data protection regulations. The provider of this technology is Borlabs – Benjamin A. Bornschein, Georg-Wilhelm-Str. 17, 21107 Hamburg (hereinafter Borlabs).
When you visit our website, a Borlabs-A cookie is stored in your browser to record the consents you have given or any revocation of those consents. This data is not shared with the provider of Borlabs Cookie shared.
The collected data will be stored until you ask us to delete it or until the Borlabs-Delete the cookie yourself or when the purpose for storing the data no longer applies. Mandatory legal retention periods remain unaffected. Details regarding the processing of Borlabs You can find the cookie at: https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/
The use of Borlabs-Cookie consent technology is used to obtain the legally required consent for the use of cookies. The legal basis for this is Article 6(1)(c) of the GDPR.
Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; hereinafter “Google”).
Google Analytics (https://analytics.google.com/analytics/web/) is used to collect and store data for marketing and optimization purposes. This data may be used to create usage profiles under a pseudonym. Cookies may be used for this purpose. Cookies enable the recognition of the web browser. During your visit to the website, the following data, among others, is recorded:
- Aufgerufene Seiten
- Orders, including sales and the products ordered
- Achieving “website goals” (e.g., contact requests and newsletter sign-ups)
- Ihr Verhalten auf den Seiten (beispielsweise Verweildauer, Klicks, Scrollverhalten)
- Your approximate location (country and city)
- Your IP address (in truncated form, so that it cannot be uniquely identified)
- Technical information such as browser, Internet service provider, device, and screen resolution
- The source of your visit (i.e., which website or advertising material led you to us).
The information generated by the cookie regarding your use of this website is transmitted to a Google server in the United States and stored there. However, Google will first truncate the IP address of the visitor or registered user within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and truncated there.
On behalf of the operator of this website and pursuant to a written data processing agreement, Google will use this information to evaluate the use of the website, to compile reports on website activity, and to provide other services related to website and internet usage to the website operator. The IP address transmitted by the browser as part of Google Analytics will not be merged with other Google data.
User-related data is automatically deleted after 14 months. Other data remains stored in aggregated form indefinitely.
Google will use this information to evaluate your use of the website, to compile reports on website activity for the website operators, and to provide other services related to website and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the data on Google’s behalf. Google will not associate your IP address with any other data held by Google.
The legal basis for the processing of personal data via Google Analytics is your consent pursuant to Article 6(1)(a) of the GDPR.
You can revoke your consent at any time, delete cookies stored in your browser, or configure your browser to notify you when cookies are set, allowing you to decide on a case-by-case basis whether to accept them, or to block cookies in specific cases or generally. You can prevent Google from collecting and further processing your data by downloading and installing the plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de
prevent. If you do not accept cookies, the functionality of our website may be limited. Withdrawing your consent does not affect the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal.
For more information on our Terms of Use and Privacy Policy, please visit http://www.google.com/analytics/terms/de.html or at https://www.google.de/intl/de/policies/.
Please note that Google Analytics on this website has been enhanced with the code “gat._anonymizeIp();” to ensure that IP addresses are collected anonymously (a process known as IP masking).
Cloudflare – Content Delivery Network (CDN)
We use the Content Delivery Network (CDN) provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, on our website. The CDN is integrated via the “_cfduid” cookie placed on our website.
The CDN is used to optimize loading and response times and to improve the protection of our website against third-party attacks. A CDN is a network of geographically distributed servers connected via the Internet that provides enhanced caching and delivery capabilities for websites. This ensures optimal performance within normal loading times, even during periods of very high and simultaneous traffic (peak loads) on our website. Your user requests to our website are routed through Cloudflare servers in the U.S. as part of the CDN.
A contract was therefore entered into with Cloudflare regarding the processing of personal data on our behalf, as well as the EU Standard Contractual Clauses.
You can find the standard contractual clauses at: https://www.cloudflare.com/cloudflare-customer-scc/.
The legitimate interest lies in optimizing loading and response times, as well as in improving the protection of our website against attacks by third parties. The legal basis for data processing is Article 6(1)(f) of the GDPR.
You can find Cloudflare’s Privacy Policy at: https://www.cloudflare.com/cloudflare-customer-dpa/
For information on what data Cloudflare collects through the use of its CDN, please refer to Cloudflare’s Privacy Policy and the following additional resources: https://blog.cloudflare.com/what-cloudflare-logs/
You can contact Cloudflare’s Data Protection Officer at [email protected] contact.
Cloudflare Turnstile
We use Cloudflare Turnstile (Turnstile) on our website, provided by Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA.Turnstile is used to verify whether data entry on this website (e.g., in a contact form) is performed by a human or by an automated program. To do this, Turnstile analyzes the website visitor’s behavior based on various characteristics. This analysis begins automatically as soon as the website visitor enters a website with Turnstile enabled. For the analysis, Turnstile evaluates various pieces of information (e.g., IP address, the duration of the website visitor’s stay on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Cloudflare in the United States.
A contract was therefore entered into with Cloudflare regarding the processing of personal data on our behalf, as well as the EU Standard Contractual Clauses.
You can find the standard contractual clauses at: https://www.cloudflare.com/cloudflare-customer-scc/
The legitimate interest lies in optimizing loading and response times, as well as in improving the protection of our website against attacks by third parties. The legal basis for data processing is Art. 6(1)(f) of the GDPR. We have a legitimate interest in protecting our web offerings from abusive automated spying and from SPAM. If consent has been obtained, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, provided that the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG.
For more information about Cloudflare Turnstile, please refer to the privacy policy at: https://www.cloudflare.com/cloudflare-customer-dpa/
c) Social media plugins
We do not use social media plugins on our websites. If our websites contain icons from social media providers, we use them only in part and solely for passive linking to the respective providers’ sites. There, we aim to inform our prospective customers about our services and also communicate with you through these channels. You can find more details on this in the following explanations
Facebook and Instagram
We also use Facebook and Instagram icons on our website.
Facebook and Instagram are operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland.
To enhance the protection of your data when you visit our website, we use these icons to embed HTML links to the Facebook and Instagram websites. This method of integration ensures that when you visit a page on our website that contains such icons, no connection is yet established with the servers of the respective social network provider. If you click on one of the buttons, a new window will open in your browser and load the page of the respective service provider, where you can (after entering your login credentials, if necessary) click the Like or Share button, for example.
For information regarding the purpose and scope of data collection, as well as the further processing and use of data by the provider on its website, and your rights and privacy settings in this regard, please refer to the provider’s privacy policy.
https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0 or https://help.instagram.com/155833707900388.
C. Business Partners and Customers
(1) Initiation and execution of contractual relationships
The following data is processed in connection with the initiation and performance of contractual relationships:
a) Contract details
When you order one of our products or services, we ask you to provide your personal information, which we need to enter into and fulfill the contract.
You can make changes or corrections to this information at any time via your customer portal.
Type of data
- Salutation
- First and Last Name
- Email address
- Telefonnummer
- Firmenname (bei Gewerbe)
- Anschrift
- Product Agreements and Use
- Contract Information
- Bezahldaten
- Umsatzsteuernummer (bei Gewerbe)
b) Customer Support
You can contact our customer support at any time. We need your information to address your concerns when you contact our customer support.
For this purpose, we process the following of your personal data:
- Kontaktdaten
- Identification and Authentication Data
- Contract Information
- Details of Your Inquiries
- Bezahldaten
c) Purpose and legal basis of data processing
We require the contract data and customer support data to facilitate the communication necessary for the proper execution of the contract, the provision of our services, the exchange of information through process communication, and the billing of services.
The legal basis for the processing of contract data and customer support data is Article 6(1)(b) of the GDPR.
d) Duration of data processing
We process your data until your contract ends. In addition, we retain your contract data if there are any outstanding objections or claims that have yet to be resolved. We also store your data for a longer period if there are legal retention obligations. In this case, the processing of the data is limited to compliance with the legal retention periods, and the data is no longer processed for any other purposes. For contract data, processing is restricted after the contract ends; after the ten-year statutory retention period pursuant to § 257 HGB and § 147 AO has expired, the data is deleted.
We retain communications with you related to customer support until the end of the contract term and, thereafter, only until any outstanding inquiries have been fully resolved or as required by applicable legal retention obligations.
(2) Communication with customers and business partners
To communicate with customers and business partners—including potential ones—we use various communication channels to present or provide our services, or to get in touch with them.
(3) Other processors as recipients of data
As a general rule, we do not disclose your data to third parties unless this is expressly stated in this Privacy Policy. Below you will find information about other processors within the meaning of Art. 28 of the GDPR (see above under A. (6)) to whom your data is transferred.
a) Payment service provider Stripe
We offer the option to process payments through the payment service provider Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter “Stripe”).
In this context, we process and share the following data about you with Stripe to the extent necessary for the performance of the contract (Art. 6(1)(b) of the GDPR).
- Name des Karteninhabers
- Email address
- Kundennummer
- Bestellnummer
- Bankverbindung
- Credit card information
- Credit Card Validity Period
- Credit Card Verification Code (CVC)
- Date and time of the transaction
- Transaktionssumme
- Name des Anbieters
- Ort
Without the transmission of your personal data, we cannot process a payment via Stripe. Stripe acts in a dual role as both a data controller and a data processor in its data processing activities. As a data controller, Stripe uses the data you provide to comply with regulatory obligations. This corresponds to Stripe’s legitimate interest (pursuant to Art. 6(1)(f) of the GDPR) and serves the purpose of contract performance (pursuant to Art. 6(1)(b) of the GDPR). We have no influence over this process.
Stripe acts as a data processor to facilitate transactions within the payment networks. Under the data processing agreement, Stripe acts solely on our instructions and is contractually obligated to comply with data protection regulations in accordance with Article 28 of the GDPR.
Stripe has implemented compliance measures for international data transfers. These measures apply to all global activities in which Stripe processes personal data of individuals in the EU. These measures are based on the EU Standard Contractual Clauses (SCCs).
For more information about Stripe’s privacy policy, please visit the following website https://stripe.com/de/privacy#translation.
b) Payment service provider PayPal
We also offer the option of processing payments through the payment service provider PayPal. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg (hereinafter “PayPal”).
If you select PayPal as your payment method, the payment details you enter will be transmitted to PayPal. The legal basis for this is Article 6(1)(b) of the GDPR (processing necessary for the performance of a contract) and Article 6(1)(a) of the GDPR, provided that you have consented to the use of PayPal. You may revoke your consent at any time with future effect.
Data is transferred to third countries in accordance with the EU Standard Contractual Clauses. For more information about PayPal’s data protection practices, please see the PayPal Privacy Policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
c) Order processing in the online store (WooCommerce)
Our online store is based on the WooCommerce shopping cart software, an extension of the WordPress content management system. When you place an order, we process the order, shipping, and billing information you provide in order to fulfill the contract (Art. 6(1)(b) GDPR). The data is stored on our server. Due to commercial and tax law retention requirements, we store invoice and order data for the statutory periods (typically 6 to 10 years).
To fulfill your order, we will share your name and shipping address with the shipping provider we have contracted, to the extent necessary for delivery (Art. 6(1)(b) of the GDPR).
Zuletzt aktualisiert: 8. June 2026