Privacy Policy

Data protection is of particularly high importance to AUREA TCM LTD (hereinafter referred to as the “Provider”). The Provider’s website can generally be used without providing any personal data. However, if a data subject wishes to use special services offered by our company via our website, the processing of personal data may become necessary. If the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain the consent of the data subject.

The processing of personal data, such as the name, address, email address, or telephone number of a data subject, shall always be carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to AUREA TCM LTD. By means of this privacy policy, our company would like to inform the public about the type, scope, and purpose of the personal data we collect, use, and process. Furthermore, this privacy policy informs data subjects of their rights.

As the controller responsible for processing, AUREA TCM LTD has implemented numerous technical and organizational measures to ensure the most complete protection possible of personal data processed through this website. Nevertheless, internet-based data transmissions may generally have security gaps, so absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, for example by telephone.

Definitions

The privacy policy of AUREA TCM LTD is based on the terminology used by the European legislator for directives and regulations when adopting the General Data Protection Regulation (GDPR). Our privacy policy should be easy to read and understand for the public, as well as for our customers and business partners. To ensure this, we would like to explain the terminology used in advance.

In this privacy policy, we use, among others, the following terms:

Personal Data

Personal data means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). A natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

Data Subject

A data subject is any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing.

Processing

Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Restriction of Processing

Restriction of processing means the marking of stored personal data with the aim of limiting its processing in the future.

Profiling

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

Pseudonymization

Pseudonymization means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

Controller or Controller Responsible for the Processing

Controller or controller responsible for the processing means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Processor

Processor means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

Recipient

Recipient means a natural or legal person, public authority, agency, or another body, to which the personal data is disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.

Third Party

Third party means a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

Consent

Consent means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to them.

Name and Address of the Controller

Controller for the purposes of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union, and other provisions related to data protection is:

AUREA TCM LTD
[Registered Address]
[Postal Code, Paphos)
Cyprus

Email: contact@aureatcm.com
Website: www.aureatcm.com

Cookies

The Provider’s website uses cookies. Cookies are text files that are placed and stored on a computer system via an internet browser.

Numerous websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a string of characters through which websites and servers can assign a specific internet browser in which the cookie was stored. This enables visited websites and servers to distinguish the individual browser of the data subject from other internet browsers that contain other cookies. A specific internet browser can be recognized and identified by means of the unique cookie ID.

Through the use of cookies, AUREA TCM LTD can provide the users of this website with more user-friendly services that would not be possible without the setting of cookies.

By means of a cookie, the information and offers on our website can be optimized with the user in mind. Cookies enable us, as mentioned before, to recognize the users of our website. The purpose of this recognition is to make it easier for users to use our website. For example, the user of a website that uses cookies does not have to enter access data again each time the website is accessed, because this is taken over by the website and the cookie stored on the user’s computer system. Another example is the cookie of a shopping cart in an online shop. The online shop remembers the items that a customer has placed in the virtual shopping cart by means of a cookie.

The data subject may, at any time, prevent the setting of cookies through our website by means of a corresponding setting of the internet browser used and may thus permanently object to the setting of cookies. Furthermore, cookies already set may be deleted at any time via an internet browser or other software programs. This is possible in all common internet browsers. If the data subject deactivates the setting of cookies in the internet browser used, not all functions of our website may be fully usable.

Collection of General Data and Information

The Provider’s website collects a series of general data and information each time the website is accessed by a data subject or an automated system. This general data and information is stored in the server log files. Collected may be:

    1. the browser types and versions used,

    1. the operating system used by the accessing system,

    1. the website from which an accessing system reaches our website (so-called referrers),

    1. the sub-websites,

    1. the date and time of access to the website,

    1. an Internet Protocol address (IP address),

    1. the internet service provider of the accessing system, and

    1. any other similar data and information that may be used in the event of attacks on our information technology systems.

When using these general data and information, AUREA TCM LTD does not draw any conclusions about the data subject. Rather, this information is needed in order to:

    1. deliver the contents of our website correctly,

    1. optimize the content of our website as well as advertising for it,

    1. ensure the long-term functionality of our information technology systems and website technology, and

    1. provide law enforcement authorities with the information necessary for prosecution in the event of a cyber attack.

Therefore, AUREA TCM LTD analyzes anonymously collected data and information statistically and also with the aim of increasing data protection and data security in our company, to ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files is stored separately from all personal data provided by a data subject.

Registration on Our Website

The data subject has the possibility to register on the website of the controller by providing personal data. Which personal data is transmitted to the controller is determined by the respective input form used for registration. The personal data entered by the data subject is collected and stored exclusively for internal use by the controller and for its own purposes. The controller may arrange for the transfer to one or more processors, for example a parcel service provider, who will also use the personal data exclusively for internal use attributable to the controller.

By registering on the website of the controller, the IP address assigned by the internet service provider (ISP) of the data subject, the date, and the time of registration are also stored. The storage of this data takes place against the background that only in this way can misuse of our services be prevented, and if necessary, these data make it possible to investigate committed offenses. In this respect, the storage of this data is necessary to secure the controller. This data is not passed on to third parties unless there is a statutory obligation to pass it on or the disclosure serves criminal prosecution.

The registration of the data subject, with the voluntary provision of personal data, is intended to enable the controller to offer the data subject content or services that, due to the nature of the matter, can only be offered to registered users. Registered persons are free to change the personal data specified during registration at any time or to have it completely deleted from the controller’s data stock.

The controller shall, at any time, provide information upon request to each data subject as to what personal data concerning the data subject is stored. Furthermore, the controller shall correct or erase personal data at the request or indication of the data subject, provided that there are no statutory retention obligations to the contrary. All employees of the controller are available to the data subject as contact persons in this context.

Contact Possibility via the Website

The Provider’s website contains information required by law that enables quick electronic contact with our company as well as direct communication with us, which also includes a general electronic mail address contact@aureatcm.com. If a data subject contacts the controller by email or via a contact form, the personal data transmitted by the data subject is automatically stored. Such personal data transmitted on a voluntary basis by a data subject to the controller is stored for the purpose of processing or contacting the data subject. This personal data is not passed on to third parties.

Data Protection in Applications and the Application Process

The controller collects and processes the personal data of applicants for the purpose of handling the application process. Processing may also take place electronically. This is particularly the case if an applicant submits corresponding application documents electronically, for example by email or by means of a web form on the website, to the controller.

If the controller concludes an employment contract with an applicant, the transmitted data will be stored for the purpose of processing the employment relationship in compliance with statutory provisions. If the controller does not conclude an employment contract with the applicant, the application documents shall be automatically erased two months after notification of the rejection decision, provided that no other legitimate interests of the controller oppose the erasure. Another legitimate interest in this sense is, for example, a burden of proof in proceedings under anti-discrimination law.

Routine Erasure and Blocking of Personal Data

The controller shall process and store the personal data of the data subject only for the period necessary to achieve the storage purpose, or insofar as this is provided for by the European legislator for directives and regulations or another legislator in laws or regulations to which the controller is subject.

If the storage purpose ceases to apply or if a storage period prescribed by the European legislator or another competent legislator expires, the personal data shall be routinely blocked or erased in accordance with legal requirements.

Rights of the Data Subject

Right to Confirmation

Every data subject shall have the right granted by the European legislator to obtain from the controller confirmation as to whether or not personal data concerning them is being processed. If a data subject wishes to exercise this right of confirmation, they may, at any time, contact an employee of the controller.

Right of Access

Every data subject affected by the processing of personal data shall have the right granted by the European legislator to obtain from the controller, at any time and free of charge, information about their personal data stored and a copy of such information. Furthermore, the European legislator has granted the data subject access to the following information:

    • the purposes of the processing

    • the categories of personal data concerned

    • the recipients or categories of recipients to whom the personal data has been or will be disclosed, in particular recipients in third countries or international organizations

    • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period

    • the existence of the right to request rectification or erasure of personal data, or restriction of processing, or to object to such processing

    • the existence of the right to lodge a complaint with a supervisory authority

    • where the personal data is not collected from the data subject: any available information as to its source

    • the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject

Furthermore, the data subject shall have a right to obtain information as to whether personal data is transferred to a third country or to an international organization. Where this is the case, the data subject shall also have the right to be informed of the appropriate safeguards relating to the transfer.

If a data subject wishes to exercise this right of access, they may, at any time, contact an employee of the controller.

Right to Rectification

Every data subject shall have the right granted by the European legislator to obtain from the controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Right to Erasure (Right to be Forgotten)

Every data subject shall have the right granted by the European legislator to obtain from the controller the erasure of personal data concerning them without undue delay where one of the following grounds applies, as long as the processing is not necessary:

    • the personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed

    • the data subject withdraws consent on which the processing is based and where there is no other legal ground for the processing

    • the data subject objects to the processing and there are no overriding legitimate grounds for the processing

    • the personal data has been unlawfully processed

    • the personal data must be erased for compliance with a legal obligation

    • the personal data has been collected in relation to the offer of information society services to a child

If one of the above reasons applies and a data subject wishes to request the erasure of personal data stored by AUREA TCM LTD, they may, at any time, contact an employee of the controller. An employee of AUREA TCM LTD shall promptly ensure that the erasure request is complied with immediately.

Where personal data has been made public by AUREA TCM LTD and our company, as controller, is obliged pursuant to Article 17(1) GDPR to erase the personal data, AUREA TCM LTD shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other controllers processing the published personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data, insofar as processing is not required.

Right to Restriction of Processing

Every data subject shall have the right granted by the European legislator to obtain from the controller restriction of processing where one of the following applies:

    • the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data

    • the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead

    • the controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise, or defense of legal claims

    • the data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject

If one of the aforementioned conditions is met, a data subject may, at any time, contact an employee of the controller to request restriction of processing.

Right to Data Portability

Every data subject shall have the right granted by the European legislator to receive the personal data concerning them, which was provided to a controller, in a structured, commonly used, and machine-readable format. They shall have the right to transmit those data to another controller without hindrance from the controller to which the personal data has been provided, as long as the processing is based on consent or on a contract and the processing is carried out by automated means, provided that the processing is not necessary for the performance of a task carried out in the public interest.

Furthermore, in exercising their right to data portability pursuant to Article 20(1) GDPR, the data subject shall have the right to have personal data transmitted directly from one controller to another, where technically feasible and when doing so does not adversely affect the rights and freedoms of others.

Right to Object

Every data subject shall have the right granted by the European legislator to object, on grounds relating to their particular situation, at any time, to processing of personal data concerning them based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions.

AUREA TCM LTD shall no longer process the personal data in the event of the objection, unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.

If AUREA TCM LTD processes personal data for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning them for such marketing. This applies to profiling insofar as it is related to such direct marketing. If the data subject objects to AUREA TCM LTD to the processing for direct marketing purposes, AUREA TCM LTD will no longer process the personal data for these purposes.

In addition, the data subject has the right, on grounds relating to their particular situation, to object to processing of personal data concerning them for scientific or historical research purposes, or for statistical purposes, unless such processing is necessary for the performance of a task carried out for reasons of public interest.

Automated Individual Decision-Making, Including Profiling

Every data subject shall have the right granted by the European legislator not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them, or similarly significantly affects them, unless the decision:

    1. is necessary for entering into, or performance of, a contract between the data subject and the controller,

    1. is authorized by Union or Member State law, or

    1. is based on the data subject’s explicit consent.

If the decision is necessary for entering into, or performance of, a contract, or is based on the data subject’s explicit consent, AUREA TCM LTD shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention, to express their point of view, and to contest the decision.

Right to Withdraw Data Protection Consent

Every data subject shall have the right granted by the European legislator to withdraw consent to the processing of personal data at any time.

If a data subject wishes to exercise the right to withdraw consent, they may, at any time, contact an employee of the controller.

Special Data Protection Provisions

Data Protection Provisions on the Use of ActiveCampaign

The controller has integrated components of ActiveCampaign on this website. ActiveCampaign, LLC (“ActiveCampaign”) is a marketing platform that enables users to reach their customers and understand how customers interact with communications and other content. In this way, marketing can be adapted based on customer interests. ActiveCampaign collects and uses information from applicants, website visitors, and current and prospective customers when they use websites, platforms, mobile applications, and other online products and services.

Operator: ActiveCampaign LLC, 1 North Dearborn Street, 5th Floor, Chicago, IL 60602, USA.

Information is collected that you provide directly, for example when you create an account, participate in interactive features, fill out a form, make a purchase, participate in a contest or promotion, communicate with us through third-party social media websites, interact with a message board, apply for a job, request customer support, use our platform, or otherwise communicate with us. The types of information that may be collected include:

    1. identifiers such as your full name, telephone number, email address, postal address, unique personal identifier, online ID, Internet Protocol address;

    1. commercial information such as records of personal property, products or services purchased or considered, or other purchasing or consumption histories or tendencies;

    1. professional or employment-related information such as company name, company payment information, and business contact information; and

    1. any other information you choose to provide.

Log information, transaction information, device information, and information collected through cookies and other tracking technologies may also be collected. ActiveCampaign uses cookies.

ActiveCampaign engages third parties and individuals, such as payment processors, research firms, analytics providers, and security providers, to help operate and provide the services. These third parties have limited access to information about you and may use it only to perform tasks on behalf of ActiveCampaign.

To provide you with the services you subscribe to or request from us, information about you may be transferred to ActiveCampaign locations in the United States, Australia, and Ireland, as well as to countries in which service providers are located.

You have the right to withdraw your consent to the processing of your personal data if we process it based on your consent.

Data Protection Provisions on the Use of Borlabs Cookie

The controller has integrated components of Borlabs on this website in the form of a cookie banner.

Operator: Borlabs – Benjamin A. Bornschein, Rübenkamp 32, 22305 Hamburg, Germany.

Borlabs Cookie does not process any personal data. The cookie borlabs-cookie stores the consents you gave when entering the website. The cookie stores information such as cookie runtime, cookie version, domain and path of the WordPress website, consents, and UID. If you wish to withdraw these consents, simply delete the cookie in your browser. When you re-enter or reload the website, you will be asked again for your cookie consent.

Data Protection Provisions on the Use of Calendly

The controller has integrated components of Calendly on this website. Calendly is a subscription-based scheduling software in the form of an online calendar that enables meetings to be scheduled easily and efficiently.

Operator: Calendly LLC, BB&T Tower, 271 17th St NW #1000, Atlanta, GA 30363, USA.

When using the tool, personal data such as name, email address, and telephone number may be requested. There is also the possibility to describe concerns and provide further information. If you use the tool, the information you enter in the Calendly form, including the data you provide there, will be stored on this website and by Calendly for the purpose of processing the request and in case of follow-up questions. Data of Calendly users and invitees are stored in data centers in the United States provided by Amazon Web Services (AWS) and Google (selected backups). All browser connections to the Calendly platform are encrypted during transmission. Processing of the data entered is carried out exclusively on the basis of your consent pursuant to Article 6(1)(a) GDPR.

Data Protection Provisions on the Use of ClickFunnels

The controller has integrated components of ClickFunnels on this website.

Operator: Etison, LLC, ATTN: Legal & Compliance Department, 3443 W. Bavaria Street, Eagle, Idaho 83616, USA.

When users visit this website, various personal data may be collected. When accessing the website, the browser used on the user’s device automatically sends information to the server of this website, which is temporarily stored in a so-called log file. This may include the IP address, date and time of access, the name and URL of the retrieved file, and the browser used. Storage of the data takes place to ensure a smooth connection to the website, convenient use of the website, evaluation of system security and stability, and for other administrative purposes. ClickFunnels uses cookies on the website.

Data Protection Provisions on the Use of CopeCart

The controller has integrated CopeCart on this website. CopeCart is shop software that enables companies to sell digital and physical products and services.

Operator: CopeCart GmbH, Ufnaustraße 10, 10553 Berlin, Germany.

If a user purchases a product or service from the controller, a purchase contract is concluded. However, data required for processing the purchase is received not only by the seller, but also by the CopeCart platform. In this context, personal data such as names, addresses, email addresses, payment data, and telephone numbers may be transmitted to a third party.

The controller has concluded a data processing agreement with CopeCart. The collection of personal data via CopeCart takes place in order to ensure smooth processing of purchase contracts, analyze sales behavior, and continuously optimize the offer and website.

Data Protection Provisions on the Use of Digistore24

The controller has integrated Digistore24 on this website. Digistore24 is an online sales platform offering an integrated online shop, common payment methods, accounting simplification including tax automation, and an affiliate network.

Operator: Digistore24 GmbH, St.-Godehard-Str. 32, 31139 Hildesheim, Germany.

Digistore24 automatically collects data and information from the computer system of the accessing computer whenever the user website is accessed. This includes information about the browser type and version, operating system, internet service provider, IP address, date and time of access, and websites from which the user reached our website.

Digistore24 uses cookies. Some cookies are stored until the end of the session to enable login or ordering processes. Other cookies may be stored for up to 185 days for affiliate tracking, screen size, permissions, prevention of duplicate orders, language settings, “stay logged in” functionality, and shopping cart contents.

Data Protection Provisions on the Use of Dropbox

The controller has integrated Dropbox on this website. Dropbox is a file-hosting online service that enables the storage, sharing, and editing of documents in the cloud.

Operator: Dropbox International Unlimited Company, One Park Place, Floor 5, Upper Hatch Street, Dublin 2, Ireland.

Dropbox stores, processes, and transmits content and files, as well as related information such as profile information, file size, upload time, collaborators, and usage activity. Dropbox also collects data about how customers use the services, device data, IP addresses, and potentially location data, depending on device settings. Dropbox uses cookies and other technologies to provide, improve, protect, and market its services.

Data Protection Provisions on the Use of Elementor

The controller has integrated components of Elementor on this website. Elementor is a website builder for WordPress.

Operator: Elementor Ltd., 2600 Flatbush Ave, Brooklyn, New York, 11234, USA.

Elementor collects information in various ways: when users visit the website, use the services, and use the software. This may include payment information, browser and device information, IP address, usage behavior, site settings, WordPress version, plugin information, template counts, and related technical information. Elementor may process personal data in different countries, including outside the EEA.

Data Protection Provisions on the Use of elopage

The controller has integrated components of elopage on this website.

Operator: elopage GmbH, Kurfürstendamm 182, 10707 Berlin, Germany.

If users visit websites without registering as a customer or otherwise explicitly transmitting information, elopage processes the data transmitted with each browser request. If users expressly submit personal data, for example via a contact form, this is done exclusively for the purpose of the request or contract. elopage may use cookies to enable certain website functions.

Data Protection Provisions on the Use of Facebook

The controller has integrated Facebook components on this website. Facebook is a social network.

Operator: Facebook, Inc., 1 Hacker Way, Menlo Park, CA 94025, USA; for persons outside the USA and Canada: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Whenever a page of this website containing a Facebook component is accessed, the browser automatically downloads a display of the Facebook component. Through this technical procedure, Facebook receives knowledge of which specific subpage of our website was visited by the data subject. If the data subject is logged in to Facebook at the same time, Facebook can associate the visit with the user’s Facebook account.

Data Protection Provisions on the Use of Facebook Pixel

The controller has integrated Facebook Pixel on this website. The Facebook Pixel is a piece of JavaScript code that allows Facebook to track user actions if the user arrived on the website via Facebook Ads.

Operator: Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

With the help of Facebook Pixel, advertising measures can be better aligned with user interests. Facebook users may see relevant advertising, provided they have allowed personalized ads. Facebook also uses the collected data for analysis and its own advertising purposes.

Data Protection Provisions on the Use of Funnelcockpit

The controller has integrated Funnelcockpit on this website.

Operators:
Just Viral GmbH & Co. KG, Reinholdstraße 5, 21073 Hamburg, Germany
Denis Hoeger Caballero, Nobelstr. 3–5, 41189 Mönchengladbach, Germany
Marius Gebhardt, Nagelsweg 22, 20097 Hamburg, Germany

When users visit the website, personal data such as IP address, date and time of access, file name and URL, and browser information may be collected in log files. Funnelcockpit also uses cookies.

Data Protection Provisions on the Use of Google AdSense

The controller has integrated Google AdSense on this website. Google AdSense is an online service that enables the placement of advertising on third-party sites.

Operator: Alphabet Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

Google AdSense uses cookies and web beacons. Through these technologies, personal data such as the IP address may be transmitted to Alphabet Inc. in the United States. These data may be used to analyze use of the website and for commission billing.

Data Protection Provisions on the Use of Google Ads

The controller has integrated Google Ads on this website. Google Ads is an internet advertising service that enables advertisers to place ads in Google search engine results and in the Google advertising network.

Operator: Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

If a data subject reaches our website via a Google ad, a conversion cookie is placed on the user’s device. The conversion cookie expires after 30 days and is not used for identification. Through the conversion cookie, both we and Google can track whether a purchase or another conversion took place.

Data Protection Provisions on the Use of Google Drive

The controller has integrated Google Drive on this website. Google Drive is a file-hosting service that enables the storage, sharing, and editing of documents in the cloud.

Operator: Alphabet Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

By means of cookies, personal information such as the access time, the location from which access originated, and the frequency of visits to our website may be stored. These data, including IP address, may be transmitted to Google in the United States.

Data Protection Provisions on the Use of Google reCAPTCHA

The controller has integrated Google reCAPTCHA on this website. reCAPTCHA attempts to distinguish whether an action on the internet is performed by a human or by an automated program or bot.

Operator: Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

This function primarily serves to distinguish whether an input is made by a natural person or abusively by automated processing. The service includes the transmission of the IP address and possibly other data required by Google for the reCAPTCHA service, and is based on our legitimate interest in preventing misuse and spam pursuant to Article 6(1)(f) GDPR.

Data Protection Provisions on the Use of Google+

The controller has integrated the Google+ button on this website. Google+ is a social network.

Operator: Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

When a page with a Google+ button is accessed, the browser automatically downloads the Google+ button. In this way, Google learns which specific subpage of our website the data subject visited. If the data subject is logged in to Google+ at the same time, Google can associate that visit with the corresponding Google+ account.

Data Protection Provisions on the Use of Hotjar

The controller has integrated Hotjar on this website. Hotjar is a behavior analytics company that analyzes website use and provides feedback via heatmaps, session recordings, and surveys.

Operator: Hotjar Ltd., Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta.

Hotjar helps us better understand the needs of our users and optimize the website. Hotjar collects information such as anonymized IP address, device screen size, device type, browser information, country, and preferred language. Hotjar uses cookies and other technologies. Users can prevent data collection by Hotjar by enabling “Do Not Track” or using the Hotjar opt-out option.

Data Protection Provisions on the Use of HubSpot

The controller has integrated HubSpot on this website.

Operator: HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141, USA.

Data Protection Provisions on the Use of HubSpot

HubSpot uses its own subscription services to create websites through which visitors can learn more about HubSpot. The data collected and managed by HubSpot through its subscription services for its own marketing purposes belongs to HubSpot and is processed, disclosed, and protected in accordance with its privacy policy.

Users are free to visit HubSpot websites without sharing personal data with HubSpot. However, when users visit these websites or register for subscription services, HubSpot may request that users provide personal data and may collect navigation data. HubSpot collects personal data when users submit web forms or interact with the website, for example when subscribing to a HubSpot blog, registering for a webinar, or requesting customer support. HubSpot also collects personal data when users register for a HubSpot account.

Personal data includes navigation data or payment data, where such information directly or indirectly identifies or contributes to the identification of a person. “Sensitive data” includes credit or debit card numbers, bank account or transfer information, government-issued identification numbers (such as social security or passport numbers), biometric data, health-related information, personal data of children subject to child protection laws, and any other data classified as special categories of personal data under GDPR or other applicable data protection laws.

When users access content provided by HubSpot, HubSpot automatically collects data related to the user’s hardware and software. This may include the IP address, browser type, domain name, internet service provider (ISP), files viewed (e.g. HTML pages and images), operating system, clickstream data, access times, and referring website addresses. HubSpot uses this data to generate general statistics about the use of its websites and may combine this automatically collected data with other personal data such as name, email address, address, and telephone number.

In some cases, HubSpot may receive personal data from external sources, including partners with whom HubSpot offers co-branded services or joint marketing activities.

The collected data is primarily used by HubSpot to improve and further develop its products and services, communicate with users, provide services, and supply statistical data to other companies regarding usage.

HubSpot websites may contain links to third-party websites.

The duration for which HubSpot stores user data depends on the type of information. After the relevant retention period, HubSpot either deletes or anonymizes the data. If neither is possible, the data will be securely stored and blocked from further processing until deletion becomes possible.

HubSpot retains personal data provided by users for as long as there is a legitimate business interest (e.g. to comply with legal obligations, resolve disputes, or enforce contractual agreements). If there is no longer a legitimate business interest, HubSpot will securely delete or anonymize the data. If this is not possible, the data will be securely stored and excluded from further processing until deletion is feasible. Upon request, HubSpot may delete such data earlier.

HubSpot may share data with trusted partners, for example to enable communication with users who have requested such contact, or for statistical analysis and customer support purposes.

Users have the right to request deletion of their data, access stored data, or withdraw previously given consent.

Further information and HubSpot’s applicable privacy policy can be found on HubSpot’s official website.


Data Protection Provisions on the Use of Instagram

The controller has integrated components of the Instagram service on this website. Instagram is an audiovisual platform that allows users to share photos and videos and to distribute such content across other social networks.

Operator: Instagram LLC, 1 Hacker Way, Building 14 First Floor, Menlo Park, CA, USA.

Each time a page of this website containing an Instagram component (Instagram button) is accessed, the internet browser on the data subject’s system is automatically prompted by the respective Instagram component to download a display of that component from Instagram. As part of this technical process, Instagram receives information about which specific subpage of our website was visited.

If the data subject is logged into Instagram at the same time, Instagram can recognize with each visit to our website and for the entire duration of the stay which specific subpage was visited. This information is collected by the Instagram component and assigned to the respective Instagram account of the data subject.

If the data subject clicks one of the Instagram buttons integrated on our website, the transmitted data and information are assigned to the personal Instagram account of the data subject and stored and processed by Instagram.

Instagram receives information via the Instagram component that the data subject has visited our website whenever the data subject is logged into Instagram at the time of access—regardless of whether the Instagram component is clicked or not. If such transmission is not desired, the data subject can prevent it by logging out of their Instagram account before accessing our website.

Further information and Instagram’s privacy policy can be found on Instagram’s official website.


Data Protection Provisions on the Use of JotForm

Our website uses plugins from JotForm, operated by JotForm Inc., 111 Pine St. Suite 1815, San Francisco, CA 94111, USA.

The plugin enables users to contact us via forms. When text is entered into the relevant fields and the “Send” button is clicked, the data is transmitted to us and stored on JotForm servers. The same applies to files uploaded via the form.

When visiting a page that includes a JotForm plugin, a connection is established to JotForm’s servers, and the server receives information about which page of our website was visited.

We use JotForm to ensure an appealing presentation of our online services. This constitutes a legitimate interest pursuant to Article 6(1)(f) GDPR.

Further information on how JotForm handles user data can be found in JotForm’s privacy policy.


Data Protection Provisions on the Use of Kajabi

The controller has integrated components of Kajabi on this website.

Operator: Kajabi LLC, 333 El Camino Real, Suite 200, Tustin, CA 92780, USA.

Kajabi provides online video courses, landing pages, and payment processing. It also supports the collection and management of newsletter subscribers and the analysis of newsletter campaigns.

If you enter data for newsletter subscription (e.g. name and email address), this data is stored on Kajabi servers in the United States. Data related to the use of our website, online courses, and services—such as name, email address, address, and payment data—may also be stored on Kajabi servers.

Kajabi enables analysis of newsletter campaigns. When you open an email sent via Kajabi, a file (web beacon) connects to Kajabi servers to determine whether the email was opened and which links were clicked. Technical data such as time of access, IP address, browser type, and operating system may also be collected. This data is used exclusively for statistical analysis and optimization of newsletter campaigns.

If you do not wish to be tracked by Kajabi, you must unsubscribe from the newsletter. A corresponding unsubscribe link is included in every email.

Processing is based on your consent (Article 6(1)(a) GDPR). You may withdraw this consent at any time.

The legality of the data processing operations already carried out remains unaffected by the withdrawal.

The data you have provided to us for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted both from our servers and from the servers of KAJABI after you unsubscribe from the newsletter. Data stored by us for other purposes (e.g. email addresses for the members area) remain unaffected by this.

KAJABI uses this data to provide and process payments for online video courses and to send newsletters on our behalf. In addition, the provider uses this data to optimize or improve its own services, such as technical optimization. According to our information, KAJABI does not use this data to pass it on to third parties.

The conclusion of a corresponding data processing agreement is currently in progress. KAJABI, LLC also takes data protection seriously in compliance with legal requirements under the GDPR. Further information can currently be found here:
The new “Data Processing Agreement” of KAJABI can be found here.


Data Protection Provisions regarding the Use of KlickTipp

The controller has integrated components of KlickTipp on this website. KlickTipp is a UK-based marketing automation platform and email marketing service.

Operator is KLICK-TIPP LIMITED, represented by Michael Toohig and Josef Wolosz, 15 Cambridge Court, 210 Shepherd’s Bush Road, London W6 7NJ, United Kingdom.

Information on the exact scope of services can be found at:


Data Protection Provisions regarding the Use of LinkedIn

The controller has integrated components of LinkedIn Corporation on this website. LinkedIn is an internet-based social network that enables users to connect with existing business contacts and establish new business relationships. More than 400 million registered users use LinkedIn in over 200 countries, making it currently the largest platform for business contacts and one of the most visited websites in the world.

Operator of LinkedIn is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. For data protection matters outside the USA, LinkedIn Ireland, Privacy Policy Issues, Wilton Plaza, Wilton Place, Dublin 2, Ireland is responsible.

Each time a page of our website that contains a LinkedIn component (LinkedIn plug-in) is accessed, this component causes the browser used by the data subject to download a corresponding display of the LinkedIn component. Further information about LinkedIn plug-ins can be found at:

As part of this technical process, LinkedIn receives knowledge of which specific subpage of our website was visited by the data subject.

If the data subject is logged into LinkedIn at the same time, LinkedIn recognizes with every visit to our website and for the entire duration of the stay which specific subpage was visited. This information is collected through the LinkedIn component and assigned to the respective LinkedIn account of the data subject.

If the data subject clicks a LinkedIn button integrated on our website, LinkedIn assigns this information to the personal LinkedIn user account of the data subject and stores this personal data.

LinkedIn always receives information via the LinkedIn component that the data subject has visited our website if the data subject is logged into LinkedIn at the time of accessing our website—regardless of whether the LinkedIn component is clicked or not. If such transmission is not desired, the data subject can prevent this by logging out of their LinkedIn account before accessing our website.

LinkedIn offers the option to unsubscribe from email messages, SMS messages, and targeted ads as well as to manage ad settings at:
LinkedIn also uses partners such as Quantcast, Google Analytics, BlueKai, DoubleClick, Nielsen, Comscore, Eloqua, and Lotame, which may set cookies. Such cookies can be rejected at:
The applicable data protection provisions of LinkedIn are available at:
The LinkedIn cookie policy is available at:

Data Protection Provisions regarding the Use of Memberspot

The controller has integrated components of Memberspot on this website. Memberspot is an online platform that enables coaches to create membership areas for their members.

Operator is Memberspot GmbH, Rilkestr. 26, 71642 Ludwigsburg, Germany.

Memberspot processes the personal data transmitted to it within the scope of the contractual and pre-contractual relationships between Memberspot and the respective customer. The scope, type, purpose, and necessity of processing depend on the underlying contractual relationship. Memberspot stores and processes the data in its IT systems.

The processed data includes all data provided for the purpose of using contractual or pre-contractual services and required for processing inquiries or contracts. This includes name, address, email address, telephone number, contract data, and payment data.

Processing is limited to the data necessary to respond to inquiries and/or fulfill a contract. Processing may also include special categories of personal data pursuant to Art. 9 (1) GDPR. If required, Memberspot obtains consent in accordance with Art. 9 (2)(a) GDPR.

Data is deleted as soon as it is no longer required to fulfill contractual or legal obligations, subject to statutory retention obligations.

Memberspot uses hosting providers to operate its online presence. If customers only use the website for informational purposes, only data transmitted by the browser is collected.

If customers contact Memberspot via email, social media, phone, fax, post, or contact forms and provide personal data (e.g. name, phone number, email), this data is stored and processed for handling the inquiry.

Customers have rights including deletion, access, restriction of processing, and the right to lodge a complaint.

According to Art. 7 (3) GDPR, customers have the right to withdraw their consent at any time. The withdrawal does not affect the lawfulness of processing carried out before withdrawal.

The applicable data protection provisions of Twitter can be found at:

Data Protection Provisions regarding the Use of perspective.io

The controller has integrated components of Perspective Funnels on this website.

The operating company of Perspective Funnels is Perspective Software GmbH, Müggelstraße 22, 10247 Berlin, Germany.

When users use this website, various personal data may be collected. When this website is accessed, the browser used on the users’ device automatically sends information to the server of this website. This information is temporarily stored in a so-called log file.

The information collected includes, among other things, the IP address of the requesting computer, the date and time of access, the name and URL of the requested file, and the browser used. The data is stored to ensure a smooth connection to the website, to ensure convenient use of the website, to evaluate system security and stability, and for other administrative purposes.

The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. f GDPR. The legitimate interest follows from the purposes for data collection listed above. Under no circumstances will the collected data be used for the purpose of drawing conclusions about the identity of the user.

Provided that users have expressly consented in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, Prospective Funnels uses their email address to send them newsletters on a regular basis. If users send inquiries to Prospective Funnels via the contact form, their details from the inquiry form, including the contact data provided there, are stored in Craft CMS and ActiveCampaign for the purpose of processing the inquiry and in case of follow-up questions. Perspective Funnels does not pass this data on without the users’ consent. For the storage and management of data (customer relationship management), Prospective Funnels uses , Chicago, Illinois 60606, USA. ActiveCampaign has committed itself to compliance with from February 2016.

If users wish to conclude a contract for the use of Perspective Funnels, their data is stored in a customer account.

Personal data will not be transferred to third parties for purposes other than those listed in this privacy policy. Accordingly, a transfer only takes place if users have given their express consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR, if the transfer is necessary pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR for the assertion, exercise, or defense of legal claims and there is no reason to assume that users have an overriding legitimate interest in the non-disclosure of their data, if there is a legal obligation for the transfer pursuant to Art. 6 para. 1 sentence 1 lit. c GDPR, or if this is legally permissible and necessary pursuant to Art. 6 para. 1 sentence 1 lit. b GDPR for the processing of contractual relationships with users. Perspective Funnels uses cookies on the website.

Users have the right, pursuant to Art. 15 GDPR, to request information about their personal data processed by Perspective Funnels. In particular, users may request information about the purposes of processing, the category of personal data, the categories of recipients to whom their data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of their data if it was not collected by us, and the existence of automated decision-making including profiling and, if applicable, meaningful information about its details. In addition, users may request the rectification of their stored data and its deletion. Restriction of the stored data may also be requested, as well as objection to the collection of data by the users. Further rights of data subjects can be found on the Perspective Funnels website or in its privacy policy.

The applicable data protection provisions can be accessed at:

Data Protection Provisions regarding the Use of Pinterest

The controller has integrated components of the Pinterest service on this website. Pinterest is a service that can be qualified as an audiovisual platform and enables users to share photos and videos and to redistribute such data in other social networks.

The operating company of Pinterest is Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.

By registering with or using Pinterest, certain information is voluntarily shared, such as name, email address, telephone number, photos, pins, comments, and other information. Depending on the device settings or through photos, the exact location may also be deliberately shared. In any case, Pinterest uses IP addresses to determine an approximate location, even if the exact location is not intended to be disclosed. It is also possible to share further information, such as gender, age, and preferred languages. If the website is used via a mobile app or other internet services, certain internet and network activities are automatically created and recorded. This is also the case when using Pinterest. The data collected by Pinterest includes, in particular, log data, device information, and clickstream data. Pinterest collects this data in particular in order to enable use and to improve it at all times.

Pinterest has a legitimate interest in using users’ information. This information is fundamental to what Pinterest offers and is necessary to tailor Pinterest and its functions to users and make them relevant. There is also a legitimate interest in keeping Pinterest secure and improving its functions so that users can find the inspiration they are looking for.

Further information and the applicable data protection provisions of Pinterest can be found at:

Data Protection Provisions regarding the Use of Pipedrive

The controller has integrated components of the Pipedrive service on this website. Pipedrive is a global cloud-based software company. It is a tool for managing customer relationships in sales.

The operating company of Pipedrive is Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia.

Pipedrive collects various types of information from or about the service or with the consent of users. Users of the website may provide personal data and Pipedrive may collect it. Examples of personal data include name, email address, postal address, mobile phone number, and credit card or other billing data. Personal data also includes other information, such as geographic areas or preferences, if such information is linked to information that identifies a specific person. Users may provide personal data in various ways within the service, for example when registering for an account, using the service, posting customer data, interacting with other users of the service through communication or messaging functions, or sending customer service requests to Pipedrive. Users may store or upload customer data into the service. Pipedrive has no direct relationship with the individuals whose personal data it hosts as part of customer data. Each customer is responsible for informing its customers and third parties about the purpose for which the customer collects their personal data and how this personal data is processed in or through the service as part of customer data.

When using its services, Pipedrive may record information from the device of the user or visitor by using various types of technologies, including cookies, “clear gifs,” or “web beacons.” This “automatically collected” information may include the IP address or another device address or ID, the web browser and/or device type, the web pages or websites visited immediately before or after the use of the service, the pages or other content that the user or visitor views or interacts with in the service, and the dates and times of the visit, access, or use of the service. Pipedrive may also use these technologies to collect information about the interaction of a visitor or user with email messages, such as whether the visitor or user opens, clicks, or forwards a message. This information is collected from all users and visitors.

Pipedrive may receive information, including personal data, from third parties and sources other than the service, such as partners, advertisers, rating agencies, and integrated services. If Pipedrive combines or links information from other sources with personal data collected through the service, the combined information is treated as personal data in accordance with this policy.

Pipedrive uses the information—except for customer data—to revise functions of the service, for maintenance, improvement, and provision of information. Pipedrive processes customer data exclusively in accordance with the instructions given by the respective customer or user. Pipedrive uses the data to understand and analyze usage trends and preferences of visitors and users, to improve the service, and to develop new products, services, features, and functions. If this purpose requires the processing of customer data by Pipedrive, the data will only be used in anonymized or aggregated form. Pipedrive may use the email address or other information of a visitor or user—except for customer data—among other things, to contact that visitor or user. Pipedrive uses cookies.

Except as described in this policy, personal data or customer data collected or stored within the service is not intentionally disclosed to third parties without the consent of the respective visitor, user, or customer. Information may be disclosed to third parties if you give us your consent to do so, as well as, among other things, when using public profile pages or in cooperation with third parties.

If users wish to access or change other personal data that has been stored, or if the deletion or transfer of data is to be requested, users may contact Pipedrive.

Pipedrive is not responsible for the content or the privacy and security practices and policies of third-party websites or services to which links or access are provided through the service.

Further information and the applicable data protection provisions of Pipedrive can be accessed at:

Data Protection Provisions regarding the Use of Proven Expert

The controller has integrated the Proven Expert component on this website. Proven Expert enables the data subject to rate the provider’s services.

The operating company of Proven Expert is Expert Systems AG, Quedlinburger Straße 1, 10589 Berlin, Germany.

In the context of creating reviews, Proven Expert stores the email address as well as the corresponding log file of the data subject as inventory data. The log file consists of the IP address assigned to the requesting computer by the internet access provider for the session, as well as the name and version of the internet browser with which the provider’s website was accessed. The storage of the inventory data is necessary for the provider of Proven Expert in order to prevent misuse (e.g. multiple reviews by users). The data subject may also voluntarily provide further information (e.g. name and company), which is then also stored by the provider.

Instead of registering or verifying the reviews submitted by the data subject, the data subject also has the option to do so via a user account with a social network. The provider of Proven Expert does not receive the access data to the profile of the data subject in a social network under any circumstances. Integrated are: LinkedIn, the social network of LinkedIn Ireland, Gardner House, Wilton Place, Wilton Plaza, Dublin 2 Ireland (“LinkedIn”); Google Plus, the social network of Google Inc., Mountain View, California, USA; and Xing, the social network of XING AG, Dammtorstraße 29–32, 20354 Hamburg, Germany (“Xing”). In addition, Facebook, the social network of Facebook Ireland Ltd, Hanover Reach, 5–7 Hanover Quay, Dublin 2 Ireland (“Facebook”), is integrated into the provider’s service; however, only reviews can be verified through it. The applicable data protection provisions of Proven Expert can currently be found on this service provider’s website at:

Data Protection Provisions regarding the Use of Recruitee

The controller has integrated components of Recruitee on this website.

The operating company is Recruitee B.V., Keizersgracht 313, 1016 EE Amsterdam, Netherlands.

Recruitee processes personal data as a service for SaaS customers. SaaS is the “software-as-a-service” for recruitment that Recruitee offers to its customers (hereinafter: customers). In such cases, the customer bears responsibility for the personal data processed. The customer is then the controller, and Recruitee is the processor. Applicants, potential job candidates, and end users of the SaaS (hereinafter: users) should always contact the customer for information about the processing of their personal data within the framework of the SaaS and about the responsibilities of the customer, which may differ from those of Recruitee.

The following categories of personal data are processed:
Customer support by Recruitee and customer success;
billing and administration by Recruitee;
provision of the SaaS by Recruitee and provision of related services;
sales and marketing for Recruitee’s products and services.

The following categories of personal data are processed:
contact data such as address, email address, and telephone number;
support correspondence;
billing data;
username and password;
SaaS activities;
other personal data as entered into the SaaS.

How long personal data is retained, the retention of which can be controlled by the customer and/or the user via the SaaS or over which they have authority to issue instructions within the framework of the agreements between the customer and Recruitee, is determined primarily by the customer and/or the user. Recruitee deletes personal data relating to users after cancellation of the services for the purpose for which the personal data was collected and provided that the personal data is no longer required for the purposes listed in this section.

The use and transfer to other applications of information from Google APIs is carried out in accordance with . Information from Google APIs includes data from Gmail accounts or Google Calendar accounts that users connect to the SaaS. Recruitee uses data from users’ Gmail accounts or Google Calendar accounts exclusively for the purpose of providing Recruitee’s SaaS.

The applicable data protection provisions can be accessed at:

Data Protection Provisions regarding the Use of Slack

The controller has integrated the Slack component on this website. Slack is a web-based instant messaging service used, among other things, for communication within working groups.

Slack is a product of Slack Technologies Inc., 500 Howard Street, San Francisco, CA 94105, USA.

The controller uses Slack as a means of communication in order to respond to users’ inquiries via the contact form as quickly as possible. If a user sends an inquiry via the contact form on the website of the controller, the entered data is sent to the controller using Slack. This ensures rapid processing of the user’s inquiry. The controller also uses Slack for internal communication and project planning. In both cases, user data such as names, addresses, contact data, and content data such as text entries are processed.

In these processes, the data is transferred to servers of Slack in the USA and stored there. For this reason, the controller has concluded a “Data Processing Addendum.” This is a contract by which Slack is obliged to protect the transmitted user data, to process it on behalf of the controller in accordance with Slack’s privacy policy, and in particular not to disclose it to unauthorized third parties.

The data is deleted after the user’s inquiry has been processed, but no later than automatically after 30 days.

The legal basis for the transfer of the user’s data is the user’s legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in user-friendly and efficient internal communication, as well as the user’s consent pursuant to Art. 6 para. 1 lit. a GDPR.

The user can view Slack’s privacy policy at the following link:

Users have the right to request the deletion of their data. Users may also, among other things, obtain access to the collected data or withdraw any consent they have given.

Data Protection Provisions regarding the Use of Spotify

The controller has integrated components of Spotify on this website. Spotify is an audio streaming service that collects users’ streaming habits in order to offer an exceptional and personalized service specifically for users.

The operating company of Spotify is Spotify AB, headquartered at Regeringsgatan 19,
SE-111 53 Stockholm, Sweden.

When visiting our website, Spotify receives the information that you have visited our site with your IP address. If you click the Spotify button while you are logged into your Spotify account, you can link the content of our pages to your Spotify profile. When you use or interact with the Spotify service, a variety of technologies are used to process the personal data collected about you for different reasons. Among other things, user data, usage data, and payment data are collected. Spotify uses the collected data in particular for providing and personalizing the Spotify service, for evaluating and developing new functions and technologies and improving the Spotify service, and for fulfilling contractual obligations with third parties, for example license agreements, and for taking appropriate measures regarding reports of infringements of intellectual property rights and inappropriate content. Your data may be disclosed to third parties, in particular in the case of publicly accessible information (e.g. profile picture, username, or similar) and if you have given your consent. Spotify transfers your personal data worldwide to companies within the Spotify group in order to carry out the activities listed in this policy.

Spotify retains personal data only as long as is necessary to provide the Spotify service and for legitimate and essential business purposes, such as maintaining the performance of the Spotify service, making data-driven business decisions about new features and offerings, complying with legal obligations, and resolving disputes. Spotify retains some of your personal data for as long as you are a user of the Spotify service.

The applicable data protection provisions of Spotify can be accessed at:

Data Protection Provisions regarding the Use of STRATO

The controller has integrated components of STRATO as a web hosting program on this website.

The operating company of STRATO is STRATO AG, Pascalstraße 10, 10587 Berlin, Germany.

STRATO collects, processes, and stores the data that users provide when they place an order with STRATO. This includes, for example, the users’ IP address. In addition, STRATO stores and processes data regarding order and payment history. STRATO also collects, processes, and stores the data that users themselves store when using our services. This includes the creation of security copies in STRATO’s backup systems. When users visit the STRATO website or use the services, the device used to access the page automatically transmits log data (connection data) to STRATO’s server. This is particularly the case when users place orders, log in, or upload or download data. Log data is also recorded by STRATO’s servers when visitors access their websites. The following log data is collected in this process: customer domain, anonymized client IP, request line, timestamp, status code, size of the response body, referer sent by the client, user agent sent by the client, remote user.

At various points in its web offering, STRATO uses cookies, pixels, and similar technologies. Some of the cookies used process data in third countries. If users consent to the processing by these cookies, they also consent to the transfer and processing of their data in these third countries in accordance with Art. 49 I lit. a GDPR.

If a user leaves a comment on the blog published on STRATO’s website, in addition to the comments, information about the time the comment was entered and, where applicable, the username (pseudonym) chosen by the data subject are stored and published. If the user leaves an email address, it is also stored, but not published. No disclosure of this collected personal data to third parties takes place unless such disclosure is required by law or serves the legal defense of the controller.

STRATO processes and uses user data to perform the contract and provide its services, to improve its services and websites and adapt them to user needs, to provide updates and upgrades, to send notifications relating to the service, and to create invoices and collect receivables.

For domain registrations, certain personal data is forwarded by STRATO to registrars and registration offices. STRATO, as controller, forwards various personal data within the scope of order data processing to its processors. STRATO has ensured the security of users’ data by concluding agreements on order data processing.

We process and store personal data only for the period necessary to achieve the purpose of storage or if this is required by law. The purpose of processing is generally achieved when your contract ends.

Data that users store themselves in the services can be changed and deleted by the users themselves. After termination of the contract, STRATO deletes the data stored in the services within 4 months. Security copies in STRATO’s backup systems are automatically deleted with a time delay. For contract data, processing is restricted after termination of the contract; after expiry of the 10-year statutory retention period in accordance with § 257 HGB and § 147 AO, the data is deleted.

Data that users enter as part of the application process is stored for a maximum of six months. Data collected by STRATO in connection with domain owner inquiries is stored until the end of the first full calendar year after the application is submitted. Log and account data are stored by STRATO with login for a maximum of 6 months. After termination of the contract, account data is deleted within 2–4 months. For customer correspondence, order history, and payment history, the statutory retention period of 6 years pursuant to § 257 HGB and § 147 AO applies.

Users have the right at any time to obtain from STRATO, free of charge, information and confirmation as to the personal data stored about them and a copy of this information. Users have the right to request the immediate rectification of inaccurate personal data concerning them. Furthermore, users have the right, taking into account the purposes of processing, to request the completion of incomplete personal data—including by means of a supplementary statement. Users have the right at any time to object to the processing of personal data concerning them which is based on Art. 6 para. 1 letters e or f GDPR. STRATO will no longer process the personal data in the event of an objection unless STRATO can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the users, or the processing serves the assertion, exercise, or defense of legal claims. Users have the right at any time to object to the processing of personal data for the purpose of direct advertising. Users may withdraw their consent to the processing of personal data at any time.

The applicable data protection provisions can be accessed at:

Data Protection Provisions regarding the Use of Trello

The controller has integrated components of Trello on this website. Trello is a web-based application for creating lists in Kanban style and is a subsidiary of Atlassian.

The operating company of Trello is Atlassian B.V., c/o Atlassian, Inc., 350 Bush Street, Floor 13, San Francisco, CA 94104, USA.

Trello collects information about users when users explicitly provide it, when users use our services, and when other sources provide Trello with this information. Trello collects information about users when users enter it into the services or otherwise provide it directly.

Trello collects information about users when they register for an account, create or modify a profile, set preferences, sign up for the services, or make purchases through the services. For example, users may add a display name, profile photo, job title, and other details to their profile information that are to be displayed within Trello’s services.

The services include the Atlassian products used by users, in which Trello collects and stores content that users post, send, receive, and share. Such content includes any information about users that they choose to provide. This includes, for example, the summary and description added to a Jira issue, the name of a Trello board, repositories, and pull requests in Bitbucket. Content also includes files and links that users upload to the services. If users use a server or data center version of the services, Trello does not host, store, transmit, receive, or collect information about users except in limited cases where the administrator permits it: among other things, Trello collects feedback that users provide directly through the product. Server and data center administrators may disable the collection of this information by the services via admin settings or prevent this information from being transmitted to Trello by blocking the transmission at the local network level.

Trello collects other content that users submit to these websites, including social media or social networking websites operated by Trello. For example, users provide content when they give feedback to Trello or when they participate in interactive features, surveys, contests, promotions, sweepstakes, activities, or events.

Regardless of whether users identify themselves as technical contacts, open a support ticket, speak directly with one of Trello’s employees, or otherwise contact the support team, users may be asked to provide their contact information, a summary of the problem they are experiencing, and any additional documentation, screenshots, or information that may be helpful in resolving the issue. Trello also collects payment and billing data when users register for certain paid services.

Trello collects information about the computer, phone, tablet, or other devices that users use to access the services. This device information includes the connection type and settings.

Atlassian and Trello’s third-party partners, such as advertising and analytics partners, use cookies and other tracking technologies (e.g. web beacons, device identifiers, and pixels) to provide functionality and to recognize users across different services and devices.

Users of the services may provide information about other users when they submit content through the services.

Trello uses information about users to provide them with the services, including processing transactions, authenticating them when they log in, providing customer support, and operating, maintaining, and improving the services.

Trello is always looking for ways to make its services smarter, faster, more secure, more integrated, and more useful. Trello uses information and collective insights (including feedback) about how people use the services to troubleshoot, identify trends, usage, activity patterns, and areas for integration, and to improve its services and develop new products, features, and technologies that benefit users and the public.

Trello uses contact information to send transaction-related communications by email and within the services, including confirming purchases, reminding users when subscriptions are expiring, responding to comments, questions, and requests, providing customer support, and sending technical notices, updates, security alerts, and administrative messages.

If users are natural persons in the European Economic Area (EEA), Trello only collects and processes information about users if Trello has legal bases to do so under applicable EU law. The legal bases depend on which services people use and how they use them.

Trello creates collaboration tools and wants them to work well for users. This means that Trello shares information about the services and with certain third parties. Trello also shares information in connection with possible business transfers, among other things.

In exceptional cases, Trello may disclose users’ information to third parties if Trello believes that disclosure is reasonably necessary to (a) comply with applicable laws, regulations, legal processes, or governmental requests, including meeting national security requirements; (b) enforce agreements, policies, and terms of use; (c) protect the security or integrity of products and services; (d) protect Atlassian, customers, or the public from harm or illegal activities; or (e) respond to an emergency, for example to prevent death or serious bodily injury to any person.

Trello uses industry-standard technical and organizational measures to secure the information collected from users.

Trello retains users’ account information for as long as their account is active and for a reasonable period thereafter in case users decide to reactivate the services. If users’ accounts are deactivated or disabled, some information and provided content will remain so that team members or other users can continue to use the services in full. If users have opted to receive marketing emails from Trello, Trello retains information about marketing preferences for a reasonable period from the date on which users last expressed interest in the service, for example when users last opened an email from Trello or stopped using the Atlassian account.

Users have the right to request a copy of their data, to object to Trello’s use of their data (including for marketing purposes), to request deletion or restriction of their data, or to request their data in a structured, electronic format.

Trello collects information globally and may transfer, process, and store user data outside their country of residence wherever Trello or its third-party service providers operate in order to provide the services to users.

The applicable data protection provisions and further information can be accessed at:

Data Protection Provisions regarding the Use of GoDaddy

The controller has integrated components of GoDaddy as a web hosting service on this website.

The operating company of GoDaddy is GoDaddy Operating Company, LLC, 2155 E. GoDaddy Way, Tempe, AZ 85284, USA.

GoDaddy collects, processes, and stores the data that users provide when they place an order with GoDaddy. This may include, for example, the users’ IP address. In addition, GoDaddy stores and processes data relating to order history, payment transactions, account information, and customer communication. GoDaddy also collects, processes, and stores the data that users themselves store when using our services. This may include the creation of backups in GoDaddy’s systems. When users visit the GoDaddy website or use the services, the device used to access the website automatically transmits log data (connection data) to GoDaddy’s servers. This is particularly the case when users place orders, log in, or upload or download data. Log data may also be recorded when visitors access websites hosted through GoDaddy. Such log data may include the customer domain, anonymized client IP address, request line, timestamp, status code, size of the response body, referrer transmitted by the client, user agent transmitted by the client, and remote user.

At various points in its online offering, GoDaddy uses cookies, pixels, and similar technologies. Some of the cookies used may process data in third countries. If users consent to processing through these cookies, they also consent to the transfer and processing of their data in such third countries in accordance with Art. 49 para. 1 lit. a GDPR.

If a user leaves a comment on a blog published on a website hosted by GoDaddy, in addition to the comment, information regarding the time of entry as well as, where applicable, the username (pseudonym) chosen by the data subject may be stored and published. If the user provides an email address, it may also be stored, but not published. No disclosure of this collected personal data to third parties takes place unless such disclosure is required by law or serves the legal defense of the controller.

GoDaddy processes and uses user data in order to perform the contract and provide its services, to improve its services and websites and adapt them to usage requirements, to provide updates and upgrades, to send notifications relating to the service, and to generate invoices and collect outstanding amounts.

For domain registrations, certain personal data may be forwarded by GoDaddy to registrars and registration authorities. GoDaddy may also forward various personal data as controller within the framework of data processing agreements to its processors. GoDaddy ensures the protection of user data by means of appropriate contractual arrangements and technical and organizational measures.

We process and store personal data only for the period necessary to achieve the purpose of storage or insofar as this has been provided for by law. As a rule, the purpose of processing ends when the contractual relationship ends.

Data that users themselves store within the services can generally be changed and deleted by the users themselves. After termination of the contract, GoDaddy may delete the data stored in the services after an appropriate retention period. Security copies in backup systems may be deleted with a time delay. For contract and billing data, processing may be restricted after termination of the contract and deleted after expiry of the applicable statutory retention periods.

Data entered by users as part of an application process may be stored for a limited period if required for processing the application and in accordance with applicable legal provisions. Data collected in connection with domain ownership requests may also be stored for a legally required or operationally necessary period. Log and account data may be stored for a limited period for security and administrative purposes. For customer correspondence, order history, and payment history, statutory retention obligations may apply.

Users have the right at any time to obtain, free of charge, information and confirmation as to whether personal data concerning them is being stored, as well as a copy of such information. Users have the right to request the immediate rectification of inaccurate personal data concerning them. Furthermore, users have the right, taking into account the purposes of processing, to request the completion of incomplete personal data, including by means of a supplementary statement. Users also have the right to object at any time to the processing of personal data concerning them which is based on Art. 6 para. 1 lit. e or f GDPR. In the event of an objection, GoDaddy or the controller will no longer process the personal data unless compelling legitimate grounds for the processing can be demonstrated which override the interests, rights, and freedoms of the user, or the processing serves the establishment, exercise, or defense of legal claims. Users also have the right at any time to object to the processing of personal data for the purpose of direct marketing. Users may withdraw consent previously granted for the processing of personal data at any time.

The applicable data protection provisions can be accessed at:

Data Protection Provisions regarding the Use of Trustpilot

The controller has integrated components of the Trustpilot service on this website. Trustpilot.com is a Danish consumer review website founded in 2007, containing reviews of companies worldwide. Nearly 1 million new reviews are published each month. The website offers freemium services to businesses.

The operating company of Trustpilot is Trustpilot A/S, Pilestraede 58, 5th Floor, 1112 Copenhagen K, Denmark.

When users create a Trustpilot account, submit a review, set up a business account on behalf of a company, or otherwise use the platform, Trustpilot may collect and process personal data such as names, email addresses, other contact information, IP addresses, browser settings, locations, usernames, passwords, photos, and preferred language.

Users may link their Trustpilot profile with profiles on social media (e.g. Facebook). If such a connection is established, Trustpilot automatically collects certain information from the social network depending on the available information and the user’s privacy settings.

Trustpilot primarily collects personal data directly from users when they provide this information (e.g. when creating an account or interacting with the platform by submitting reviews or responses).

Trustpilot may also receive information from third parties, for example when users register via Facebook or when companies send review invitations including user details such as name, email address, and reference numbers (e.g. order numbers).

In addition, Trustpilot automatically collects information from users’ devices, such as IP address, location, and browser/device information.

The collected data is used for providing services, displaying reviews, enabling access to accounts, identifying users, analyzing data, preventing fraud, improving services, developing new features, evaluating marketing effectiveness, and verifying the authenticity of reviews.

Trustpilot shares personal data with selected third parties (including affiliates and service providers) that support the operation of the platform. These processors act only on Trustpilot’s instructions under data processing agreements.

Data is stored only as long as necessary or legally required. Users may delete their data or request deletion. If an account is deleted, Trustpilot retains a limited log (name, email, deletion date) for three years; all other data, including reviews, is deleted.

Some anonymized or aggregated data may be retained. Data received from companies is retained for three years. Trustpilot uses cookies and similar technologies.

Users can access, edit, download, or delete their data via their account and manage subscription and marketing settings. They also have rights to access, rectification, erasure, restriction, and objection.

Further information and applicable privacy policies can be accessed at:

Data Protection Provisions regarding the Use of Typeform

The controller has integrated components of Typeform on this website. Typeform is a Barcelona-based software-as-a-service (SaaS) company specializing in the creation of online forms and surveys. Its main software creates dynamic forms based on user requirements.

The operating company of Typeform is Typeform S.L., Carrer Bac de Roda, 163, 08018 Barcelona, Spain.

The data entered into the forms is stored by this service and transmitted to us or made accessible to us. Typeform does not use this data for its own purposes.

The legal basis for this data processing is Art. 6 para. 1 lit. f GDPR (legitimate interest of the controller). A legitimate interest exists in the targeted and individualized presentation of contact forms tailored to specific topics and questions, as well as the ability to quickly and cost-effectively adapt them.

No transfer of this personal data to third parties takes place.

Further information and the applicable data protection provisions can be accessed at typeform.com.


Data Protection Provisions regarding the Use of Vimeo

The controller has integrated components of Vimeo on this website.

The operating company of Vimeo is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.

When visiting one of our pages equipped with a Vimeo plugin, a connection to the Vimeo servers is established. The Vimeo server is informed which of our pages you have visited. In addition, Vimeo obtains your IP address. This also applies if you are not logged into Vimeo or do not have a Vimeo account. The information collected by Vimeo is transmitted to the Vimeo server in the United States.

If you are logged into your Vimeo account, you allow Vimeo to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your Vimeo account.

The use of Vimeo is in the interest of an appealing presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR.

If corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; consent can be revoked at any time.

Further information and the applicable data protection provisions can be accessed at:


Data Protection Provisions regarding the Use of Webflow

The controller has integrated components of Webflow on this website.

The operating company of Webflow is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA.

When users access this website, various personal data may be collected. When accessing the website, information is automatically sent by the user’s browser to the server of this website and temporarily stored in a log file.

The collected information includes, among other things, the IP address of the requesting computer, date and time of access, name and URL of the retrieved file, and the browser used.

The storage of this data takes place to ensure a smooth connection to the website, to ensure comfortable use of the website, to evaluate system security and stability, and for other administrative purposes.

The legal basis for data processing is Art. 6 para. 1 sentence 1 lit. f GDPR. The legitimate interest arises from the purposes listed above for data collection. Under no circumstances are the collected data used to draw conclusions about the person of the user.

If users have given their explicit consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR, Webflow uses their email address to regularly send them newsletters. If users submit inquiries via contact forms, the information provided, including contact details, will be stored in systems such as Craft CMS and ActiveCampaign for processing and follow-up questions. This data will not be shared without consent.

If users wish to conclude a contract via Webflow, their data will be stored in a customer account.

Webflow carries out most of the data processing activities required to provide services. However, Webflow engages third-party providers (e.g., payment processors, cloud storage providers, customer support tools, analytics tools, IT and security providers).

Webflow ensures the security of personal data and limits storage to the period necessary to fulfill processing purposes, including legal obligations. Data transfers to the USA and other countries are carried out using approved transfer mechanisms. Webflow uses cookies.

Users have the right, in accordance with Art. 15 GDPR, to request information about their personal data, including purposes, categories, recipients, storage duration, and rights such as rectification, deletion, restriction, objection, and complaint.

Further information can be accessed at:

Data Protection Provisions regarding the Use of WebinarJam

The controller has integrated components of WebinarJam on this website. Free webinars are offered here.

The operating company is Genesis Digital LLC, 7660 Fay Ave #H184, La Jolla, CA 9203, USA.

After registering for seminars, WebinarJam becomes aware of your email address and you will receive an invitation link. After clicking on the invitation link, a connection to the WebinarJam servers is established. In this process, the servers are informed which of our pages you have visited (referrer). In addition, your IP address is transmitted to the WebinarJam server. This also applies if you are not logged into WebinarJam or do not have an account with WebinarJam.

Further information and the applicable data protection provisions can be accessed at home.webinarjam.com.


Data Protection Provisions regarding the Use of Wistia

The controller has integrated components of the video portal Wistia on this website.

The operating company is Wistia Inc., 17 Tudor Street, Cambridge, Massachusetts, 02139, USA.

When a page equipped with a Wistia plugin is accessed, a connection to the Wistia servers is established. In this process, the Wistia server is informed which of the pages were visited and when. In addition, Wistia obtains the IP address. This also applies if the visitor is not logged into Wistia or does not have a Wistia account. The information collected by Wistia is transmitted to the Wistia server in the USA.

If the visitor is logged into their Wistia account, this enables Wistia to assign the browsing behavior directly to the personal profile of the visitor. This can be prevented by logging out of the Wistia account.

Further information on the collection and use of data by Wistia can be found in Wistia’s privacy policy:


Data Protection Provisions regarding the Use of Wufoo

The controller has integrated components of Wufoo on this website. Wufoo is a form service.

The operating company is Momentive Europe UC, 2 Shelbourne Buildings, Second Floor, Shelbourne Rd, Ballsbridge, Dublin 4, Ireland.

When using contact forms, the email address, further contact details, information about professional position, and details regarding your inquiry are collected and processed. The data is collected using the Wufoo form service. As a result, the content entered by the user into a contact form is processed and stored. Depending on the respective contact form, the content may include the following: company, name, email address, telephone number, preferred supplier, invoice number, credit card details, product-related information, as well as other self-explanatory fields with individual queries. The content is only processed and stored once you submit a form.

The applicable data protection provisions can be accessed here:

Data Protection Provisions regarding the Use of Xing

The controller has integrated components of Xing on this website. Xing is an internet-based social network that enables users to connect with existing business contacts and to establish new business contacts. Individual users can create a personal profile on Xing. Companies can, for example, create company profiles or publish job offers on Xing.

The operating company of Xing is XING SE, Dammtorstraße 30, 20354 Hamburg, Germany.

Each time one of the individual pages of this website is accessed, which is operated by the controller and on which a Xing component (Xing plug-in) has been integrated, the internet browser on the information technology system of the data subject is automatically prompted by the respective Xing component to download a display of the corresponding Xing component from Xing. Further information on Xing plug-ins can be accessed at: . As part of this technical procedure, Xing obtains knowledge of which specific subpage of our website is visited by the data subject.

If the data subject is logged into Xing at the same time, Xing recognizes with each call-up of our website by the data subject and for the entire duration of the respective stay on our website which specific subpage of our website the data subject visits. This information is collected by the Xing component and assigned by Xing to the respective Xing account of the data subject. If the data subject activates one of the Xing buttons integrated on our website, for example the “Share” button, Xing assigns this information to the personal Xing user account of the data subject and stores this personal data.

Xing always receives information via the Xing component that the data subject has visited our website if the data subject is logged into Xing at the time of accessing our website; this takes place regardless of whether the data subject clicks on the Xing component or not. If such transmission of this information to Xing is not desired by the data subject, the delivery may be prevented if the data subject logs off from their Xing account before accessing our website.

The data protection provisions published by Xing, which can be accessed at , provide information on the collection, processing, and use of personal data by Xing. Furthermore, Xing has published data protection information for the XING Share button at .

Data Protection Provisions regarding the Use of Yoast SEO

The controller has integrated components of the Yoast SEO service on this website.

The operating company of Yoast SEO is Yoast BV, Don Emanuelstraat 3, 6602 GX Wijchen, The Netherlands.

This website uses various web analysis tools (e.g., Google Analytics) and other measurement tools (e.g., Hotjar) to analyze how users use the website. These tools use “cookies,” which are text files stored on your computer, to collect standard internet log information and visitor behavior information in an anonymous form. The information generated by the cookie about the use of this website (including your IP address) is transmitted to Google and sometimes to other providers. This information is then used to evaluate the use of the website by visitors and to compile statistical reports on website activity for yoast.com.

Yoast SEO will never use the statistical analysis tool to track or collect personally identifiable information of visitors to the website. The web analytics providers do not associate users’ IP addresses with any other data held by them. Neither Yoast SEO nor the web analytics providers will link an IP address with the identity of a computer user or attempt to do so. Yoast SEO will not associate any data collected from this website with personal information from any source unless users explicitly submit that information via a form on the Yoast SEO website.

This website contains (affiliate) links to some other websites. Yoast.com and its authors are not responsible for the privacy practices or the content of those websites.

If users leave a comment or subscribe to an email list, Yoast SEO asks for their name and email address. If users purchase a product, Yoast SEO also asks for the name, address, and email address, and may receive some additional information such as the URL of the user’s website. The email and all other information are used solely to inform users about updates related to Yoast. Users’ personal data will not be shared with third parties for any purpose.

Further information and the applicable data protection provisions of Yoast SEO can be accessed at:

Data Protection Provisions regarding the Use of YouTube

The controller has integrated components of YouTube on this website. YouTube is an internet video portal that enables video publishers to upload video clips free of charge and allows other users to view, rate, and comment on them, also free of charge. YouTube allows the publication of all kinds of videos, which is why complete film and television broadcasts, as well as music videos, trailers, or user-generated videos, can be accessed via the internet portal.

The operating company of YouTube is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Inc., 1600 Amphitheatre Pkwy, Mountain View, CA 94043-1351, USA.

Each time one of the individual pages of this website is accessed, on which a YouTube component (YouTube video) has been integrated, the internet browser on the information technology system of the data subject is automatically prompted to download a display of the corresponding YouTube component. Further information about YouTube can be accessed at: . During this technical process, YouTube and Google gain knowledge of which specific subpage of our website was visited by the data subject.

If the data subject is logged into YouTube at the same time, YouTube recognizes which specific subpage of our website the data subject visits when accessing a subpage that contains a YouTube video. This information is collected by YouTube and Google and assigned to the respective YouTube account of the data subject.

YouTube and Google always receive information via the YouTube component that the data subject has visited our website if the data subject is logged into YouTube at the time of accessing our website; this takes place regardless of whether the data subject clicks on a YouTube video or not. If such transmission of this information to YouTube and Google is not desired, it can be prevented by logging out of the YouTube account before accessing our website.

The data protection provisions published by YouTube, which can be accessed at , provide information on the collection, processing, and use of personal data by YouTube and Google.

Data Protection Provisions regarding the Use of Zapier

The controller has integrated components of Zapier on this website. Zapier is used for the integration of different databases and tools.

The operating company is Zapier Inc., 548 Market St #62411, San Francisco, California 94104, USA.

Customer data, with the exception of payment data, may be transmitted. Zapier collects information about users. This includes information provided by the user such as name, email address, and address. In addition, Zapier automatically collects user information when a new account is created, such as payment information. Zapier receives information about users from other sources such as third-party service providers, public databases, and our business and sales partners. This information may include business contact information, address, job title, email address, and telephone number. Zapier may combine this information with information collected in other ways. Zapier collects user information primarily to improve its own services, to respond to user inquiries, and to protect the integrity or security of the company, the website, the services, or third-party applications. The data may also be used to fulfill obligations, enforce rights, comply with legal obligations (including assisting customers in fulfilling their legal obligations), where necessary for legitimate interests, or to fulfill another purpose for which you have provided the data. Information collected by Zapier from the website is transferred to and processed in the United States and in any other country where Zapier or its affiliates, subsidiaries, or third-party service providers maintain facilities or personnel. Zapier takes appropriate measures to protect users’ personal data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction, taking into account the risks involved in the processing and the nature of the personal data. However, no application, internet, or email transmission is ever completely secure or error-free, and Zapier does not guarantee the security of personal data.

Further information and the applicable data protection provisions can be accessed at:


Data Protection Provisions regarding the Use of Zoom

The controller has integrated components of Zoom on this website.

The operating company is Zoom Video Communications, Inc., 55 Almaden Blvd, Suite 600, San Jose, CA 95113, USA.

Zoom collects, among other things, the following information when users register for a free Zoom account: date of birth (only as proof of age), first and last name, and telephone numbers. For users who create a paid Zoom account, Zoom stores, in particular, user data in connection with a Zoom account, telephone number for billing, and billing address. Zoom also automatically stores technical information from Zoom software or systems hosting the services, as well as from systems, applications, and devices used to access the services. Location data is also collected automatically.

Zoom shares personal data with companies, organizations, and persons outside of Zoom and third parties when personal consent of the users has been obtained (if required). If Zoom has received personal data through a Zoom partner and the user becomes a customer, Zoom may share selected personal data with the respective partner or its representative within the framework of the partner agreement in order to reward a referral partner of a jointly sponsored event. Zoom’s partners are contractually obligated to comply with appropriate data protection and security obligations. Zoom provides personal data to suppliers and service providers so that they can support Zoom in providing services, as well as for Zoom’s business purposes.

If users wish to correct or update information they have provided to Zoom, they must contact Zoom directly at and update their profile. If users are located in the European Economic Area, they may have the right to exercise certain data protection rights under applicable law. Zoom will process such requests in accordance with applicable data protection laws. Zoom may retain certain information for recordkeeping purposes or to complete transactions initiated prior to a deletion request.

Zoom operates globally, which means that personal data may be stored and processed in any country where Zoom or its service providers maintain facilities or conduct events. Zoom stores collected personal data as long as necessary, unless a longer retention period is required by law.

The applicable data protection provisions can be accessed at:

Legal Basis for Processing

Art. 6 para. 1 lit. a GDPR serves our company as the legal basis for processing operations for which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is a party, as is the case, for example, with processing operations necessary for the supply of goods or the provision of any other service or consideration, the processing is based on Art. 6 para. 1 lit. b GDPR. The same applies to such processing operations that are necessary for carrying out pre-contractual measures, for example in cases of inquiries about our products or services. If our company is subject to a legal obligation by which the processing of personal data is required, such as for the fulfillment of tax obligations, the processing is based on Art. 6 para. 1 lit. c GDPR. In rare cases, the processing of personal data may be necessary in order to protect the vital interests of the data subject or another natural person. This would be the case, for example, if a visitor were injured on our premises and their name, age, health insurance data, or other vital information had to be passed on to a doctor, hospital, or other third party. Then the processing would be based on Art. 6 para. 1 lit. d GDPR. Finally, processing operations could be based on Art. 6 para. 1 lit. f GDPR. Processing operations not covered by any of the aforementioned legal bases are based on this legal basis if the processing is necessary for the purposes of legitimate interests pursued by our company or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Such processing operations are particularly permitted because they have been specifically mentioned by the European legislator. In this respect, it was considered that a legitimate interest could be assumed if the data subject is a customer of the controller (Recital 47 sentence 2 GDPR).


Legitimate Interests pursued by the Controller or by a Third Party

Where the processing of personal data is based on Article 6 para. 1 lit. f GDPR, our legitimate interest is to carry out our business activities for the benefit of the well-being of all our employees and our shareholders.


Period for which the Personal Data will be Stored

The criterion used to determine the period of storage of personal data is the respective statutory retention period. After expiration of that period, the corresponding data is routinely deleted, provided it is no longer required for the fulfillment or initiation of a contract.


Legal or Contractual Requirements to Provide Personal Data; Necessity for the Conclusion of the Contract; Obligation of the Data Subject to Provide the Personal Data; Possible Consequences of Failure to Provide such Data

We inform you that the provision of personal data is partly required by law (e.g. tax regulations) or may also result from contractual provisions (e.g. information about the contractual partner). In some cases, it may be necessary for the conclusion of a contract that a data subject provides us with personal data, which must subsequently be processed by us. The data subject is, for example, obliged to provide us with personal data if our company concludes a contract with them. Failure to provide personal data would result in the contract not being concluded with the data subject. Before providing personal data, the data subject must contact one of our employees. Our employee will clarify to the data subject on a case-by-case basis whether the provision of personal data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data, and what the consequences of failure to provide the personal data would be.


Existence of Automated Decision-Making

As a responsible company, we do not use automated decision-making or profiling.


Creation of this Privacy Policy

This privacy policy was created by SYLVENSTEIN Rechtsanwälte in cooperation with DGD Deutsche Gesellschaft für Datenschutz GmbH.

Legal Notice: This site is not a part of the Facebook TM website or Facebook TM Inc. Additionally, this site is NOT endorsed by FacebookTM in any way. FACEBOOK TM is a trademark of FACEBOOK TM, Inc.

© 2026 AUREA TCM LTD All Rights Resserved.