Privacy policy

Privacy policy

Table of Contents

Introduction and Overview

We have prepared this privacy policy (version 14.04.2023-111824141) to explain to you, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we, as the controller – and the processors commissioned by us (e.g. providers) – process, will process in the future, and what lawful options you have. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about data that we process about you.

Privacy policies usually sound very technical and use legal jargon. This privacy policy, on the other hand, is intended to describe the most important things to you as simply and transparently as possible. Where it promotes transparency, technical terms are explained in a reader-friendly way, links to further information are provided, and graphics are used. We thus inform you in clear and simple language that, within the scope of our business activities, we only process personal data when there is a corresponding legal basis. This is certainly not possible if one provides explanations that are as brief, unclear and legally/technically worded as possible, as is often standard on the Internet when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is one piece of information or another that you were not yet aware of.
If you still have questions, we would ask you to contact the responsible office named below or in the legal notice, follow the links provided, and view further information on third-party websites. Our contact details can of course also be found in the legal notice.

Scope of Application

This privacy policy applies to all personal data processed by us within the company and to all personal data processed by companies commissioned by us (processors). By personal data we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data ensures that we can offer and bill for our services and products, whether online or offline. The scope of this privacy policy includes:

  • all online presences (websites, online shops) that we operate
  • social media presences and email communication
  • mobile apps for smartphones and other devices

In short: The privacy policy applies to all areas in which personal data is processed in a structured manner within the company via the channels mentioned. Should we enter into legal relationships with you outside these channels, we will inform you separately if necessary.

Legal Bases

In the following privacy policy, we provide you with transparent information about the legal principles and provisions, i.e. the legal bases of the General Data Protection Regulation, that enable us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can of course read this EU General Data Protection Regulation online on EUR-Lex, the access point to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679 read.

We process your data only if at least one of the following conditions applies:

  1. Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
  2. Contract (Article 6(1)(b) GDPR): In order to fulfill a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase contract with you, we require personal information in advance.
  3. Legal obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally obliged to keep invoices for accounting purposes. These generally contain personal data.
  4. Legitimate interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and economically efficiently. This processing is therefore a legitimate interest.

Other conditions, such as the performance of tasks in the public interest and the exercise of official authority, as well as the protection of vital interests, generally do not apply to us. If such a legal basis should nevertheless be relevant, it will be indicated at the appropriate point.

In addition to the EU regulation, national laws also apply:

  • In Austria this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), abbreviated DSG.
  • In Germany the Federal Data Protection Act, abbreviated BDSG.

If further regional or national laws apply, we will inform you about them in the following sections.

Contact Details of the Controller

If you have any questions about data protection or the processing of personal data, you will find the contact details of the responsible person or office below:
AdSimple GmbH
Fabriksgasse 20, 2230 Gänserndorf, Austria

Email: [email protected]
Phone: +43 2282 / 60 715
Legal notice: https://www.adsimple.at/impressum/

Storage Period

As a general criterion, we store personal data only for as long as is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for the data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.

If you request the deletion of your data or withdraw your consent to data processing, the data will be deleted as quickly as possible, provided there is no obligation to store it.

We will inform you further below about the specific duration of the respective data processing, provided we have further information on this.

Rights under the General Data Protection Regulation

In accordance with Articles 13 and 14 GDPR, we inform you about the following rights to which you are entitled so that data is processed fairly and transparently:

  • According to Article 15 GDPR, you have the right to information about whether we process data about you. If this is the case, you have the right to receive a copy of the data and to obtain the following information:
    • the purpose for which we carry out the processing;
    • the categories, i.e. the types of data, that are processed;
    • who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
    • how long the data is stored;
    • the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
    • that you can lodge a complaint with a supervisory authority (links to these authorities can be found further below);
    • the origin of the data if we did not collect it from you;
    • whether profiling is carried out, i.e. whether data is automatically evaluated in order to create a personal profile of you.
  • According to Article 16 GDPR, you have the right to rectification of the data, which means that we must correct data if you find errors.
  • According to Article 17 GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you may request the deletion of your data.
  • According to Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data and may no longer use it further.
  • According to Article 20 GDPR, you have the right to data portability, which means that upon request we will provide you with your data in a commonly used format.
  • According to Article 21 GDPR, you have the right to object, which, once enforced, entails a change in the processing.
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then examine as quickly as possible whether we can legally comply with this objection.
    • If data is used for direct advertising, you may object to this type of data processing at any time. We may then no longer use your data for direct marketing.
    • If data is used for profiling, you may object to this type of data processing at any time. We may then no longer use your data for profiling.
  • According to Article 22 GDPR, under certain circumstances you have the right not to be subject to a decision based solely on automated processing (for example profiling).
  • According to Article 77 GDPR, you have the right to lodge a complaint. This means that you can complain to the data protection authority at any time if you believe that the processing of personal data violates the GDPR.

In short: You have rights – do not hesitate to contact the responsible office listed above!

If you believe that the processing of your data violates data protection law or that your data protection rights have otherwise been infringed, you can lodge a complaint with the supervisory authority. For Austria, this is the Data Protection Authority, whose website you can find at https://www.dsb.gv.at/ find. In Germany, each federal state has a data protection officer. For more detailed information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) contact. The following local data protection authority is responsible for our company:

Austrian Data Protection Authority

Head: Mag. Dr. Andrea Jelinek

Address: Barichgasse 40-42, 1030 Vienna

Phone no.: +43 1 52 152-0

Email address:
[email protected]

Website:
https://www.dsb.gv.at/

Data Transfer to Third Countries

We transfer or process data in countries outside the EU (third countries) only if you consent to this processing, if it is required by law or contractually necessary, and in any case only to the extent that this is generally permitted. In most cases, your consent is the most important reason why we have data processed in third countries. The processing of personal data in third countries such as the USA, where many software manufacturers offer services and have their server locations, may mean that personal data is processed and stored in unexpected ways.

We expressly point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. Data processing by US services (such as Google Analytics) may result in data being processed and stored without anonymization. Furthermore, US government authorities may be able to access individual data. In addition, collected data may be linked with data from other services of the same provider, provided you have a corresponding user account. Where possible, we try to use server locations within the EU, if this is offered.

We will provide you with more detailed information about data transfer to third countries at the appropriate places in this privacy policy, where applicable.

Security of Data Processing

To protect personal data, we have implemented both technical and organizational measures. Wherever possible, we encrypt or pseudonymize personal data. In doing so, we make it as difficult as possible, within our means, for third parties to infer personal information from our data.

Art. 25 GDPR refers here to “data protection by design and by default” and means that both software (e.g. forms) and hardware (e.g. access to the server room) should always be designed with security in mind and appropriate measures implemented. Where necessary, we will discuss specific measures below.

TLS encryption with https

TLS, encryption and https sound very technical, and they are. We use HTTPS (Hypertext Transfer Protocol Secure stands for “secure hypertext transfer protocol”) to transmit data over the Internet in a way that is protected against eavesdropping.
This means that the complete transmission of all data from your browser to our web server is secured – nobody can “listen in”.

We have thus introduced an additional layer of security and comply with data protection by design (Article 25(1) GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission on the Internet, we can ensure the protection of confidential data.
You can recognize the use of this data transmission safeguard by the small lock symbol at the top left of the browser, to the left of the Internet address (e.g. examplepage.de), and by the use of the https scheme (instead of http) as part of our Internet address.
If you would like to know more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to obtain good links to further information.

Communication

Communication Summary

Data subjects: Everyone who communicates with us by telephone, email or online form
Processed data: e.g. telephone number, name, email address, entered form data. More details can be found for the respective type of contact used
Purpose: Handling communication with customers, business partners, etc.
Storage period: Duration of the business case and the statutory provisions
?? Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)

If you contact us and communicate by telephone, email or online form, personal data may be processed.

The data is processed for handling and processing your question and the related business transaction. The data is stored for as long as the business case lasts or for as long as the law requires.

Data subjects

All those who seek contact with us via the communication channels provided by us are affected by the processes mentioned.

Telephone

If you call us, the call data is stored in pseudonymized form on the respective end device and by the telecommunications provider used. In addition, data such as name and telephone number may subsequently be sent by email and stored for the purpose of responding to the inquiry. The data is deleted as soon as the business case has ended and legal requirements permit this.

Email

If you communicate with us by email, data may be stored on the respective end device (computer, laptop, smartphone, etc.) and data will be stored on the email server. The data is deleted as soon as the business case has ended and legal requirements permit this.

Online forms

If you communicate with us using an online form, data is stored on our web server and, if applicable, forwarded to one of our email addresses. The data is deleted as soon as the business case has ended and legal requirements permit this.

Legal Bases

The processing of the data is based on the following legal bases:

  • Art. 6(1)(a) GDPR (consent): You give us consent to store your data and to continue using it for purposes relating to the business case;
  • Art. 6(1)(b) GDPR (contract): Processing is necessary for the performance of a contract with you or with a processor, such as the telephone provider, or we must process the data for pre-contractual activities, such as preparing an offer;
  • Art. 6(1)(f) GDPR (legitimate interests): We want to handle customer inquiries and business communication in a professional manner. Certain technical facilities such as email programs, Exchange servers and mobile network operators are necessary for this in order to conduct communication efficiently.

Data Processing Agreement (DPA)

In this section, we would like to explain what a data processing agreement is and why it is needed. Because the word “Auftragsverarbeitungsvertrag” is quite a tongue twister, we will also often use only the acronym DPA here in the text. Like most companies, we do not work alone, but also make use of services provided by other companies or individuals. By involving various companies or service providers, we may pass on personal data for processing. These partners then act as processors, with whom we conclude a contract, the so-called data processing agreement (DPA). The most important thing for you to know is that the processing of your personal data takes place exclusively according to our instructions and must be governed by the DPA.

Who are processors?

As a company and website owner, we are responsible for all data that we process from you. In addition to controllers, there may also be so-called processors. This includes any company or person that processes personal data on our behalf. More precisely, and according to the GDPR definition: any natural or legal person, public authority, agency or other body that processes personal data on our behalf is considered a processor. Processors may therefore be service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.

For a better understanding of the terminology, here is an overview of the three roles in the GDPR:

Data subject (you as a customer or interested party) ? Controller (we as the company and client) ? Processor (service providers such as web hosts or cloud providers)

Content of a data processing agreement

As already mentioned above, we have concluded a DPA with our partners who act as processors. Above all, it states that the processor processes the data to be processed exclusively in accordance with the GDPR. The contract must be concluded in writing; however, in this context, electronic conclusion of the contract is also considered “written”. The processing of personal data is carried out only on the basis of the contract. The contract must contain the following:

  • binding to us as the controller
  • obligations and rights of the controller
  • categories of data subjects
  • type of personal data
  • type and purpose of data processing
  • subject matter and duration of data processing
  • place where data processing is carried out

Furthermore, the contract contains all obligations of the processor. The most important obligations are:

  • to ensure data security measures
  • to take possible technical and organizational measures to protect the rights of the data subject
  • to maintain a data processing register
  • to cooperate with the data protection supervisory authority upon request
  • to carry out a risk analysis with regard to the personal data received
  • sub-processors may only be engaged with the written approval of the controller

You can see what such a DPA specifically looks like, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html view. A sample contract is presented here.

Cookies

Cookies Summary

Data subjects: Website visitors
Purpose: depends on the respective cookie. More details can be found further below or from the manufacturer of the software that sets the cookie.
Processed data: Depends on the cookie used in each case. More details can be found further below or from the manufacturer of the software that sets the cookie.
Storage period: depends on the respective cookie; may vary from hours to years
?? Legal bases: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What are cookies?

Our website uses HTTP cookies to store user-specific data.
In the following, we explain what cookies are and why they are used so that you can better understand the following privacy policy.

Whenever you browse the Internet, you use a browser. Well-known browsers include Chrome, Safari, Firefox, Internet Explorer and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

One thing cannot be denied: cookies are truly useful little helpers. Almost all websites use cookies. More precisely, they are HTTP cookies, since there are also other cookies for other areas of application. HTTP cookies are small files that are stored on your computer by our website. These cookie files are automatically placed in the cookie folder, essentially the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.

Cookies store certain user data from you, such as language or personal page settings. When you visit our site again, your browser transmits the “user-related” information back to our site. Thanks to cookies, our website knows who you are and offers you the settings you are accustomed to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.

The following graphic shows a possible interaction between a web browser such as Chrome and the web server. The web browser requests a website and receives a cookie back from the server, which the browser uses again as soon as another page is requested.

HTTP cookie interaction between browser and web server

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site; third-party cookies are created by partner websites (e.g. Google Analytics). Each cookie must be assessed individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans or other “malware”. Cookies also cannot access information on your PC.

Cookie data may look like this, for example:

Name: _ga
Value: GA1.2.1326744211.152111824141-9
Purpose of use: Distinguishing website visitors
Expiration date: after 2 years

A browser should be able to support these minimum sizes:

  • At least 4096 bytes per cookie
  • At least 50 cookies per domain
  • At least 3000 cookies in total

What types of cookies are there?

The question of which cookies we specifically use depends on the services used and is clarified in the following sections of the privacy policy. At this point, we would like to briefly discuss the different types of HTTP cookies.

There are 4 types of cookies:

Essential cookies
These cookies are necessary to ensure basic website functions. For example, these cookies are needed when a user places a product in the shopping cart, then continues browsing on other pages and only later proceeds to checkout. These cookies prevent the shopping cart from being deleted even if the user closes their browser window.

Functional cookies
These cookies collect information about user behavior and whether the user receives any error messages. In addition, these cookies are also used to measure the loading time and the behavior of the website in different browsers.

Target-oriented cookies
These cookies ensure better user-friendliness. For example, entered locations, font sizes or form data are stored.

Advertising cookies
These cookies are also called targeting cookies. They serve to deliver individually tailored advertising to the user. This can be very practical, but also very annoying.

Usually, when you visit a website for the first time, you are asked which of these types of cookies you would like to allow. And of course, this decision is also stored in a cookie.

If you would like to know more about cookies and are not afraid of technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Request for Comments of the Internet Engineering Task Force (IETF) called “HTTP State Management Mechanism”.

Purpose of processing via cookies

The purpose ultimately depends on the respective cookie. You can find more details about this below or from the manufacturer of the software that sets the cookie.

What data is processed?

Cookies are small helpers for many different tasks. Unfortunately, it is not possible to generalize which data is stored in cookies, but in the context of the following privacy policy we will inform you about the data processed or stored.

Storage period of cookies

The storage period depends on the respective cookie and is specified further below. Some cookies are deleted after less than an hour, while others can remain stored on a computer for several years.

You also have an influence on the storage period yourself. You can manually delete all cookies at any time via your browser (see also “Right to object” below). Furthermore, cookies based on consent are deleted at the latest after you withdraw your consent, while the lawfulness of storage until then remains unaffected.

Right to object – how can I delete cookies?

How and whether you want to use cookies is up to you. Regardless of which service or website the cookies come from, you always have the option to delete, disable or only partially allow cookies. For example, you can block third-party cookies but allow all other cookies.

If you want to find out which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find this in your browser settings:

Chrome: Delete, enable and manage cookies in Chrome

Safari: Manage cookies and website data with Safari

Firefox: Delete cookies to remove data that websites have placed on your computer

Internet Explorer: Delete and manage cookies

Microsoft Edge: Delete and manage cookies

If you generally do not want any cookies, you can configure your browser so that it always informs you when a cookie is to be set. This allows you to decide for each individual cookie whether to allow it or not. The procedure differs depending on the browser. It is best to search for the instructions on Google using the search term “delete cookies Chrome” or “disable cookies Chrome” in the case of a Chrome browser.

Legal basis

Since 2009 there have been so-called “cookie guidelines”. These state that the storage of cookies requires your Consent (Article 6(1)(a) GDPR) consent. However, there are still very different responses to these guidelines within the EU countries. In Austria, this directive was implemented in Section 96(3) of the Telecommunications Act (TKG). In Germany, the cookie guidelines were not implemented as national law. Instead, this directive was largely implemented in Section 15(3) of the Telemedia Act (TMG).

For strictly necessary cookies, even where no consent is given, there are legitimate interests (Article 6(1)(f) GDPR), which in most cases are of an economic nature. We would like to provide visitors to the website with a pleasant user experience, and certain cookies are often absolutely necessary for this.

Where cookies that are not strictly necessary are used, this only occurs with your consent. The legal basis in this respect is Art. 6(1)(a) GDPR.

In the following sections, you will be informed in more detail about the use of cookies, provided that the software used uses cookies.

Web Hosting Introduction

Web hosting summary

Data subjects: Website visitors
Purpose: professional hosting of the website and securing operations
Processed data: IP address, time of website visit, browser used and other data. You can find more details about this below or from the web hosting provider used in each case.
Storage period: depends on the respective provider, but generally 2 weeks
?? Legal bases: Art. 6(1)(f) GDPR (Legitimate interests)

What is web hosting?

When you visit websites today, certain information – including personal data – is automatically created and stored, including on this website. This data should be processed as sparingly as possible and only with justification. By website, we mean the entirety of all web pages on a domain, i.e. everything from the start page (homepage) to the very last subpage (like this one). By domain, we mean, for example, example.de or sampleexample.com.

If you want to view a website on a computer, tablet or smartphone, you use a program called a web browser. You probably know some web browsers by name: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. We call it browser or web browser for short.

To display the website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complicated and time-consuming task, which is why this is usually handled by professional providers. They offer web hosting and thereby ensure reliable and error-free storage of website data. Quite a lot of technical terms, but please stay with us, it gets even better!

When the browser on your computer (desktop, laptop, tablet or smartphone) establishes a connection and during data transfer to and from the web server, personal data may be processed. On the one hand, your computer stores data; on the other hand, the web server must also store data for a period of time in order to ensure proper operation.

A picture is worth a thousand words, so the following graphic illustrates the interaction between the browser, the Internet and the hosting provider.

Browser and web server

Why do we process personal data?

The purposes of data processing are:

  1. Professional hosting of the website and securing operations
  2. to maintain operational and IT security
  3. Anonymous evaluation of access behavior to improve our offering and, where applicable, for criminal prosecution or the pursuit of claims

What data is processed?

Even while you are visiting our website right now, our web server, which is the computer on which this web page is stored, generally automatically stores data such as

  • the complete Internet address (URL) of the accessed web page
  • browser and browser version (e.g. Chrome 87)
  • the operating system used (e.g. Windows 10)
  • the address (URL) of the previously visited page (referrer URL) (e.g. https://www.beispielquellsite.de/vondabinichgekommen/)
  • the host name and IP address of the device from which access is made (e.g. COMPUTERNAME and 194.23.43.121)
  • date and time
  • in files known as web server log files

How long is data stored?

As a rule, the data mentioned above is stored for two weeks and then automatically deleted. We do not pass this data on, but we cannot rule out that this data may be viewed by authorities in the event of unlawful behavior.

In short: Your visit is logged by our provider (the company that runs our website on special computers (servers)), but we do not pass on your data without consent!

Legal basis

The lawfulness of the processing of personal data in the context of web hosting arises from Art. 6(1)(f) GDPR (safeguarding legitimate interests), because the use of professional hosting with a provider is necessary in order to present the company securely and user-friendly on the Internet and to be able to pursue attacks and claims arising from this where appropriate.

As a rule, there is a contract for order processing between us and the hosting provider pursuant to Art. 28 et seq. GDPR, which ensures compliance with data protection and guarantees data security.

World4You Privacy Policy

We use World4You for our website, among other things a web hosting provider. The service provider is the Austrian company World4You Internet Services GmbH, Hafenstraße 35, 4020 Linz, Austria.

You can learn more about the data processed through the use of World4You in the privacy policy at https://www.world4you.com/de/unternehmen/datenschutzerklaerung.html.

Data Processing Agreement (DPA) World4You

Within the meaning of Article 28 of the General Data Protection Regulation (GDPR), we have concluded a data processing agreement (DPA) with World4You (World4You Internet Services GmbH, Hafenstraße 35, 4020 Linz, Austria). You can read about exactly what a DPA is and, above all, what must be included in a DPA in our general section “Data Processing Agreement (DPA)”.

This contract is required by law because World4You processes personal data on our behalf. It clarifies that World4You may process data it receives from us only according to our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) at https://www.world4you.com/faq/de/dsgvo/faq.stellt-world4you-eine-vereinbarung-zur-auftragsverarbeitung-zur-verfuegung.html.

Web Design Introduction

Web design privacy policy summary

Data subjects: Website visitors
Purpose: improving the user experience
Processed data: Which data is processed depends heavily on the services used. Usually this involves, for example, IP address, technical data, language settings,  browser version, screen resolution and name of the browser. You can find more details about this in the web design tools used in each case.
Storage period: depends on the tools used
?? Legal bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate interests)

What is web design?

We use various tools on our website that serve our web design. Web design is not, as is often assumed, only about making our website look attractive, but also about functionality and performance. But of course, the right visual appearance of a website is also one of the major goals of professional web design. Web design is a sub-area of media design and deals with both the visual as well as the structural and functional design of a website. The aim is to use web design to improve your experience on our website. In web design jargon, this is referred to as user experience (UX) and usability. User experience means all the impressions and experiences that the website visitor has on a website. One aspect of user experience is usability. This is about the user-friendliness of a website. Particular emphasis is placed here on ensuring that content, subpages or products are clearly structured and that you can easily and quickly find what you are looking for. In order to offer you the best possible experience on our website, we also use so-called web design tools from third-party providers. In this privacy policy, the “web design” category therefore includes all services that improve the design of our website. These may include, for example, fonts, various plugins or other integrated web design functions.

Why do we use web design tools?

How you absorb information on a website depends very heavily on the structure, functionality and visual perception of the website. Therefore, good and professional web design has become increasingly important for us as well. We are constantly working to improve our website and see this as an extended service for you as a website visitor. Furthermore, a beautiful and functioning website also has economic advantages for us. After all, you will only visit us and make use of our offers if you feel completely comfortable.

What data is stored by web design tools?

When you visit our website, web design elements may be integrated into our pages that can also process data. Exactly which data is involved naturally depends heavily on the tools used. Further below you can see exactly which tools we use for our website. For more detailed information about data processing, we recommend that you also read the respective privacy policy of the tools used. In most cases, you will find out there which data is processed, whether cookies are used and how long the data is stored. Fonts such as Google Fonts, for example, also automatically transmit information such as language settings, IP address, browser version, browser screen resolution and browser name to Google servers.

Duration of data processing

How long data is processed is very individual and depends on the web design elements used. If cookies are used, for example, the retention period may be only one minute, but also a few years. Please inform yourself about this. For this, we recommend our general text section on cookies as well as the privacy policies of the tools used. There you will usually find out exactly which cookies are used and what information is stored in them. Google font files, for example, are stored for one year. This is intended to improve the loading time of a website. In principle, data is only ever stored for as long as is necessary to provide the service. In the case of legal requirements, data may also be stored for longer.

Right to object

You also have the right and the option at any time to withdraw your consent to the use of cookies or third-party providers. This works either via our cookie management tool or via other opt-out functions. You can also prevent data collection by cookies by managing, disabling or deleting cookies in your browser. Among web design elements (mostly fonts), however, there is also data that cannot be deleted quite so easily. This is the case when data is automatically collected directly when a page is accessed and transmitted to a third-party provider (such as Google). In that case, please contact the support of the respective provider. In the case of Google, you can reach support at https://support.google.com/?hl=de.

Legal basis

If you have consented to the use of web design tools, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) GDPR (Consent), this consent constitutes the legal basis for the processing of personal data as may occur when data is collected by web design tools. We also have a legitimate interest in improving the web design on our website. After all, only then can we provide you with an attractive and professional online offering. The corresponding legal basis for this is Art. 6(1)(f) GDPR (Legitimate interests). Nevertheless, we use web design tools only if you have given your consent. We definitely want to emphasize this again here.

Information on special web design tools – if available – can be found in the following sections.

Google Fonts Privacy Policy

Google Fonts privacy policy summary

Data subjects: Website visitors
Purpose: optimization of our service
Processed data: data such as IP address and CSS and font requests
You can find more details about this further below in this privacy policy.
Storage period: font files are stored by Google for one year
?? Legal bases: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate interests)

What are Google Fonts?

We use Google Fonts on our website. These are the “Google fonts” of the company Google Inc. For the European area, the company Google Ireland Limited (Gordon House, Barrow Street Dublin 4, Ireland) is responsible for all Google services.

You do not need to register or provide a password to use Google fonts. Furthermore, no cookies are stored in your browser. The files (CSS, fonts/typefaces) are requested via the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, requests for CSS and fonts are completely separate from all other Google services. If you have a Google account, you do not need to worry that your Google account data will be transmitted to Google while using Google Fonts. Google records the use of CSS (Cascading Style Sheets) and the fonts used and stores this data securely. We will look in detail at exactly what the data storage looks like.

Google Fonts (formerly Google Web Fonts) is a directory of more than 800 fonts that Google makes available to its users free of charge.

Many of these fonts are published under the SIL Open Font License, while others have been published under the Apache License. Both are free software licenses.

Why do we use Google Fonts on our website?

With Google Fonts, we can use fonts on our own website without having to upload them to our own server. Google Fonts is an important building block for keeping the quality of our website high. All Google fonts are automatically optimized for the web, which saves data volume and is a major advantage especially for use on mobile devices. When you visit our site, the small file size ensures a fast loading time. Furthermore, Google Fonts are secure web fonts. Different image synthesis systems (rendering) in different browsers, operating systems and mobile devices can lead to errors. Such errors can sometimes visually distort text or entire web pages. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform problems with Google Fonts. Google Fonts supports all common browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). We therefore use Google Fonts so that we can present our entire online service as beautifully and uniformly as possible.

What data is stored by Google?

When you visit our website, the fonts are loaded via a Google server. Through this external call, data is transmitted to Google servers. In this way, Google also recognizes that you or your IP address have visited our website. The Google Fonts API was developed to reduce the use, storage and collection of end-user data to what is necessary for the proper provision of fonts. Incidentally, API stands for “Application Programming Interface” and serves, among other things, as a data transmitter in the software sector.

Google Fonts stores CSS and font requests securely at Google and is therefore protected. Through the collected usage figures, Google can determine how well the individual fonts are received. Google publishes the results on internal analysis pages, such as Google Analytics. In addition, Google also uses data from its own web crawler to determine which websites use Google fonts. This data is published in the BigQuery database of Google Fonts. Businesses and developers use the Google web service BigQuery to examine and move large amounts of data.

However, it should also be borne in mind that with every Google Font request, information such as language settings, IP address, browser version, browser screen resolution and browser name is automatically transmitted to Google servers. Whether this data is also stored cannot be clearly determined or is not clearly communicated by Google.

How long and where is the data stored?

Google stores requests for CSS assets for one day on its servers, which are mainly located outside the EU. This enables us to use the fonts with the help of a Google stylesheet. A stylesheet is a style template that can be used to easily and quickly change, for example, the design or font of a website.

The font files are stored by Google for one year. Google’s aim with this is to fundamentally improve the loading time of websites. When millions of websites refer to the same fonts, they are cached after the first visit and immediately appear again on all other websites visited later. Sometimes Google updates font files to reduce file size, increase language coverage and improve design.

How can I delete my data or prevent data storage?

The data that Google stores for one day or one year cannot simply be deleted. The data is automatically transmitted to Google when the page is accessed. In order to delete this data early, you must contact Google support at https://support.google.com/?hl=de&tid=111824141 In this case, you can prevent data storage only if you do not visit our site.

Unlike other web fonts, Google allows us unrestricted access to all fonts. We can therefore access an unlimited sea of fonts and thus get the best out of our website. You can find more about Google Fonts and further questions at https://developers.google.com/fonts/faq?tid=111824141. Google does address data protection-related matters there, but really detailed information about data storage is not included. It is relatively difficult to obtain truly precise information from Google about stored data.

Legal basis

If you have consented to the use of Google Fonts, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) GDPR (Consent) this consent constitutes the legal basis for the processing of personal data as may occur when data is collected by Google Fonts.

We also have a legitimate interest in using Google Font in order to optimize our online service. The corresponding legal basis for this is Art. 6(1)(f) GDPR (Legitimate interests). Nevertheless, we use Google Font only if you have given your consent.

Google also processes data from you, among other places, in the USA. We point out that, according to the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfer to the USA. This may be associated with various risks for the lawfulness and security of data processing.

As the basis for data processing by recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, especially in the USA) or for data transfer there, Google uses so-called Standard Contractual Clauses (= Art. 46(2) and (3) GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through these clauses, Google undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses, among other places, here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which also correspond to the Standard Contractual Clauses for Google Fonts, can be found at https://business.safety.google/adsprocessorterms/.

You can also find out which data Google generally collects and what this data is used for at https://www.google.com/intl/de/policies/privacy/ read.

Explanation of Terms Used

We always strive to draft our privacy policy as clearly and understandably as possible. However, this is not always easy, especially with technical and legal topics. It often makes sense to use legal terms (such as personal data) or certain technical expressions (such as cookies, IP address). But we do not want to use these without explanation. Below you will now find an alphabetical list of important terms used, which we may not have addressed sufficiently in the previous privacy policy. If these terms have been taken from the GDPR and are definitions, we will also quote the GDPR texts here and, where appropriate, add our own explanations.

Supervisory authority

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:


“supervisory authority” an independent public authority which is established by a Member State pursuant to Article 51;

Explanation: “Supervisory authorities” are always state, independent institutions that also have authority to issue instructions in certain cases. They serve to carry out so-called state supervision and are located in ministries, special departments or other authorities. For data protection in Austria there is an Austrian Data Protection Authority, for Germany there is a separate data protection authority for each federal state.

Processor

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:


“processor” a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

Explanation: As a company and website owner, we are responsible for all data that we process from you. In addition to controllers, there may also be so-called processors. This includes any company or person that processes personal data on our behalf. Consequently, processors may include, in addition to service providers such as tax advisors, also hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.

Supervisory authority concerned

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:


“supervisory authority concerned” a supervisory authority which is concerned by the processing of personal data because

a)

the controller or processor is established on the territory of the Member State of that supervisory authority,

b)

data subjects residing in the Member State of that supervisory authority are substantially affected or likely to be substantially affected by the processing, or

c)

a complaint has been lodged with that supervisory authority;

Explanation: In Germany, each federal state has its own supervisory authority for data protection. So if your company headquarters (main establishment) is in Germany, your contact is generally the respective supervisory authority of the federal state. In Austria, there is only one supervisory authority for data protection.

Consent

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:


“consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

Explanation: As a rule, such consent on websites is given via a cookie consent tool. You are surely familiar with this. Whenever you visit a website for the first time, you are usually asked via a banner whether you agree or consent to data processing. Usually you can also make individual settings and thus decide for yourself which data processing you allow and which you do not. If you do not consent, no personal data from you may be processed. In principle, consent can of course also be given in writing, i.e. not via a tool.

Personal data

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:


“personal data”

any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

Explanation: Personal data is therefore all data that can identify you as a person. As a rule, this includes data such as:

  • Name
  • Address
  • Email address
  • Postal address
  • Telephone number
  • Date of birth
  • Identification numbers such as social security number, tax identification number, identity card number or student ID number
  • Bank data such as account number, credit information, account balances and much more

According to the European Court of Justice (ECJ), your IP address is also considered personal data. Based on your IP address, IT experts can determine at least the approximate location of your device and subsequently you as the connection holder. Therefore, storing an IP address also requires a legal basis within the meaning of the GDPR. There are also so-called “special categories” of personal data that are also particularly worthy of protection. These include:

  • racial and ethnic origin
  • political opinions
  • religious or philosophical beliefs
  • trade union membership
  • genetic data such as data obtained from blood or saliva samples
  • biometric data (this is information about mental, physical or behavioral characteristics that can identify a person).
    Health data
  • Data concerning sexual orientation or sex life

Profiling

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:


“profiling” any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements;

Explanation: In profiling, various pieces of information about a person are compiled in order to learn more about that person. In the web area, profiling is often used for advertising purposes or also for credit checks. Web or advertising analysis programs, for example, collect data about your behavior and your interests on a website. This results in a special user profile, with the help of which advertising can be targeted to a specific target group.

Controller

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:


“controller” the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union law or Member State law, the controller or the specific criteria for its nomination may be provided for by Union law or Member State law;

Explanation: In our case, we are responsible for the processing of your personal data and are therefore the “controller”. If we pass collected data on to other service providers for processing, they are “processors”. For this, a “Data Processing Agreement (DPA)” must be signed.

Processing

Definition according to Article 4 of the GDPR

For the purposes of this Regulation, the term means:


“processing”

any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

Note: When we speak of processing in our privacy policy, we mean any type of data processing. As mentioned above in the original GDPR statement, this includes not only collection but also the storage and processing of data.

Closing Remarks

Congratulations! If you are reading these lines, you have truly “fought” your way through our entire privacy policy or at least scrolled this far. As you can see from the scope of our privacy policy, we take the protection of your personal data anything but lightly.
It is important to us to inform you about the processing of personal data to the best of our knowledge and belief. In doing so, however, we do not only want to tell you which data is processed, but also explain the reasons for using various software programs. As a rule, privacy policies sound very technical and legalistic. Since most of you, however, are not web developers or lawyers, we also wanted to take a different approach linguistically and explain the matter in simple and clear language. Of course, this is not always possible due to the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions about data protection on our website, please do not hesitate to contact us or the responsible office. We wish you a pleasant time and hope to welcome you back to our website soon.

All texts are protected by copyright.

Source: Created with the Privacy Policy Generator by AdSimple