Privacy Policy

1. Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on data protection can be found in our privacy policy listed below this text.

Data Collection on this Website

Who is responsible for the data collection on this website?

The data processing on this website is carried out by the website operator. You can find their contact details in the section „Notice regarding the responsible party“ in this privacy policy.

How do we collect your data?

Your data is collected firstly by you providing it to us. This could, for example, be data you enter in a contact form.

Other data is collected automatically or after your consent when you visit the website by our IT systems. This is primarily technical data (e.g., internet browser, operating system, or the time of page access). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right to obtain information about the origin, recipients, and purpose of your stored personal data at any time, free of charge. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time for further questions on the subject of data protection.

Analytics and Third-Party Tools

When visiting this website, your surfing behavior may be statistically analyzed. This is mainly done with so-called analytics programs.

Detailed information about these analytics programs can be found in the following privacy policy.

2. Hosting

This website is hosted externally. The personal data collected on this website is stored on the host’s servers. This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses, and other data generated through a website.

External hosting is carried out for the purpose of fulfilling contracts with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of the secure, fast, and efficient provision of our online services by a professional provider (Art. 6 para. 1 lit. f GDPR). If consent has been requested, processing is based exclusively on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDG, insofar as the consent includes the storage of cookies or access to information in the user’s device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be revoked at any time.

Our hoster(s) will only process your data to the extent necessary to fulfill their service obligations and follow our instructions regarding this data.

We use the following host(s):

Websupport sro
Karadžičova 12
821 08 Bratislava
Slovakia

Data Processing Agreement

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required under data protection law that ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

3. General Information and Mandatory Notices

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.

We point out that data transmission over the Internet (e.g., when communicating via email) can have security gaps. A complete protection of data against access by third parties is not possible.

Notice regarding the responsible party

The responsible party for data processing on this website is:

A for M design s.r.o.
Pri kríži 2190/6
Bratislava – mestská časť Dúbravka 841 02

Phone: +421 901 123 456
Email: info@modelarka.eu

The responsible entity is the natural or legal person who, alone or together with others, decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Period

Unless a more specific storage period has been mentioned within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke your consent to data processing, your data will be deleted, provided we have no other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, deletion will occur after these reasons no longer apply.

General Information on the Legal Basis for Data Processing on This Website

If you have consented to data processing, we process your personal data based on Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, provided special categories of data according to Art. 9 para. 1 GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information in your end device (e.g., via device fingerprinting), data processing is additionally carried out based on § 25 para. 1 TDDG. Consent can be revoked at any time. If your data is necessary for contract fulfillment or pre-contractual measures, we process your data based on Art. 6 para. 1 lit. b GDPR. Furthermore, we process your data if it is necessary for fulfilling a legal obligation based on Art. 6 para. 1 lit. c GDPR. Data processing can also be based on our legitimate interest under Art. 6 para. 1 lit. f GDPR. The respective applicable legal basis for data processing is explained in this privacy policy.

Note on Data Transfer to Non-Secure Third Countries and Transfer to US Companies Not Certified Under the DPF

We use tools from companies based in data protection non-secure third countries, as well as US tools, whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to these countries and processed there. We note that data protection laws in these non-secure third countries cannot guarantee a level of protection comparable to the EU.

We point out that the USA, as a generally secure third country, provides a data protection level comparable to the EU. Data transfer to the USA is permissible if the recipient has certification under the „EU-US Data Privacy Framework“ (DPF) or possesses appropriate additional safeguards. Information about transfers to third countries, including the data recipients, can be found in this privacy policy.

Recipients of Personal Data

In the course of our business activities, we work with various external entities. In some cases, the transmission of personal data to these external entities is necessary. We only transfer personal data to external entities when it is necessary for contract fulfillment, when we are legally obliged to do so (e.g., transfer of data to tax authorities), when we have a legitimate interest in the transfer under Art. 6 para. 1 lit. f GDPR, or when another legal basis permits the data transfer. When using processors, we only transfer personal data of our customers based on a valid processing agreement. In the case of joint processing, a joint processing contract will be concluded.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You can revoke an already given consent at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING SERVES TO ASSERT, EXERCISE, OR DEFEND LEGAL CLAIMS (OBJECTION UNDER ART. 21 PARA. 1 GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH ADVERTISING PURPOSES; THIS ALSO APPLIES TO PROFILING, INSOFAR AS IT IS ASSOCIATED WITH SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION UNDER ART. 21 PARA. 2 GDPR).

Right to File Complaints with Regulatory Authorities

If there is a breach of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, particularly in the member state of their habitual residence, workplace, or the place of the alleged violation. This right to lodge a complaint is without prejudice to any other administrative or judicial remedies.

Right to Data Portability

You have the right to receive data that we process based on your consent or in fulfillment of a contract in a commonly used, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done if technically feasible.

Access, Rectification, and Deletion

You have the right to receive information about your stored personal data at any time, free of charge, including its origin, recipient, and purpose of the data processing, as well as a right to rectification or deletion of this data. For this purpose, and for any other questions regarding personal data, you can contact us at any time.

Right to Restrict Processing

You have the right to request the restriction of the processing of your personal data. For this purpose, you can contact us at any time. The right to restrict processing applies in the following cases:

  • If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. During the verification period, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you may request the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you need it to exercise, defend, or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
  • If you have filed an objection under Art. 21 para. 1 GDPR, a balance must be struck between your interests and ours. As long as it is not clear whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data may – apart from being stored – only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a member state.

SSL or TLS Encryption

This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser’s address bar changes from „http://“ to „https://“ and by the lock symbol in your browser bar.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Objection to Advertising Emails

We hereby object to the use of contact data published within the scope of the legal notice requirement for sending unsolicited advertising and informational materials. The operators of the pages expressly reserve the right to take legal action in the event of unsolicited promotional information, such as spam emails.

4. Data Collection on This Website

Cookies

Our website uses so-called „cookies.“ Cookies are small data packets that do no harm to your device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on your device. Session cookies are automatically deleted after your visit. Persistent cookies remain on your device until you delete them or they are automatically deleted by your web browser.

Cookies can be set by us (first-party cookies) or by third-party companies (so-called third-party cookies). Third-party cookies enable the integration of specific services from third-party companies within websites (e.g., cookies for processing payment services).

Cookies serve various purposes. Many cookies are technically necessary because certain website functions would not work without them (e.g., the shopping cart function or displaying videos). Other cookies may be used to analyze user behavior or for advertising purposes.

Cookies that are required for electronic communication, the provision of certain functions requested by you (e.g., the shopping cart function), or the optimization of the website (e.g., cookies for audience measurement) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically flawless and optimized provision of its services. If consent for the storage of cookies and similar recognition technologies was requested, the processing is based exclusively on this consent (Art. 6(1)(a) GDPR and § 25(1) TDDG); consent can be revoked at any time.

You can configure your browser to inform you when cookies are set and to allow cookies only in individual cases, exclude the acceptance of cookies for specific cases or in general, and enable the automatic deletion of cookies when the browser is closed. If cookies are disabled, the functionality of this website may be limited.

You can find more information about the cookies and services used on this website in this privacy policy.

Server Log Files

The provider of these pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

These data are not combined with other data sources.

The collection of these data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically flawless presentation and optimization of the website — for this, the server log files must be collected.

Contact Form

If you submit inquiries to us via the contact form, your information from the inquiry form, including the contact details you provide, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.

The processing of these data is based on Art. 6(1)(b) GDPR, if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), if it was requested; consent can be revoked at any time.

The data you enter in the contact form will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g., after the processing of your request is completed). Mandatory legal provisions — particularly retention periods — remain unaffected.

Inquiry by Email, Phone, or Fax

If you contact us by email, phone, or fax, your inquiry, including all resulting personal data (name, inquiry), will be stored and processed by us for the purpose of handling your request. We do not share this data without your consent.

The processing of these data is based on Art. 6(1)(b) GDPR, if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of inquiries directed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR), if it was requested; consent can be revoked at any time.

The data you send to us via contact inquiries will remain with us until you request us to delete it, revoke your consent to store it, or the purpose for storing the data no longer applies (e.g., after the processing of your request is completed). Mandatory legal provisions — particularly statutory retention periods — remain unaffected.

5. Social Media

Facebook

Elements of the Facebook social network are integrated on this website. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. However, according to Facebook, the collected data is also transferred to the USA and other third countries.

You can find an overview of Facebook social media elements here: https://developers.facebook.com/docs/plugins/?locale=de_DE.

If the social media element is active, a direct connection is established between your device and the Facebook server. As a result, Facebook receives information that you have visited this website with your IP address. If you click the Facebook „Like-Button“ while logged into your Facebook account, you can link the content of this website to your Facebook profile. This allows Facebook to associate your visit to this website with your user account. We would like to point out that we, as the provider of these pages, have no knowledge of the content of the data transmitted, nor its use by Facebook. Further information can be found in Facebook’s privacy policy: https://de-de.facebook.com/privacy/explanation.

The use of this service is based on your consent under Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TDDG. The consent can be revoked at any time.

As far as personal data is collected on our website using the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 DSGVO). Joint responsibility is limited exclusively to the collection of data and its transmission to Facebook. The processing by Facebook after forwarding is not part of the joint responsibility. Our jointly binding obligations are set out in an agreement on joint processing. The wording of the agreement can be found here: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the privacy information regarding the use of the Facebook tool and for its secure implementation on our website. Facebook is responsible for the data security of its products. You can exercise your data subject rights (e.g., requests for information) regarding data processed by Facebook directly with Facebook. If you assert data subject rights with us, we are obligated to forward these requests to Facebook.

The data transfer to the USA is based on the standard contractual clauses of the European Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381, and https://www.facebook.com/policy.php.

The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA to ensure compliance with European data protection standards for data processing in the USA. Each company certified under the DPF commits to comply with these data protection standards. For more information, you can visit the provider’s link: https://www.dataprivacyframework.gov/participant/4452.

Instagram

Functions of the Instagram service are integrated on this website. These functions are provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

If the social media element is active, a direct connection between your device and the Instagram server is established. As a result, Instagram receives information about your visit to this website.

If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the data transmitted, nor its use by Instagram.

The use of this service is based on your consent under Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TDDG. The consent can be revoked at any time.

As far as personal data is collected on our website using the tool described here and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are jointly responsible for this data processing (Art. 26 DSGVO). Joint responsibility is limited exclusively to the collection of data and its transmission to Facebook or Instagram. The processing by Facebook or Instagram after forwarding is not part of the joint responsibility. Our jointly binding obligations are set out in an agreement on joint processing. The wording of the agreement can be found here: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the privacy information regarding the use of the Facebook or Instagram tool and for its secure implementation on our website. Facebook is responsible for the data security of the Facebook or Instagram products. You can exercise your data subject rights (e.g., requests for information) regarding data processed by Facebook or Instagram directly with Facebook. If you assert data subject rights with us, we are obligated to forward these requests to Facebook.

The data transfer to the USA is based on the standard contractual clauses of the European Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/, and https://de-de.facebook.com/help/566994660333381.

Further information can be found in Instagram’s privacy policy: https://privacycenter.instagram.com/policy/.

The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA to ensure compliance with European data protection standards for data processing in the USA. Each company certified under the DPF commits to comply with these data protection standards. For more information, you can visit the provider’s link: https://www.dataprivacyframework.gov/participant/4452.

Pinterest

On this website, we use elements of the social network Pinterest, operated by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.

When you access a page that contains such an element, your browser establishes a direct connection to Pinterest’s servers. This social media element transmits log data to Pinterest’s servers in the USA. These log data may include your IP address, the address of the websites visited, which also contain Pinterest features, browser type and settings, the date and time of the request, your use of Pinterest, and cookies.

The use of this service is based on your consent under Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TDDG. The consent can be revoked at any time.

Further information on the purpose, scope, and further processing and use of the data by Pinterest, as well as your rights and options for protecting your privacy, can be found in Pinterest’s privacy policy: https://policy.pinterest.com/de/privacy-policy.

6. Analytics Tools and Advertising

WP Statistics

This website uses the analytics tool WP Statistics to statistically evaluate visitor traffic. The provider is Veronalabs, Tatari 64, 10134, Tallinn, Estonia (https://veronalabs.com).

WP Statistics allows us to analyze the usage of our website. WP Statistics collects, among other things, log files (IP address, referrer, browser used, user origin, search engine used) and actions performed by website visitors (e.g., clicks and views).

The data collected with WP Statistics is stored exclusively on our own server.

The use of this analytics tool is based on Art. 6 para. 1 lit. f DSGVO. We have a legitimate interest in the anonymized analysis of user behavior in order to optimize both our web offering and our advertising. If corresponding consent has been requested, processing is carried out exclusively based on Art. 6 para. 1 lit. a DSGVO and § 25 para. 1 TDDG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) as defined by the TDDG. The consent can be revoked at any time.

IP Anonymization

We use WP Statistics with anonymized IP. Your IP address is truncated so that it can no longer be directly assigned to you.

7. Plugins and Tools

Google Fonts (Local Hosting)

This page uses Google Fonts, provided by Google, for a consistent display of fonts. The Google Fonts are installed locally. There is no connection to Google servers.

For more information about Google Fonts, visit https://developers.google.com/fonts/faq and the Google Privacy Policy: https://policies.google.com/privacy?hl=de.

Google Maps

This page uses the mapping service Google Maps. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. With this service, we can embed map material on our website.

To use the features of Google Maps, it is necessary to store your IP address. This information is typically transmitted to a Google server in the USA and stored there. The provider of this page has no influence over this data transmission. When Google Maps is activated, Google may use Google Fonts for a consistent display of fonts. When you access Google Maps, your browser loads the necessary web fonts into its cache to display texts and fonts correctly.

The use of Google Maps is in the interest of an appealing presentation of our online offerings and an easy findability of the locations specified by us on the website. This constitutes a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR. If corresponding consent has been requested, processing is carried out exclusively based on Art. 6 (1) lit. a GDPR and § 25 (1) TDDG, to the extent that the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

More information on how user data is handled can be found in Google’s Privacy Policy: https://policies.google.com/privacy?hl=de.

The company has a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards in data processing in the USA. Each company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

OpenStreetMap

We use the mapping service of OpenStreetMap (OSM).

We embed the map material from OpenStreetMap on the server of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. The UK is considered a data protection-safe third country. This means that the UK has a level of data protection that corresponds to the level of data protection in the European Union. When using the OpenStreetMap maps, a connection is established to the servers of the OpenStreetMap Foundation. This may transmit your IP address and other information about your behavior on this website to the OSMF. OpenStreetMap may store cookies in your browser or use comparable recognition technologies.

The use of OpenStreetMap is in the interest of an appealing presentation of our online offerings and easy findability of the locations specified by us on the website. This constitutes a legitimate interest within the meaning of Art. 6 (1) lit. f GDPR. If corresponding consent has been requested, processing is carried out exclusively based on Art. 6 (1) lit. a GDPR and § 25 (1) TDDG, to the extent that the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be revoked at any time.

Google reCAPTCHA

We use „Google reCAPTCHA“ (hereinafter „reCAPTCHA“) on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

reCAPTCHA is used to check whether the data entry on this website (e.g., in a contact form) is made by a human or an automated program. To do this, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the site. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, duration of the website visit, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.

The reCAPTCHA analyses run entirely in the background. Website visitors are not informed that an analysis is taking place.

The storage and analysis of the data is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated scraping and SPAM. If corresponding consent has been requested, processing is carried out exclusively based on Art. 6 (1) lit. a GDPR and § 25 (1) TDDG, to the extent that the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be revoked at any time.

For more information on Google reCAPTCHA, please refer to Google’s privacy policy and terms of use at the following links: https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.

The company has a certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards in data processing in the USA. Each company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.

Cloudflare Turnstile

We use Cloudflare Turnstile (hereinafter „Turnstile“) on this website. The provider is Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA (hereinafter „Cloudflare“).

Turnstile is used to check whether the data entry on this website (e.g., in a contact form) is made by a human or an automated program. To do this, Turnstile analyzes the behavior of the website visitor based on various characteristics.

This analysis begins automatically as soon as the website visitor enters a website with Turnstile activated. For the analysis, Turnstile evaluates various information (e.g., IP address, duration of the website visit, or mouse movements made by the user). The data collected during the analysis is forwarded to Cloudflare.

The storage and analysis of the data is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings from abusive automated scraping and SPAM. If corresponding consent has been requested, processing is carried out exclusively based on Art. 6 (1) lit. a GDPR and § 25 (1) TDDG, to the extent that the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be revoked at any time.

The data processing is based on standard contractual clauses, which can be found here: https://www.cloudflare.com/cloudflare-customer-scc/.

For more information on Cloudflare Turnstile, please refer to the privacy policy at https://www.cloudflare.com/cloudflare-customer-dpa/.

The company has a certification under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the USA that aims to ensure compliance with European data protection standards in data processing in the USA. Each company certified under the DPF commits to adhering to these data protection standards. Further information can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5666.

Wordfence

We have integrated Wordfence on this website. The provider is Defiant Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA (hereinafter „Wordfence“).

Wordfence serves to protect our website from unauthorized access or malicious cyberattacks. For this purpose, our website establishes a permanent connection to the servers of Wordfence so that Wordfence can compare its databases with the accesses made on our website and block them if necessary.

The use of Wordfence is based on Art. 6 (1) lit. f GDPR. The website operator has a legitimate interest in providing effective protection for its website against cyberattacks. If corresponding consent has been requested, processing is carried out exclusively based on Art. 6 (1) lit. a GDPR and § 25 (1) TDDG, to the extent that the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TDDG. Consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.wordfence.com/help/general-data-protection-regulation/.

Real Cookie Banner

To manage the cookies and similar technologies used (tracking pixels, web beacons, etc.) and related consents, we use the consent tool „Real Cookie Banner“. Details on how „Real Cookie Banner“ works can be found at https://devowl.io/rcb/data-processing/.

The legal basis for the processing of personal data in this context are Art. 6 (1) lit. c GDPR and Art. 6 (1) lit. f GDPR. Our legitimate interest is the management of the cookies and similar technologies used and the related consents.

The provision of personal data is neither contractually required nor necessary for the conclusion of a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we will not be able to manage your consents.

Source: https://www.e-recht24.de