Skip to content

Privacy Policy

This is a translation of our German privacy policy. In case of doubt or discrepancies, the German version shall prevail. German version

We are very pleased that you are interested in our organisation. The protection of your personal data is particularly important to our management. You can use our websites without disclosing personal data to us. If, however, you wish to use more specific services via our websites, including our other online presences, applications and social media pages, we may have to process your personal data. If we wish to process data about you and we cannot rely on any other legal basis, we always ask you first for your consent (e.g. via a cookie banner).

When handling your personal data (such as name, address, email or telephone number), we always comply with the applicable data protection laws. With this privacy policy we inform you about which data we process. You will also learn in this privacy policy which data subject rights you have.

We have taken various technical and organisational measures in order to protect your data on our websites as well as possible. Nevertheless, there are always risks on the internet, and complete protection is not possible. You can therefore also transmit your personal data to us by other means, for example by telephone, if you prefer to do so.

This privacy policy serves not only to fulfil the obligations under the GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This privacy policy is also intended to serve compliance with legal provisions, such as those of the United Kingdom (UK-GDPR), the Schweizer Bundesgesetz über den Datenschutz and the Schweizer Datenschutzverordnung (DSG, DSV), the California Consumer Privacy Act (CCPA/CPRA), China's Personal Information Protection Law (PIPL), the Delaware Personal Data Privacy Act (DPDPA), the Tennessee Information Protection Act (TIPA), the Minnesota Consumer Data Privacy Act (MCDPA), the Iowa Act Relating to Consumer Data Protection (ICDPA), the Maryland Online Data Privacy Act (MODPA), the Nebraska Data Privacy Act (NDPA), the New Hampshire Consumer Data Privacy Law (SB255), the New Jersey Data Privacy Law (SB332), the South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection provisions, and is to be interpreted accordingly. The privacy policy set out below is to be construed for each country, state or federal state so that the terminology and legal bases used correspond to the terms and legal bases used in the respective state or federal state.

For reasons of better readability, the simultaneous use of the linguistic forms male, female, diverse and other gender identities (m/f/d/other) is dispensed with on our websites, in publications, in communications and in our privacy policy. All formulations used apply equally to all genders.

For suggestions for improvement regarding the texts in this privacy policy, or if you need an external data protection officer, please contact the author of the texts: Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E..

1. Definitions

In our privacy policy we use special terms from various data protection laws. We want our policy to be easy to understand, and we therefore explain these terms in advance.

The definitions set out below are, where applicable, to be interpreted or extended on the basis of the case law of the General Court of the European Union (EuG), the Court of Justice of the European Union (EuGH), the Swiss Federal Supreme Court (BGE), the Supreme Court of the United Kingdom (UKSC) or on the basis of national data protection laws or the national case law of a state or federal state, including but not limited to California, including judge-made law, also under common law, where this is necessary for the application of the law in an individual case.

We use the following terms, among others, in this privacy policy:

a) personal data

Personal data means any information relating to an identified or identifiable natural person (hereinafter, where applicable, “data subject”). A natural person is regarded as identifiable if he or she can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such on the basis of national data protection laws or the national case law of a state or federal state, including judge-made law, also under common law.

b) data subject

Data subject means any identified or identifiable natural person whose personal data are processed by the controller, a processor, an international organisation or another data recipient, and persons who must be regarded as such on the basis of national data protection laws or the national case law of a state or federal state, including judge-made law, also under common law.

c) processing

Processing means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

d) restriction of processing

Restriction of processing means the marking of stored personal data with the aim of limiting their processing in the future.

e) profiling

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

f) pseudonymisation

Pseudonymisation means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures which ensure that the personal data are not attributed to an identified or identifiable natural person.

g) controller

Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union law or Member State law, the controller or the specific criteria for its nomination may be provided for by Union law or Member State law.

h) processor

Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

i) recipient

Recipient means a natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union law or Member State law shall not be regarded as recipients.

j) third party

Third party means a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or the processor, are authorised to process the personal data.

k) consent

Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes, in the form of a statement or another clear affirmative action, by which the data subject signifies agreement to the processing of personal data relating to him or her.

2. Name and address of the controller

The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and in the European Economic Area, the British data protection laws, the Swiss data protection laws (DSG, DSV), the Californian data protection laws (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and other provisions of a data protection nature is:

Jakob Schönenberg

Am Schwenkhaus 9

57627 Gehlert

Tel.: +49 151 26974546

Email: hello@statusloop.dev

Website: www.statusloop.dev

3. Collection of general data and information

Our websites collect a series of general data and information with every call-up of the websites by a data subject or an automated system. These general data and information are stored in the log files of the respective server. The following may be collected, among other things: (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our websites (so-called referrers), (4) the sub-pages which are accessed via an accessing system on our websites, (5) the date and time of an access to the website, (6) an Internet Protocol address (IP address), (7) the Internet service provider of the accessing system and (8) other similar data and information that serve to avert danger in the event of attacks on our information technology systems.

When using these general data and information, we do not draw any conclusions about the data subject. This information is rather required in order (1) to deliver the contents of our websites correctly, (2) to optimise the contents of our websites and the advertising for them, (3) to ensure the permanent functionality of our information technology systems and the technology of our websites, and (4) to provide law enforcement authorities, in the event of a cyberattack, with the information necessary for prosecution. These anonymously collected data and information are therefore evaluated by us, on the one hand, statistically and, furthermore, with the aim of increasing data protection and data security in our company, in order ultimately to ensure an optimal level of protection for the personal data processed by us. The data in the server log files are stored separately from all personal data provided by a data subject.

The purpose of the processing is the aversion of danger and the safeguarding of IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is in particular the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.

4. Contact option via the website and other data transfers and your consent

Our websites contain details that enable rapid electronic contact with our company as well as immediate communication with us, which likewise includes a general address of so-called electronic mail (email address) and, where applicable, a telephone number. If a data subject contacts us by email, via a contact form, via an input form or otherwise, the personal data transmitted by the data subject are stored automatically. Such personal data transmitted to us by a data subject on a voluntary basis are processed for the purposes of handling the request or of contacting the data subject.

For the transmission, storage and processing of your contact data and inquiries and for contacting you, we obtain your consent pursuant to Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:

By transmitting your personal data, you voluntarily consent to the processing of your entered or transmitted personal data for the purposes of handling the inquiry and to being contacted. By transmitting your data to us, you also voluntarily give express consent pursuant to Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this privacy policy and for the purposes named, in particular for such transfers to third countries for which an adequacy decision of the EU/EEA exists or does not exist, as well as to companies or other bodies which are not covered by an existing adequacy decision on the basis of self-certification or other accession criteria, and in which or for which considerable risks exist and no appropriate safeguards for the protection of your personal data exist (e.g. because of § 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When giving your voluntary and express consent, you were aware that an adequate level of data protection may not exist in third countries and that your data subject rights may not be enforceable. You may withdraw your data protection consent at any time with effect for the future. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. With a single action (the entry and transmission), you give several consents. These are both consents under EU/EEA data protection law and those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legal provisions which are required, among other things, as a legal basis for a planned further processing of your personal data. With your action you also confirm that you have read and taken note of this privacy policy.

5. Routine erasure and restriction of personal data

We process and store personal data for the period necessary to achieve the purpose of the processing, or where this has been provided for by the European legislator of directives and regulations or by another legislator in laws or regulations to which we are subject, or for as long as a legal basis for the processing exists.

If the purpose of the processing ceases to apply, or a storage period prescribed by the European legislator of directives and regulations or by another competent legislator expires, or the legal basis for the processing ceases to apply, the personal data are routinely restricted or erased in accordance with the statutory provisions.

6. Rights of the data subject under the GDPR

a) Right to confirmation

Every data subject has the right to obtain from the controller confirmation as to whether personal data concerning him or her are being processed.

If a data subject wishes to exercise this right, he or she may contact us at any time for this purpose.

b) Right of access

Every data subject has the right to obtain from the controller, at any time, free information about the personal data stored concerning him or her and a copy of those data. Furthermore, the European legislator of directives and regulations has granted the data subject access to the following information:

• the purposes of the processing,

• the categories of personal data that are processed,

• the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations,

• where possible, the envisaged period for which the personal data will be stored, or, if this is not possible, the criteria for determining that period,

• the existence of a right to rectification or erasure of personal data concerning him or her, or to restriction of processing by the controller, or of a right to object to this processing,

• the existence of a right to lodge a complaint with a supervisory authority,

• where the personal data are not collected from the data subject: all available information as to the origin of the data,

• the existence of automated decision-making, including profiling, pursuant to Art. 22 (1) and (4) GDPR and — at least in those cases — meaningful information about the logic involved as well as the significance and the envisaged consequences of such processing for the data subject.

Furthermore, the data subject has a right of access as to whether personal data have been transferred to a third country or to an international organisation. Where this is the case, the data subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.

If a data subject wishes to exercise this right, he or she may contact us at any time for this purpose.

c) Right to rectification

Every data subject has the right to obtain the rectification without undue delay of inaccurate personal data concerning him or her. Furthermore, taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of a supplementary statement.

If a data subject wishes to exercise this right, he or she may contact us at any time for this purpose.

d) Right to erasure (right to be forgotten)

Every data subject has the right to obtain from the controller the erasure without undue delay of personal data concerning him or her, where one of the following grounds applies and insofar as the processing is not necessary:

• The personal data were collected or otherwise processed for purposes for which they are no longer necessary.

• The data subject withdraws his or her consent on which the processing was based pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR, and there is no other legal basis for the processing.

• The data subject objects to the processing pursuant to Art. 21 (1) GDPR, and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Art. 21 (2) GDPR.

• The personal data have been unlawfully processed.

• The erasure of the personal data is necessary for compliance with a legal obligation under Union law or Member State law to which the controller is subject.

• The personal data have been collected in relation to the offer of information society services pursuant to Art. 8 (1) GDPR.

Where one of the aforementioned grounds applies and a data subject wishes to arrange for the erasure of personal data stored by us, he or she may contact us at any time for this purpose.

Where the personal data have been made public by us and our organisation, as controller, is obliged pursuant to Art. 17 (1) GDPR to erase the personal data, we, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other controllers which are processing the published personal data that the data subject has requested those other controllers to erase all links to those personal data, or copies or replications of those personal data, insofar as the processing is not necessary.

e) Right to restriction of processing

Every data subject has the right to obtain from the controller restriction of processing where one of the following conditions is met:

• The accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data.

• The processing is unlawful, the data subject opposes the erasure of the personal data and requests the restriction of the use of the personal data instead.

• The controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims.

• The data subject has objected to the processing pursuant to Art. 21 (1) GDPR and it has not yet been established whether the legitimate grounds of the controller override those of the data subject.

Where one of the aforementioned conditions is met and a data subject wishes to request the restriction of personal data stored by us, he or she may contact us at any time for this purpose.

f) Right to data portability

Every data subject has the right to receive the personal data concerning him or her which have been provided by the data subject to a controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where the processing is based on consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the processing is carried out by automated means, unless the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Furthermore, in exercising his or her right to data portability pursuant to Art. 20 (1) GDPR, the data subject has the right to have the personal data transmitted directly from one controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of other persons.

If a data subject wishes to exercise this right, he or she may contact us at any time for this purpose.

g) Right to object

Every data subject has the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on Art. 6 (1) (e) or (f) GDPR. This also applies to profiling based on these provisions.

In the event of an objection, we no longer process the personal data, unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing serves the establishment, exercise or defence of legal claims.

Where we process personal data in order to carry out direct marketing, the data subject has the right to object at any time to processing of the personal data for the purpose of such marketing. This also applies to profiling to the extent that it is related to such direct marketing. If the data subject objects to us to processing for direct marketing purposes, we will no longer process the personal data for these purposes.

In addition, the data subject has the right, on grounds relating to his or her particular situation, to object to processing of personal data concerning him or her which is carried out by us for scientific or historical research purposes or for statistical purposes pursuant to Art. 89 (1) GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.

If a data subject wishes to exercise this right, he or she may contact us at any time for this purpose. The data subject is furthermore free, in the context of the use of information society services and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.

h) Automated individual decision-making, including profiling

Every data subject has the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning him or her or similarly significantly affects him or her, where the decision (1) is not necessary for entering into, or the performance of, a contract between the data subject and the controller, or (2) is permissible on the basis of legal provisions of the Union or of the Member States to which the controller is subject and those legal provisions contain suitable measures to safeguard the rights and freedoms and the legitimate interests of the data subject, or (3) is based on the data subject's explicit consent.

Where the decision (1) is necessary for entering into, or the performance of, a contract between the data subject and the controller, or (2) it is based on the data subject's explicit consent, we take suitable measures to safeguard the rights and freedoms and the legitimate interests of the data subject, which include at least the right to obtain human intervention on the part of the controller, to express his or her own point of view and to contest the decision.

If a data subject wishes to exercise this right, he or she may contact us at any time for this purpose.

i) Right to withdraw data protection consent

Every data subject has the right to withdraw consent to the processing of personal data at any time.

If a data subject wishes to exercise this right, he or she may contact us at any time for this purpose.

7. General purpose of the processing, categories of data processed and categories of recipients

The general purpose of the processing of personal data is the handling of all processes that concern the controller, customers, prospective customers, business partners or other contractual or pre-contractual relationships between the groups named (in the broadest sense) or statutory obligations of the controller. This general purpose applies where no more specific purposes are stated for a concrete processing operation.

The categories of personal data processed by us are customer data, prospective-customer data, employee data (incl. applicant data) and supplier data. The categories of recipients of the personal data are public bodies, external bodies, internal processing, intra-group processing and other bodies.

A list of our processors and of the data recipients in third countries and, where applicable, of the international organisations is either published on our website or can be requested from us free of charge.

8. Legal bases for the processing

Art. 6 (1) (a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose. Where the processing of personal data is necessary for the performance of a contract to which the data subject is party, as is the case, for example, with processing operations that are necessary for a delivery of goods or the provision of another service or consideration, the processing is based on Art. 6 (1) (b) GDPR. The same applies to such processing operations that are necessary in order to take pre-contractual measures, for example in cases of inquiries about our products or services. Where we are subject to a legal obligation by which a processing of personal data becomes necessary, for example in order to fulfil tax obligations, the processing is based on Art. 6 (1) (c) GDPR.

In rare cases, the processing of personal data could become necessary in order to protect the vital interests of the data subject or of another natural person. This would be the case, for example, if a visitor were injured at our premises and his or her name, age, health insurance data or other vital information subsequently had to be passed on to a physician, a hospital or other third parties. The processing would then be based on Art. 6 (1) (d) GDPR.

Where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, the legal basis is Art. 6 (1) (e) GDPR.

Finally, processing operations could be based on Art. 6 (1) (f) GDPR. Processing operations which are not covered by any of the aforementioned legal bases are based on this legal basis where the processing is necessary for the purposes of a legitimate interest of our company or of a third party, except where the interests, fundamental rights and fundamental freedoms of the data subject override that interest. Such processing operations are permitted to us in particular because they were specifically mentioned by the European legislator. In this respect, he took the view that a legitimate interest could be assumed, for example, where the data subject is a customer of the controller (Recital 47 sentence 2 GDPR).

9. Legitimate interests in the processing pursued by the controller or a third party, and direct marketing

Where the processing of personal data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the conduct of our business activity for the benefit of the well-being of our staff and our shareholders.

We may send you direct marketing about our own goods or services which are similar to the goods or services you inquired about, commissioned or purchased. You may object to direct marketing at any time (e.g. by email). In doing so, you incur no costs other than the transmission costs according to the basic tariffs. The processing of personal data for the purposes of direct marketing is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.

Our messages and newsletters may also constitute communication for the purposes of direct marketing within the meaning of Art. 13 (2) of EU Directive 2002/58 (data protection directive for electronic communications) and the national law resulting from the Directive, where we have obtained your electronic and other contact information in connection with the sale of a service or a product, which includes the creation of a free user account through which you are permitted, among other things, to access free content on our websites and publications (newsletters etc.), where we advertise similar products or services with the direct marketing, so that the direct marketing is also permissible without consent (cf. EuGH, Urt. v. 13.11.2025, Rs. C 654/23 (CJEU, judgment of 13 November 2025, Case C-654/23)). You may refuse the use of the contact information in such cases at any time free of charge.

10. Period for which the personal data are stored

The criterion for the duration of the storage of personal data is the respective statutory retention period. Where no statutory retention period exists, the criterion is the contractual or internal retention period. After expiry of the period, the corresponding data are routinely deleted, unless they are still required for the performance of a contract or the initiation of a contract. This applies in particular to all processing operations for which no more specific criteria have been laid down.

11. Statutory or contractual provisions for the provision of the personal data; necessity for the conclusion of a contract; obligation of the data subject to provide the personal data; possible consequences of failure to provide the data

We inform you that the provision of personal data is in part required by law (e.g. tax provisions) or may also result from contractual arrangements (e.g. information about the contractual partner). Sometimes it may be necessary for the conclusion of a contract that a data subject provides us with personal data which must subsequently be processed by us. The data subject is, for example, obliged to provide us with personal data if our organisation concludes a contract with him or her. Failure to provide the personal data would have the consequence that the contract with the data subject could not be concluded. Before personal data are provided by the data subject, he or she must contact us. We inform the data subject, on a case-by-case basis, whether the provision of the personal data is prescribed by law or by contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data, and what consequences the failure to provide the personal data would have.

12. Existence of automated decision-making

As a responsible company, we normally refrain from automatic decision-making or profiling. If, in exceptional cases, we carry out automatic decision-making or profiling, we inform the data subject either separately or via a sub-item in our privacy policy (here on our website). In this case, the following applies:

Automated decision-making, including profiling, may take place where this (1) is necessary for entering into, or the performance of, a contract between the data subject and us, or (2) is permissible on the basis of legal provisions of the Union or of the Member States to which we are subject and those legal provisions contain suitable measures to safeguard the rights and freedoms and the legitimate interests of the data subject, or (3) takes place with the explicit consent of the data subject.

In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we take suitable measures to safeguard the rights and freedoms and the legitimate interests of the data subject. In these cases, you have the right to obtain human intervention on the part of the controller, to express your own point of view and to contest the decision.

Meaningful information about the logic involved as well as the significance and the envisaged consequences of such processing for the data subject are set out in this privacy policy where applicable.

13. Recipients in a third country and suitable or appropriate safeguards and the means by which a copy of them may be obtained, or where they are available.

Pursuant to Art. 46 (1) GDPR, the controller or a processor may transfer personal data to a third country only if the controller or the processor has provided suitable safeguards and on condition that enforceable rights and effective legal remedies are available to the data subjects. Suitable safeguards may, without requiring any specific authorisation by a supervisory authority, be provided by standard data protection clauses, Art. 46 (2) (c) GDPR.

With all recipients from third countries, the EU standard data protection clauses or other suitable safeguards are agreed before the first transfer of personal data, or the transfers are based on adequacy decisions. Consequently, it is ensured that suitable safeguards, enforceable rights and effective legal remedies are guaranteed for all processing of personal data. Every data subject can obtain a copy of the standard data protection clauses or adequacy decisions from us. In addition, the standard data protection clauses and adequacy decisions are available in the Official Journal of the European Union.

Art. 45 (3) GDPR empowers the European Commission to decide, by means of an implementing act, that a non-EU state ensures an adequate level of protection. This means a level of protection for personal data that essentially corresponds to the level of protection within the EU. Adequacy decisions have the consequence that personal data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) into a third country without further obstacles. Similar provisions apply to the United Kingdom, Switzerland and some other states.

In all cases in which the European Commission, or a government or competent authority of another state, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g. EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g. self-certified entities) are based exclusively on that entity's membership of the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in that framework. If we or one of our group companies is established in a third country with an adequate level of protection, all transfers to us or our group company are based exclusively on the respective adequacy decisions.

Every data subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legislative materials or on the websites of data protection supervisory authorities or other authorities or institutions.

14. Right to lodge a complaint with a data protection supervisory authority

As controller, we are obliged to inform the data subject of the existence of a right to lodge a complaint with a supervisory authority. The right to lodge a complaint is governed by Art. 77 (1) GDPR. According to this provision, every data subject, without prejudice to any other administrative or judicial remedy, has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement, if the data subject considers that the processing of personal data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint was restricted by the Union legislator solely to the effect that it may be exercised only vis-à-vis a single supervisory authority (Recital 141 sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same data subject. If a data subject wishes to complain about us, it is therefore requested that only a single supervisory authority be contacted.

15. Registration or completion of input masks on our website and your consent

You have the option of registering on our websites by providing personal data and/or of completing input masks. Which personal data are transmitted to us in doing so follows from the respective input mask used for the registration or input. The personal data entered by you are processed exclusively for internal use by us and for our own purposes. We may, however, pass your personal data on to one or more processors, for example to parcel service providers, which likewise use your personal data exclusively for purposes attributable to us as controller. A disclosure may also take place if you have commissioned the disclosure from us; the legal basis is then Art. 6 (1) (b) GDPR.

Through a registration or input on our website, the IP address assigned by your Internet service provider (ISP), as well as the date and the time of the registration or input, may also be stored. These data are stored because only in this way can misuse of our services be prevented, and these data make it possible, where necessary, to investigate criminal offences that have been committed. In this respect, the storage of these data is necessary for our own protection. The purpose of this processing is the aversion of danger and the detection of misuse and the investigation of criminal offences, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is in particular the protection of our information technology systems and the investigation of criminal offences. As a rule, these data are not passed on to third parties, unless there is a statutory obligation to pass them on or the disclosure serves criminal prosecution.

The registration, input and transmission of your personal data also serves us in offering you content or services which, by their nature, can only be offered to persons who are registered or known to us. You are free to have the personal data stated at registration amended at any time, or completely deleted from our data stock. The purposes of the processing are the receipt of the data by us and the use of your data for further processing, for communication with you and the mapping or implementation of the registration or of the input purposes. The legal basis is your consent pursuant to Art. 6 (1) (a) GDPR and/or Art. 49 (1) (1) (a) GDPR.

By entering and transmitting your data, you voluntarily consent to the processing of your entered personal data. By entering your data and transmitting them to us, you also voluntarily give express consent pursuant to Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this privacy policy and for the purposes named, in particular for such transfers to third countries for which an adequacy decision of the EU/EEA exists or does not exist, as well as to companies or other bodies which are not covered by an existing adequacy decision on the basis of self-certification or other accession criteria, and in which or for which considerable risks exist and no appropriate safeguards for the protection of your personal data exist (e.g. because of § 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When giving your voluntary and express consent, you were aware that an adequate level of data protection may not exist in third countries and that your data subject rights may not be enforceable. You may withdraw your data protection consent at any time with effect for the future. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. With a single action (the entry and transmission), you give several consents. These are both consents under EU/EEA data protection law and those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legal provisions which are required, among other things, as a legal basis for a planned further processing of your personal data. With your action you also confirm that you have read and taken note of this privacy policy.

We provide every data subject, at any time on request, with information as to which personal data concerning the data subject are stored. Furthermore, we rectify or erase personal data at the wish or indication of the data subject, insofar as no statutory retention obligations or other grounds justifying processing stand in the way. All our employees are happy to be available to you as contact persons in this connection.

16. Cookies and external connections, advertising IDs and your consent

On our websites we use cookies, advertising IDs and external connections in order, on the one hand, to improve the user experience and, on the other hand, to optimise our advertising and existing processes. Cookies are small text files which are stored by your browser on your computer or system and which contain information in order to identify you more quickly on a visit. Almost all modern websites use cookies, advertising IDs and/or external connections.

Cookies have a so-called cookie ID. This ID is unique to each cookie and helps to distinguish your browser from others. This enables us to adapt our service to your needs and to provide you with a personalised user experience. Cookies also make it easier for you to use websites. For example, you do not have to log in again each time to an online shop or on a website if a cookie has remembered your data. You can disable the use of cookies in your browser at any time, or delete stored cookies. We point out that, without the stored cookies, it may no longer be possible to use all functions on our websites.

Advertising IDs are bound to your hardware. This ID is unique to each device and helps to distinguish your devices from others. This enables us to adapt our service to your needs and to provide you with a personalised user experience.

External connections are established in order to load and store external content and external cookies, and likewise have the purpose of optimising the user experience, advertising and our processes. The legal basis for the storage and reading of our cookies and advertising IDs and for the establishment of the external connections is the aforementioned legitimate interests (Art. 6 (1) (f) GDPR), unless a separate consent pursuant to Art. 6 (1) (a) GDPR and/or Art. 49 (1) (1) (a) GDPR has been obtained from you.

The following applies to all cookies, advertising IDs and external connections integrated in a cookie banner:

By clicking the consent button in our cookie banner, you voluntarily consent to the setting or activation of the respective cookies and external connections, as well as to the transmission of advertising IDs and operating-system advertising IDs, such as AdIDs (Android), IDFAs (Apple) or the Windows advertising ID (consent pursuant to Art. 6 (1) (a) GDPR), the functions of which are explained in more detail in this privacy policy or in documents linked below or external links and are therefore known to you. By activating the consent button, you also voluntarily give express consent pursuant to Art. 49 (1) (1) (a) GDPR to personalised advertising, advertising-ID transmissions and other data transfers to third countries to and by the companies named in this privacy policy and for the purposes named, in particular for such transfers to third countries for which an adequacy decision of the EU/EEA exists or does not exist, as well as to companies or other bodies which are not covered by an existing adequacy decision on the basis of self-certification or other accession criteria, and in which or for which considerable risks exist and no appropriate safeguards for the protection of your personal data exist (e.g. because of § 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When giving your voluntary and express consent, you were aware that an adequate level of data protection may not exist in third countries and that your data subject rights may not be enforceable. You may withdraw your data protection consent at any time with effect for the future, e.g. by changing your cookie settings or deleting your cookies. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. With a single action (activating the consent button), you give several consents. These are both consents under EU/EEA data protection law and those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legal provisions which are necessary, among other things, for storing and reading information and are required as a legal basis for a planned further processing of the data read out. Your consent includes in particular express consent to all downstream data processing by third-party providers, which may also take place in unsafe third countries, in particular for personalised and targeted advertising, by all companies named in our privacy policy, as well as their sub-processors and controllers which receive data from these third-party providers or from us, or to which data are transmitted, within a data processing chain. You are aware that you can refuse your consent by clicking the other button or, where applicable, make individual settings. With your action you also confirm that you have read and taken note of this privacy policy.

For all cookies and external connections integrated in our cookie banner, in addition to the legal bases set out in other sections of this privacy policy, consent pursuant to Art. 6 (1) (a) GDPR and/or express consent pursuant to Art. 49 (1) (1) (a) GDPR also apply as legal bases.

17. Data protection provisions on the deployment and use of Google Site Verification

We use the Google Site Verification service in order to verify our website to Google. This verification is a prerequisite for the use of further Google services such as Google Search Console, Google Analytics or Google Ads. As part of Site Verification, a verification token is integrated via various methods (e.g. HTML file, meta tag, DNS record or Google Tag Manager) in order to prove ownership of the domain. When the service is used, personal data may be processed, in particular in the form of IP addresses, technical access data and information about the domain, the website or the Google account used.

The processing takes place automatically via Google servers. After successful verification, the website property is stored in the Google account of the verifying user.

The operating company of the service and thus the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative pursuant to Art. 14 of the Bundesgesetz über den Datenschutz (DSG) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zürich, Switzerland.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing is the technical proof of domain ownership for the activation of Google services such as Search Console or Analytics. The processing takes place on the basis of Art. 6 (1) (f) GDPR. The legitimate interest lies in the use of Google tools, the proper assignment of services to the domain and the technical protection of accounts against misuse.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service is, where applicable, a certified member of one or more of the Data Privacy Frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law nor by contract, nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Google can be retrieved at https://policies.google.com/privacy.

18. Data protection provisions on the deployment and use of JavaScript and JavaScript frameworks

On our website we use JavaScript or JavaScript frameworks as a client-side programming language or JS framework for the dynamic display of content and for interaction in the browser. JavaScript enables, among other things, the display of pop-ups, the loading of dynamic content, the tracking of user behaviour, the sending of forms and communication with third-party providers via APIs. JavaScript is not an independent software product with an external operating company, but a scripting language integrated by default in web browsers which is executed on our websites.

The source code based on JavaScript is hosted on our own IT infrastructure and executed by the web browser. The operating company of the service is us.

In addition, we may use various open-source JavaScript libraries or frameworks in the course of our web development, for example Vue JS, Angular JS or comparable projects. These serve the structured, modular extension of the functionality of our website, in particular for client-side validation, for optimising user guidance, for reducing loading times and for asynchronous data processing. Insofar as technically possible, we host these components locally on our own IT infrastructure, so that no data are transferred to third parties. In certain cases, however, individual components may be integrated via external sources such as content delivery networks (CDNs). This may result in connections being established with third-party servers, in the course of which in particular the IP address, technical metadata or usage parameters are processed.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing lies in enabling interactive functions, dynamic content, easier development, client-side validation and improved user guidance. The processing takes place on the basis of Art. 6 (1) (f) GDPR. The legitimate interest lies in easier development and in making available a functional and user-friendly website.

The criteria for determining the period for which personal data are processed depend on the respective purpose of the interaction, in particular the duration of the respective session or the storage of client-side information (e.g. in connection with cookies or local storage). The provision of personal data is required for the use of interactive website functions.

19. Data protection provisions on the deployment and use of Discord

Discord offers a versatile communication platform that was developed specifically for the gaming community, but is also used far beyond that by various groups and communities of interest. Users can exchange text messages on Discord, use voice and video communication and share screen content. The platform makes it possible to create and manage both private and public servers in order to form communities and to facilitate communication within groups.

When Discord is used, personal data such as user names, email addresses, communication content (e.g. text messages, images, videos), usage data and, for certain functions, also IP addresses are processed. This information is necessary in order to provide the services offered, to manage user accounts, to ensure the security of the platform and to offer a personalised user experience.

The operating company of the service and thus the recipient of the personal data is: Discord, Inc., 444 De Haro Street, Suite 200, San Francisco, CA 94107, USA. For data subjects in the EU and the EEA, Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: VeraSafe United Kingdom Ltd., 37 Albert Embankment, London SE1 7TL, United Kingdom.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing lies in the use and improvement of the communication services. The processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the data subject is party, and on Art. 6 (1) (f) GDPR, the legitimate interest being the provision and use of an efficient and secure platform for communication and community-building.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service is, where applicable, a certified member of one or more of the Data Privacy Frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Discord, Inc. can be retrieved at https://discord.com.

20. Data protection provisions on the deployment and use of Microsoft Teams

Microsoft Teams is a communication and collaboration tool within the Microsoft 365 suite that was designed specifically for business use. It enables teams to work together effectively wherever they are, through functions such as chat, video calls, meetings, file sharing and integration with other Microsoft products and services. Microsoft Teams promotes teamwork through digital spaces that enable seamless communication and collaboration, regardless of whether the team members are in the same office or distributed across various locations worldwide.

When Microsoft Teams is used, personal data such as names, email addresses, telephone numbers, usage data (e.g. time and duration of meetings, chat logs), content data (e.g. files, notes, messages) and location data are processed. This information is necessary in order to provide the services, to improve the user experience, to ensure support and to ensure the security and compliance of the services.

The operating company of the service and thus the recipient of the personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and the EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, Great Britain. The representative pursuant to Art. 14 of the Bundesgesetz über den Datenschutz (DSG) in Switzerland is: Microsoft Schweiz GmbH, Seestraße 356, 8038 Zürich, Switzerland.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing lies in the use, provision, administration and improvement of Microsoft Teams for communication. The processing is based on the performance of a contract (Art. 6 (1) (b) GDPR) to which the data subject is party, and on legitimate interests (Art. 6 (1) (f) GDPR), such as the improvement of our services and the use and provision of modern means of communication.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service is, where applicable, a certified member of one or more of the Data Privacy Frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Microsoft Teams can be viewed at https://privacy.microsoft.com.

21. Data protection provisions on the deployment and use of Slack

Slack is a platform for team communication and collaboration that enables companies and organisations to communicate more efficiently through channels, direct messages and the exchange of files. Slack is used to coordinate projects, to exchange information and to collaborate in real time.

When Slack is used, various types of personal data are processed, including contact data such as names, email addresses and telephone numbers, and the contents of the communication, including messages, shared files and other information. These data are necessary in order to provide the services, to manage user accounts and to personalise the platform.

The operating company of the service and thus the recipient of the personal data is: Slack Technologies, LLC, 50 Fremont Street, San Francisco, CA 94105, USA. For data subjects in the EU and the EEA, Slack Technologies Limited, Salesforce Tower, 60 R801, North Dock, Dublin, Ireland, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Salesforce.com EMEA Limited, 3rd Floor, Salesforce Tower, 110 Bishopsgate, London EC2N 4AY, United Kingdom.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the data processing lies in the use of the communication and collaboration platform. The processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR to which the data subject is party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the improvement of our communication.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service has, where applicable, concluded one of the EU standard contracts with us. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Slack can be viewed at https://slack.com.

22. Data protection provisions on the deployment and use of Telegram

Telegram offers a messaging service that is characterised by high security standards and user-friendliness. Users can exchange messages, images, videos and files via Telegram and use group chats and channels for communication. A special feature of Telegram is end-to-end encryption in so-called Secret Chats, which ensures secure communication.

When Telegram is used, certain personal data are processed; these include the user's telephone number as the primary means of identification and, optionally, the name and the profile picture. Telegram stores messages in encrypted form on its servers in order to enable synchronisation between the user's various devices. Telegram emphasises, however, that it has no access to the contents of the end-to-end-encrypted Secret Chats.

The operating company of the service and thus the recipient of the personal data is: Telegram Messenger, Inc., Vistra Corporate Services Centre, Wickhams Cay Ii, Road Town, Tortola, VG1110, British Virgin Islands. For data subjects in the EU and the EEA, the European Data Protection Office (EDPO), Avenue Huart Hamoir 71, 1030 Brussels, Belgium, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Telegram Messenger LLP, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the data processing is to make a messaging service available and to use it. The processing of the telephone number and, optionally, of further data such as name and profile picture takes place on the basis of the users' consent pursuant to Art. 6 (1) (a) GDPR or serves the performance of a contract pursuant to Art. 6 (1) (b) GDPR to which the data subject is party. The use of the application is furthermore based on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of an efficient method of communication.

The operating company of the service is located in a third country. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service has, where applicable, concluded one of the EU standard contracts with us. Where transfers take place, you can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Telegram can be retrieved at https://telegram.org.

23. Data protection provisions on the deployment and use of WhatsApp

WhatsApp LLC offers a widely used instant-messaging service that enables users to send and receive text messages, voice messages, images, videos and documents. In addition, users can make voice and video calls. WhatsApp is characterised by end-to-end encryption, which ensures the security and privacy of communication between the users.

When WhatsApp is used, personal data such as telephone numbers, profile names, profile pictures, online status information and location data are processed. In addition, information about the interactions between the users, such as messages and call data, is transmitted in encrypted form and may be used by WhatsApp to improve the service and to ensure security.

The operating company of the service and thus the recipient of the personal data is: WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. The representative under national law in the United Kingdom is: WhatsApp Ltd., 57 Garth Road, London, England, NW2 2NH, United Kingdom.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the data processing lies in the use of the messaging service and the associated functions. The processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR to which the data subject is party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of an efficient platform, the improvement of our services and ensuring the security of the users and their data.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of WhatsApp can be viewed at https://www.whatsapp.com.

24. Data protection provisions on the deployment and use of IONOS

IONOS is a company in the field of web hosting and domain services. As a provider in this field, IONOS not only provides the technical infrastructure for our online presence, but also offers a range of related services, such as email hosting, SSL certificates and data backup. Through the use of IONOS, various types of data are processed, in particular data that arise when domains are registered, such as the name of the domain holder, contact data and technical information about the domain.

In addition, IONOS collects data about website traffic in order to ensure IT security and to ward off attacks such as DDoS attacks. This information may include IP addresses, timestamps and pages accessed. The processing of these data serves the provision and optimisation of the hosting services, the safeguarding of network and information security and the improvement of the user-friendliness of our website.

The operating company of the service and thus the recipient of the personal data is: IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The representative under national law in the United Kingdom is: IONOS Cloud Limited, 2 Cathedral Walk, The Forum, Gloucester, GL1 1AU, United Kingdom.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing is the use of web hosting services and related services. The processing is based on Art. 6 (1) (f) GDPR. The legitimate interest lies in the reliable and secure provision of our website and of the associated services.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of IONOS SE can be retrieved at https://www.ionos.de.

25. Data protection provisions on the deployment and use of Google Fonts

Google Fonts is a free service of Google LLC that makes a wide range of fonts available to web developers in order to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on various devices and browsers. Google Fonts is provided via the Google servers, thereby ensuring high availability and fast loading times.

When Google Fonts is used, personal data such as IP addresses and browser information may be processed, because a request is sent to the Google servers when the fonts are loaded. These data are used in order to provide the service, to optimise performance and to prevent misuse.

The operating company of the service and thus the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative pursuant to Art. 14 of the Bundesgesetz über den Datenschutz (DSG) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zürich, Switzerland.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing lies in the use and optimisation of the font service for web developers and end users. The processing is based on Art. 6 (1) (f) GDPR, the legitimate interest being the improvement of the user experience on websites through the provision of a variety of fonts and the ensuring of fast loading times.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service is, where applicable, a certified member of one or more of the Data Privacy Frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Google Fonts can be viewed at https://policies.google.com/privacy.

26. Data protection provisions on the deployment and use of Twilio

We use Twilio for the technical implementation and performance of communication services such as the sending of SMS, voice services, authentication procedures (e.g. two-factor authentication), WhatsApp messages and for the integration of real-time communication into our applications. Twilio offers APIs and platform solutions with which communication processes can be automated and scaled and data can be transmitted securely. In this context, personal data may be processed, in particular where users receive or send messages via one of the systems supported by Twilio, make or receive calls, or communicate via other supported channels. Among other things, telephone numbers, IP addresses, device data, communication content, timestamps, usage logs, location information, connection data and metadata relating to the communication are processed.

The processing takes place automatically via Twilio's cloud-based infrastructure, whereby data are processed both for the provision of the services and in order to ensure transmission security, for error analysis and for compliance with regulatory requirements. Twilio offers mechanisms for encryption, access control and auditing in order to ensure the security of the information processed. Depending on the use case, communication via Twilio may be connected with other third-party providers (e.g. network operators or messaging services).

The operating company of the service and thus the recipient of the personal data is: Twilio, Inc., 101 Spear Street, 5th Floor, San Francisco, CA 94105, USA. For data subjects in the EU and the EEA, Twilio Ireland Limited, 70 Sir John Rogerson's Quay, Dublin 2, Dublin, D02 R296, Ireland, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Twilio UK Limited, 280 Bishopsgate, London, EC2M 4AG, Great Britain.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing is the performance, automation and logging of communication processes via digital channels in order to improve customer contact, to ensure the authenticity of user access and for integration into operational workflows. The processing takes place on the basis of Art. 6 (1) (b) GDPR, that is, for the performance of a contract to which the data subject is party, and of Art. 6 (1) (f) GDPR. The legitimate interest lies in the secure and reliable provision of modern communication solutions, the improvement of the user experience and the fulfilment of technical and regulatory requirements.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service is, where applicable, a certified member of one or more of the Data Privacy Frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is not prescribed by law or by contract, nor is it required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Twilio can be retrieved at https://www.twilio.com/.

27. Data protection provisions on the deployment and use of Google Analytics

Google Analytics is a tool of Google LLC that offers website and app operators detailed statistics on traffic and user behaviour. It enables the collection and analysis of data on website visits, user interactions and conversion rates, which helps operators to understand and optimise their online presence. Google Analytics uses cookies in order to collect information about the behaviour of users, including page views, time spent on the page and the paths that users take on the website.

When Google Analytics is used, personal data such as IP addresses, browser information and interaction data are processed. These data help website operators to measure the performance of their website, to improve the user experience and to develop targeted marketing strategies.

The operating company of the service and thus the recipient of the personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and the EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative pursuant to Art. 14 of the Bundesgesetz über den Datenschutz (DSG) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zürich, Switzerland.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing lies in the analysis and optimisation of websites and apps and of advertising. The processing is based on Art. 6 (1) (f) GDPR, the legitimate interest being the improvement of the website, the increase in user-friendliness and the effectiveness of online marketing.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service is, where applicable, a certified member of one or more of the Data Privacy Frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Google Analytics can be viewed at https://policies.google.com/privacy.

28. Data protection provisions on the deployment and use of LinkedIn

LinkedIn is a social network for professional contacts and career development. The platform enables users to create a professional profile, to network with colleagues, business partners and potential employers, to share professional experience and skills and to inform themselves about industry news. LinkedIn also offers tools for companies and recruiters to search for talent, to publish job advertisements and to build a brand presence.

When LinkedIn is used, personal data such as names, email addresses, professional titles and experience, educational background, skills, interests and usage data of the platform are processed. This information is necessary in order to provide and use the service, to create networking opportunities, to present personalised content and job offers and to ensure the security of user data.

The operating company of the service and thus the recipient of the personal data is: LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing lies in the use and optimisation of networking and career services. The processing is based on the user's consent (Art. 6 (1) (a) GDPR), the performance of a contract (Art. 6 (1) (b) GDPR) to which the data subject is party, and on legitimate interests (Art. 6 (1) (f) GDPR), such as marketing and recruitment.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service is, where applicable, a certified member of one or more of the Data Privacy Frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of LinkedIn Corporation can be viewed at https://www.linkedin.com.

29. Data protection provisions on the deployment and use of Meta Platforms

Meta Platforms is a technology company that operates several social networks and communication platforms, including Facebook, Instagram, WhatsApp and Messenger. These services enable billions of users worldwide to network, to share content, to communicate and to form communities around their interests.

When the services of Meta Platforms are used, personal data such as names, email addresses, telephone numbers, profile information, posts, comments, messages, interactions with content and advertising, location data and payment information are processed. This information is used in order to provide the services, to ensure the security of users, to offer personalised content and advertising and to improve the user experience.

The operating company of the service and thus the recipient of the personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and the EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent's Place, London, NW1 3FG, United Kingdom.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing lies in the use, provision, administration and improvement of the social networks and communication services. The processing is based on the user's consent (Art. 6 (1) (a) GDPR), the performance of a contract (Art. 6 (1) (b) GDPR) to which the data subject is party, and on legitimate interests (Art. 6 (1) (f) GDPR), such as the use and improvement of the services.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service is, where applicable, a certified member of one or more of the Data Privacy Frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Meta Platforms, Inc. can be viewed at https://www.facebook.com.

30. Data protection provisions on the deployment and use of Reddit

Reddit is an online community platform that enables users to share and comment on content. When Reddit is used, personal data such as usage data, IP addresses, location information and interaction data are processed in order to display content and to enable interaction with the platform. These data are used in order to display personalised content, to improve the user experience and to keep the platform secure.

The operating company of the service and thus the recipient of the personal data is: Reddit, Inc., 548 Market St. 16093, San Francisco, California, 94104, USA. For data subjects in the EU and the EEA, Reddit Netherlands B.V., Euro Business Center, Keizersgracht 62, 1015CS Amsterdam, Netherlands, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Reddit UK Limited, 5 New Street Square, London, EC4A 3TW, United Kingdom.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the processing is the use and provision of user interactions and personalised content on the platform. The processing is based on Art. 6 (1) (f) GDPR, the legitimate interest being the improvement of the user experience, interactivity on the platform and the use of the platform.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service is, where applicable, a certified member of one or more of the Data Privacy Frameworks. Further details can be found at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law nor by contract, nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of Reddit can be retrieved at https://www.reddit.com/.

31. Data protection provisions on the deployment and use of X (formerly Twitter)

X (formerly known as Twitter) is a global platform for public self-expression and conversation in real time. Users can create and share short messages, so-called tweets, which may contain text, images, videos and links. The platform enables users to follow current news, to interact with others and to take part in global discussions.

When X is used, various types of personal data are processed, including user names, email addresses, telephone numbers and location data. This information may be used for the creation of accounts, the personalisation of content, the provision of advertising, security purposes and for analytical evaluations.

The operating company of the service and thus the recipient of the personal data is: X Corp., 865 FM-1209, Building 2, Bastrop, TX 78602, USA. For data subjects in the EU and the EEA, X Internet Unlimited Company, 1 Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative pursuant to Art. 14 of the Bundesgesetz über den Datenschutz (DSG) in Switzerland is: X Schweiz GmbH, c/o Wasag Treuhand AG, Normannenstrasse 8, 3018 Bern, Switzerland.

Personal data are processed, among other things, on the basis of the user's consent (Art. 6 (1) (a) GDPR), for the performance of a contract (Art. 6 (1) (b) GDPR) to which the data subject is party, or on the basis of legitimate interests (Art. 6 (1) (f) GDPR), such as the use of the platform and the improvement of communication with the public.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service has, where applicable, concluded one of the EU standard contracts with us. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the contractual relationship between us and the operating company of the service or statutory or contractual retention periods. The provision of the personal data is neither prescribed by law or by contract nor required for the conclusion of a contract. You are not obliged to provide personal data to us or to the operating company of the service. If the data are not provided, however, our services or those of the operating company of the service may not be able to be used.

Further information and the applicable data protection provisions of X can be viewed at https://twitter.com/.

32. Data protection provisions on the deployment and use of Stripe

Stripe is a technology company that offers powerful and flexible tools for e-commerce, including payment processing, billing and financial management solutions. Stripe enables companies of any size to accept and process online payments, to manage subscriptions and to carry out fraud prevention. The platform is known for reducing the complexity of financial transactions and for making them more secure and more user-friendly.

When Stripe services are used, personal data such as names, addresses, email addresses, telephone numbers, bank and payment information and transaction data are processed. This information is necessary in order to provide the payment services, to prevent fraud, to offer customer support and to fulfil legal requirements.

The operating company of the service and thus the recipient of the personal data is: Stripe, Inc., 354 Oyster Point Boulevard, San Francisco, CA 94080, USA. For data subjects in the EU and the EEA, Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, acts as the contact point and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Stripe Payments UK Ltd., 9th Floor, 107 Cheapside, London, EC2V 6DN, United Kingdom.

Purposes for which the personal data are to be processed, and the legal basis for the processing: The purpose of the data processing lies in the use of payment processing via Stripe. The processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR to which the data subject is party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the improvement of our services, fraud prevention, the use of efficient payment applications, and compliance with statutory requirements.

The operating company of the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or on other suitable or appropriate safeguards named in Art. 46 (2) GDPR. The operating company of the service has, where applicable, concluded one of the EU standard contracts with us. You can request a copy of the suitable or appropriate safeguards from us.

The criteria for determining the period for which the personal data are processed are the statutory or contractual retention periods. The provision of the personal data is prescribed by law or by contract, or is required for the conclusion of a contract. You are not obliged to provide us with personal data for this processing. If the data are not provided, however, our services cannot be used by you.

Further information and the applicable data protection provisions of Stripe can be viewed at https://stripe.com.

This privacy policy was created through the use of a generator that was developed jointly by specialists in telecommunications law, external data protection officers and the ISO 22301 certification body.