Privacy Policy
This Privacy Policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “Data”) within our online offering and the associated websites, features, and content, as well as external online presences, such as our social media profiles. (Hereinafter collectively referred to as the “Online Offering”). With regard to the terms used, such as “processing” or “controller,” we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Person in Charge
Machbar
39 Obere Königsstraße
34117 Kassel
Phone: +49 561 4759560
Fax: +49 561 47595629
Email: machbar
Website: machbar
Managing Directors: Michael Heppe, Clemens Camphausen, Andreas Feischen
Link to the Legal Notice: machbar
Types of data processed:
– Master data (e.g., names, addresses).
– Contact data (e.g., email, phone numbers).
– Content data (e.g., text entries, photographs, videos).
– Usage data (e.g., websites visited, interest in content, access times).
– Meta/communication data (e.g., device information, IP addresses).
Categories of Data Subjects
Visitors and users of the online service (hereinafter, we collectively refer to these individuals as “users”).
Purpose of the Processing
– Providing the online service, its features, and content.
– Responding to contact requests and communicating with users.
– Security measures.
– Audience measurement/marketing
Terminology Used
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any handling of data.
“Pseudonymization” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures that ensure the personal data is not attributed to an identified or identifiable natural person.
“Profiling” means any form of automated processing of personal data consisting of the use of such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
“Controller” means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.
“Processor” means a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.
Relevant Legal Bases
In accordance with Article 13 of the GDPR, we are providing you with the legal bases for our data processing activities. Unless the legal basis is specified in the Privacy Policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing to fulfill our services, carry out contractual obligations, and respond to inquiries is Article 6(1)(b) of the GDPR; the legal basis for processing to fulfill our legal obligations is Article 6(1)(c) of the GDPR, and the legal basis for processing to protect our legitimate interests is Article 6(1)(f) of the GDPR. In the event that the vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.
Safety Measures
In accordance with Article 32 of the GDPR, and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as access to, input of, and disclosure of the data, ensuring its availability, and maintaining its separation. Furthermore, we have established procedures to ensure the exercise of data subjects’ rights, the erasure of data, and a response to data breaches. Furthermore, we take the protection of personal data into account from the very beginning of the development or selection of hardware, software, and procedures, in accordance with the principle of data protection through design and by default (Art. 25 GDPR).
Cooperation with Data Processors and Third Parties
If, in the course of our data processing, we disclose data to other individuals or companies (processors or third parties), transfer it to them, or otherwise grant them access to the data, this is done only on the basis of a legal authorization (e.g., if the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Article 6(1)(b) of the GDPR), you have given your consent, a legal obligation requires it, or based on our legitimate interests (e.g., when using agents, web hosts, etc.).
If we engage third parties to process data on the basis of a so-called “Data Processing Agreement,” this is done in accordance with Article 28 of the GDPR.
Transfers to Third Countries
To the extent that we transfer personal data to recipients in countries outside the European Union (EU) or the European Economic Area (EEA), or engage service providers with access from such countries, we do so only if the specific requirements of Articles 44 et seq. of the GDPR are met.
Data transfers to certain third countries may be permissible, in particular, if the European Commission has issued an adequacy decision for the respective third country. For data transfers to certified companies in the United States, this may occur, in particular, on the basis of the EU-U.S. Data Privacy Framework. The European Commission issued a corresponding adequacy decision on July 10, 2023.
If no adequacy decision exists for a recipient country or if the respective recipient is not covered by such a decision, we base the transfer of personal data on appropriate safeguards, in particular the Standard Contractual Clauses approved by the European Commission.
Please note that, despite contractual and technical safeguards, a level of data protection fully comparable to that of the EU cannot be guaranteed in every case when data is transferred to third countries.
If we use services on our website from providers based in third countries, we will inform you about the details of the respective data transfer, the relevant legal basis, and the safeguards used in the respective sections of this Privacy Policy.
Rights of Data Subjects
You have the right to request confirmation as to whether data concerning you is being processed, as well as access to that data, further information, and a copy of the data in accordance with Article 15 of the GDPR.
In accordance with Article 16 of the GDPR, you have the right to request that data concerning you be completed or that inaccurate data concerning you be corrected.
In accordance with Article 17 of the GDPR, you have the right to request that the relevant data be erased without delay; alternatively, in accordance with Article 18 of the GDPR, you have the right to request a restriction on the processing of the data.
You have the right to request, in accordance with Article 20 of the GDPR, to receive the data concerning you that you have provided to us and to request that it be transmitted to other data controllers.
You also have the right, pursuant to Article 77 of the GDPR, to lodge a complaint with the competent supervisory authority.
Right of Withdrawal
You have the right to withdraw any consent you have given in accordance with Article 7(3) of the GDPR, effective for the future.
Right to Object
You may object at any time to the future processing of your personal data in accordance with Article 21 of the GDPR. In particular, you may object to processing for direct marketing purposes.
Cookies and the Right to Object to Direct Marketing
“Cookies” are small files that are stored on users’ computers. Various types of information can be stored in cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to a website. Temporary cookies—also known as “session cookies” or “transient cookies”—are cookies that are deleted after a user leaves an online service and closes their browser. Such a cookie can, for example, store the contents of a shopping cart in an online store or a user’s login status. Cookies that remain stored even after the browser is closed are referred to as “permanent” or “persistent.” For example, a user’s login status can be stored so that it remains valid when the user returns to the site several days later. Similarly, such a cookie may store the user’s interests, which are used for audience measurement or marketing purposes. “Third-party cookies” are cookies provided by parties other than the controller operating the online service (in contrast, when only the controller’s own cookies are used, they are referred to as “first-party cookies”).
We may use temporary and permanent cookies and provide information about this in our Privacy Policy. If users do not wish to have cookies stored on their computers, they are asked to disable the corresponding option in their browser’s settings. Stored cookies can be deleted in the browser’s settings. Disabling cookies may result in functional limitations of this online service.
A general objection to the use of cookies for online marketing purposes can be submitted for a wide range of services—particularly in the case of tracking—via the U.S. website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, you can prevent cookies from being stored by disabling them in your browser settings. Please note that, in this case, you may not be able to use all features of this online service.
Deletion of Data
The data we process will be deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated otherwise in this Privacy Policy, the data we store will be deleted as soon as it is no longer necessary for its intended purpose and no legal retention obligations prevent its deletion. If the data is not erased because it is required for other, legally permissible purposes, its processing will be restricted. This means the data will be blocked and not processed for any other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
In accordance with German legal requirements, data is retained for a period of 10 years in particular, pursuant to Sections 147(1) of the German Fiscal Code (AO), Section 257(1)(1) and (4), and (4) of the German Commercial Code (HGB) (books, records, management reports, accounting documents, trading ledgers, documents relevant for taxation, etc.) and for 6 years in accordance with Section 257(1)(2) and (3), and (4) of the German Commercial Code (HGB) (business correspondence).
In accordance with statutory requirements in Austria, records must be retained for 7 years pursuant to § 132(1) of the Austrian Federal Tax Code (BAO) (accounting records, receipts/invoices, accounts, supporting documents, business papers, statements of income and expenses, etc.), for 22 years in connection with real estate, and for 10 years for documents related to electronically supplied services, telecommunications, radio, and television services provided to non-business customers in EU member states for which the Mini One-Stop Shop (MOSS) is utilized.
Business-Related Processing
In addition, we process
– contract data (e.g., subject matter of the contract, term, customer category).
– payment data (e.g., bank account information, payment history) from our customers, prospects, and business partners for the purposes of providing contractual services, customer service and support, marketing, advertising, and market research.
Hosting and Email Delivery
The hosting services we use are intended to provide the following: infrastructure and platform services, computing capacity, storage space and database services, email delivery, security services, and technical maintenance services, which we utilize for the purpose of operating this online offering.
In doing so, we—or our hosting provider—process inventory data, contact data, content data, contractual data, usage data, metadata, and communication data from customers, prospective customers, and visitors to this online service based on our legitimate interests in providing this online service efficiently and securely, in accordance with Article 6(1)(f) of the GDPR in conjunction with Article 28 of the GDPR (conclusion of a data processing agreement).
Webflow
We host our website with Webflow. The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San
Francisco, CA 94103, USA (hereinafter: Webflow). When you visit our website, Webflow
collects various log files, including your IP addresses.
Webflow is a tool for creating and hosting websites. Webflow stores cookies or other tracking technologies that are necessary for displaying the site, providing certain
website functions, and ensuring security (essential cookies).
For details, please refer to Webflow’s Privacy Policy:
https://webflow.com/legal/eu-privacy-policy.
The use of Webflow is based on Art. 6(1)(f) of the GDPR. We have a
legitimate interest in ensuring that our website is displayed as reliably as possible. If consent has been requested
, processing is carried out exclusively on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG
. Consent may be revoked at any time.
Data transfers to the U.S. are based on the EU Commission’s Standard Contractual Clauses.
Details can be found here: https://webflow.com/legal/eu-privacy-policy.
Data Processing
We have entered into a data processing agreement (DPA) with the provider mentioned above.
This is a contract required under data protection law that ensures that
the provider processes the personal data of our website visitors only in accordance with our instructions and in
compliance with the GDPR.
Collection of Access Data and Log Files
We, or rather our hosting provider, collect data regarding every access to the server on which this service is located (so-called server log files) based on our legitimate interests within the meaning of Article 6(1)(f) of the GDPR. The access data includes the name of the webpage accessed, the file, the date and time of access, the amount of data transferred, a notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), the IP address, and the requesting provider.
For security reasons (e.g., to investigate cases of misuse or fraud), log file information is stored for a maximum of 7 days and then deleted. Data that must be retained for evidentiary purposes is exempt from deletion until the respective incident has been fully resolved.
Agency Services
We process our customers’ data as part of our contractual services, which include conceptual and strategic consulting, campaign planning, software and design development/consulting or maintenance, implementation of campaigns and processes/handling, server administration, data analysis/consulting services, and training services.
In doing so, we process master data (e.g., customer master data such as names or addresses), contact data (e.g., email, phone numbers), content data (e.g., text entries, photographs, videos), contract data (e.g., subject matter of the contract, term), payment data (e.g., bank account information, payment history), usage and metadata (e.g., in the context of evaluating and measuring the success of marketing measures). As a general rule, we do not process special categories of personal data, unless they are part of commissioned processing. Data subjects include our customers, prospective customers, and their own customers, users, website visitors, or employees, as well as third parties. The purpose of the processing is to provide contractual services, handle billing, and deliver our customer service. The legal bases for processing are derived from Art. 6(1)(b) GDPR (contractual services) and Art. 6(1)(f) GDPR (analysis, statistics, optimization, security measures). We process data that is necessary for the establishment and fulfillment of contractual services and indicate that the provision of such data is required. Disclosure to third parties occurs only if required within the scope of a contract. When processing data entrusted to us under a contract, we act in accordance with the client’s instructions and the legal requirements for data processing on behalf of a client pursuant to Article 28 of the GDPR, and we process the data for no purposes other than those specified in the contract.
We delete the data after the expiration of statutory warranty obligations and comparable obligations. The necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, deletion occurs after their expiration (6 years, pursuant to Section 257(1) of the German Commercial Code (HGB); 10 years, pursuant to Section 147(1) of the German Fiscal Code (AO)). In the case of data disclosed to us by the client in connection with an assignment, we delete the data in accordance with the terms of the assignment, generally upon completion of the assignment.
Performance of Contractual Obligations
We process master data (e.g., names, addresses, and contact information of users) and contract data (e.g., services used, names of contact persons, payment information) for the purpose of fulfilling our contractual obligations and providing services in accordance with Article 6(1)(b) of the GDPR. The fields marked as required in online forms are necessary for the conclusion of the contract.
When you use our online services, we store the IP address and the time of the respective user action. This storage is based on our legitimate interests, as well as the users’ interests in protection against misuse and other unauthorized use. This data is generally not disclosed to third parties, unless such disclosure is necessary to pursue our legal claims or there is a legal obligation to do so pursuant to Article 6(1)(c) of the GDPR.
We process usage data (e.g., the web pages visited on our online platform, interest in our products) and content data (e.g., entries in the contact form or user profile) for advertising purposes within a user profile in order to display, for example, product recommendations based on the services the user has previously used.
The data is deleted after the expiration of statutory warranty obligations and comparable obligations; the necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, the data is deleted after their expiration. Information in any customer account remains until the account is deleted.
Administration, Financial Accounting,
Office Organization, Contact Management
We process data in connection with administrative tasks, the organization of our operations, financial accounting, and compliance with legal obligations, such as archiving. In doing so, we process the same data that we process in connection with the provision of our contractual services. The legal bases for processing are Article 6(1)(c) of the GDPR and Article 6(1)(f) of the GDPR. This processing affects customers, prospective customers, business partners, and website visitors. The purpose and our interest in the processing lie in administration, financial accounting, office organization, and data archiving—that is, tasks that serve to maintain our business operations, fulfill our responsibilities, and provide our services. The deletion of data related to contractual services and contractual communication is in accordance with the information provided regarding these processing activities.
In this context, we disclose or transfer data to tax authorities, advisors (such as tax consultants or auditors), as well as other fee-collecting agencies and payment service providers.
Furthermore, based on our business interests, we store information about suppliers, event organizers, and other business partners, e.g., for the purpose of contacting them at a later date. We generally store this data—which is predominantly company-related—on a permanent basis.
Business Analyses and Market Research
In order to operate our business efficiently and to identify market trends as well as customer and user preferences, we analyze the data we have on business transactions, contracts, inquiries, etc. In doing so, we process inventory data, communication data, contract data, payment data, usage data, and metadata on the basis of Article 6(1)(f) of the GDPR, whereby the data subjects include customers, prospective customers, business partners, visitors, and users of our online services.
The analyses are conducted for the purposes of business evaluations, marketing, and market research. In doing so, we may take into account the profiles of registered users, including information such as their purchase history. The analyses help us improve user-friendliness, optimize our offerings, and enhance operational efficiency. The analyses are used solely by us and are not disclosed externally, unless they consist of anonymous analyses with aggregated data.
If these analyses or profiles contain personally identifiable information, they will be deleted or anonymized upon termination of the user’s account; otherwise, they will be deleted two years after the conclusion of the contract. In all other cases, overall business analyses and general trend assessments are conducted anonymously whenever possible.
Privacy Notice for the Application Process
We process applicant data solely for the purpose of and within the scope of the application process, in accordance with legal requirements. The processing of applicant data is carried out to fulfill our (pre)contractual obligations within the scope of the application process pursuant to Article 6(1)(b) and Article 6(1)(f) of the GDPR, provided that data processing becomes necessary for us, for example, in the context of legal proceedings (in Germany, § 26 BDSG also applies).
The application process requires that applicants provide us with their application data. The necessary application data is indicated, if we offer an online form; otherwise, it is derived from the job descriptions and generally includes personal information, mailing and contact addresses, and the documents accompanying the application, such as a cover letter, resume, and certificates. In addition, applicants may voluntarily provide us with additional information.
By submitting their application to us, applicants consent to the processing of their data for the purposes of the application process in accordance with the manner and scope set forth in this Privacy Policy.
To the extent that special categories of personal data within the meaning of Article 9(1) of the GDPR are voluntarily provided as part of the application process, their processing is additionally carried out in accordance with Article 9(2)(b) of the GDPR (e.g., health data, such as severe disability status or ethnic origin).
To the extent that special categories of personal data within the meaning of Article 9(1) of the GDPR are requested from applicants as part of the application process, their processing is additionally carried out in accordance with Article 9(2)(a) of the GDPR (e.g., health data, if such data is necessary for the performance of the job).
If available, applicants may submit their applications to us via an online form on our website. The data is transmitted to us using state-of-the-art encryption.
Applicants may also submit their applications to us via email. However, please note that emails are generally not sent in encrypted form, and applicants must ensure encryption themselves. We therefore cannot assume any responsibility for the transmission of the application between the sender and our server, and we therefore recommend using an online form or sending the application by mail. In addition to applying via the online form or email, applicants still have the option of sending their application to us by mail.
The data provided by applicants may be further processed by us for the purposes of the employment relationship in the event of a successful application. Otherwise, if the application for a job opening is unsuccessful, the applicants’ data will be deleted. Applicants’ data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time.
Subject to a valid revocation by the applicant, the data will be deleted after a period of six months has elapsed, so that we can answer any follow-up questions regarding the application and fulfill our record-keeping obligations under the Equal Treatment Act. Invoices for any travel expense reimbursements will be archived in accordance with tax regulations.
Contact Us
When you contact us (e.g., via the contact form, email, phone, or social media), your information is processed in accordance with Article 6(1)(b) of the GDPR to handle and process your inquiry. Your information may be stored in a customer relationship management system (“CRM system”) or a comparable inquiry management system.
We delete the inquiries once they are no longer necessary. We review their necessity every two years; furthermore, statutory archiving requirements apply.
Google reCAPTCHA
We use “Google reCAPTCHA” on our website, a service designed to detect bots and prevent abusive automated submissions to our contact form. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Depending on the technical configuration, processing may also be carried out by Google’s affiliates, in particular Google LLC, USA. reCAPTCHA is used to verify whether entries in our contact form are made by a human or, in an abusive manner, through automated processing. For this purpose, reCAPTCHA processes personal data and technical information, such as the IP address, referrer information, details about the browser and operating system, language settings, mouse movements, keystrokes, time spent on the page, screen and window resolution, as well as other interaction and device data. This may also include the cookie _grecaptcha set or read.
This data is processed to protect our website and our forms from spam, misuse, and automated attacks.
Legal Basis
This processing is based on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may revoke your consent at any time with future effect.
To the extent that personal data is transferred to the United States, this is done in accordance with the applicable data protection safeguards. For more information on Google’s data processing practices, please refer to Google’s Privacy Policy and the information on reCAPTCHA.
Google Analytics
Based on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic operation of our online service within the meaning of Article 6(1)(f) of the GDPR), we use Google Analytics, a web analytics service provided by Google LLC (“Google”). Google uses cookies. The information generated by the cookie regarding users’ use of the online service is generally transmitted to a Google server in the United States and stored there.
Google is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
Google will use this information on our behalf to evaluate how users use our online service, to compile reports on activity within this online service, and to provide us with other services related to the use of this online service and Internet usage. In doing so, pseudonymous user profiles may be created from the processed data.
We use Google Analytics only with IP anonymization enabled. This means that users’ IP addresses are truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the United States and truncated there.
The IP address transmitted by the user’s browser is not combined with other data held by Google. Users can prevent the storage of cookies by adjusting their browser settings accordingly; users can also prevent Google from collecting the data generated by the cookie and related to their use of the online service, as well as from processing this data, by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
For more information on Google’s use of data, as well as options for settings and opting out, please refer to Google’s Privacy Policy (https://policies.google.com/technologies/ads) and the settings for Google’s display of advertisements (https://adssettings.google.com/authenticated).Users’ personal data is deleted or anonymized after 14 months.
Google AdWords and Conversion Tracking
Based on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic operation of our online services within the meaning of Article 6(1)(f) of the GDPR), we use the services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).
Google is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
We use Google’s “AdWords” online marketing service to place ads on the Google Display Network (e.g., in search results, in videos, on websites, etc.) so that they are shown to users who are likely to be interested in the ads. This allows us to display ads for and within our online service in a more targeted manner, so that users are shown only ads that potentially match their interests. For example, if a user is shown ads for products they have previously shown interest in on other websites, this is referred to as “remarketing.” For these purposes, when our website or other websites where the Google Display Network is active are accessed, a Google code is executed directly by Google, and so-called (re)marketing tags (invisible graphics or code, also known as “web beacons”) are embedded into the website. With their help, an individual cookie—that is, a small file—is stored on the user’s device (comparable technologies may also be used instead of cookies). This file records which websites the user has visited, what content they are interested in, and which offers the user has clicked on, as well as technical information about the browser and operating system, referring websites, visit duration, and other details regarding the use of the online service.
We also receive an individual “conversion cookie.” Google uses the information collected via this cookie to generate conversion statistics for us. However, we only receive the anonymous total number of users who clicked on our ad and were redirected to a page tagged with a conversion tracking tag. However, we do not receive any information that can be used to personally identify users.
User data is processed pseudonymously within the Google Display Network. This means that Google does not, for example, store or process users’ names or email addresses, but rather processes the relevant data on a cookie-by-cookie basis within pseudonymous user profiles. This means that, from Google’s perspective, the ads are not managed and displayed for a specifically identified individual, but rather for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly permitted Google to process the data without this pseudonymization. The information collected about users is transmitted to Google and stored on Google’s servers in the United States.
For more information on Google’s use of data, as well as options for settings and opting out, please refer to Google’s Privacy Policy (https://policies.google.com/technologies/ads) and the settings for Google’s ad display (https://adssettings.google.com/authenticated).
Social Media Presence
We maintain online presences on social networks and platforms to communicate with customers, prospective customers, and users who are active there and to inform them about our services. When accessing the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.
Unless otherwise specified in our Privacy Policy, we process users’ data when they communicate with us on social networks and platforms, e.g., by posting on our online presences or sending us messages.
Integration of Third-Party Services and Content
Within our online offering, we rely on our legitimate interests (i.e., our interest in the analysis, optimization, and economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR) to integrate content or services from third-party providers, such as videos or fonts (hereinafter collectively referred to as “Content”).
This always requires that the third-party providers of this Content collect the users’ IP addresses, as they would be unable to send the Content to the users’ browsers without the IP address. The IP address is therefore necessary for the display of this Content. We make every effort to use only such content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. These “pixel tags” allow information such as visitor traffic on the pages of this website to be analyzed. This pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, time of visit, and other details regarding the use of our online service; it may also be linked to such information from other sources.
Vimeo
We may embed videos from the “Vimeo” platform provided by Vimeo Inc., Attention: Legal Department, 555 West 18th Street, New York, New York 10011, USA. Privacy Policy: https://vimeo.com/privacy. Please note that Vimeo may use Google Analytics; for more information, please refer to the privacy policy (https://www.google.com/policies/privacy) as well as the opt-out options for Google Analytics (http://tools.google.com/dlpage/gaoptout?hl=de) or Google’s settings for data use for marketing purposes (https://adssettings.google.com/.).
YouTube
We embed videos from the “YouTube” platform provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.
JWPlayer
Our website incorporates a plugin from the video portal JWPlayer, LongTail Ad Solutions, Inc., d/b/a JW Player, 2 Park Avenue, 10th Floor, New York, NY 10016, USA. Every time you visit a page that features one or more JWPlayer video clips, a direct connection is established between your browser and a JWPlayer server in the United States. Information about your visit and your IP address is stored there. When you interact with the JWPlayer plugins (e.g., by clicking the play button), this information is also transmitted to JWPlayer and stored there.
The JWPlayer privacy policy, which contains more detailed information about the collection and use of your data by JWPlayer, can be found here.
In addition, JWPlayer calls the Google Analytics tracker via an iFrame in which the video is displayed. This is JWPlayer’s own tracking system, to which we have no access. You can prevent tracking by Google Analytics by using the opt-out tools that Google offers for certain web browsers. Users can also prevent Google from collecting the data generated by Google Analytics and related to their use of the website (including your IP address), as well as prevent Google from processing this data, by downloading and installing the available browser plugin.
View and change cookie consent