Informativa sulla privacy
Siamo lieti del vostro interesse per la nostra organizzazione. La protezione dei vostri Dati Personali è particolarmente importante per la nostra direzione. Di norma, potete utilizzare i nostri siti web senza rivelarci alcun Dato Personale. Tuttavia, se desiderate usufruire di servizi più specifici tramite i nostri siti web, inclusi gli altri nostri siti web, applicazioni e pagine di social media, potremmo dover trattare i vostri Dati Personali. Se desideriamo trattare dati che vi riguardano e non possiamo fare affidamento su nessun'altra base giuridica, vi chiederemo sempre prima il vostro Consenso (ad esempio, tramite un banner per i cookie).
Rispettiamo sempre le leggi applicabili sulla protezione dei dati quando trattiamo i vostri Dati Personali (come nome, indirizzo, e-mail o numero di telefono). Con la presente Informativa sulla privacy, vi informiamo su quali dati trattiamo. Questa Informativa sulla privacy vi spiega anche quali diritti avete in qualità di Interessati.
Abbiamo adottato diverse misure tecniche e organizzative per proteggere al meglio i vostri dati sui nostri siti web. C'è tuttavia sempre il rischio di minacce su Internet e non è possibile garantire una protezione completa. Per questo motivo, se preferite, potete trasmetterci i vostri Dati Personali anche in altro modo, ad esempio per telefono.
La presente Informativa sulla privacy non è intesa unicamente a soddisfare gli obblighi previsti dal GDPR e a conformarsi alla legislazione degli Stati membri dell'Unione Europea (UE) e dello Spazio Economico Europeo (SEE). La presente Informativa sulla privacy è altresì intesa a conformarsi a normative quali le leggi sulla protezione dei dati del Regno Unito (UK-GDPR), la Legge federale svizzera sulla protezione dei dati e la Ordinanza svizzera sulla protezione dei dati (LPD, OPD), il California Consumer Privacy Act (CCPA/CPRA), la Legge sulla protezione delle informazioni personali della Cina (PIPL), il Delaware Personal Data Privacy Act (DPDPA), il Tennessee Information Protection Act (TIPA), il Minnesota Consumer Data Privacy Act (MCDPA), l'Iowa Act Relating to Consumer Data Protection (ICDPA), il Maryland Online Data Privacy Act (MODPA), il Nebraska Data Privacy Act (NDPA), la legge sulla protezione dei dati dei consumatori del New Hampshire (SB255), la legge sulla protezione dei dati del New Jersey (SB332), il disegno di legge sulla privacy dei consumatori della Carolina del Sud (House Bill 4696) e altre normative globali sulla protezione dei dati, e deve essere interpretata di conseguenza. La seguente Informativa sulla privacy deve essere interpretata per ciascun paese, stato o stato federato in modo tale che i termini e le basi giuridiche utilizzati corrispondano ai termini e alle basi giuridiche utilizzati nel rispettivo stato o stato federato.
Per una migliore leggibilità, sui nostri siti web, nelle pubblicazioni, nella comunicazione e nella nostra Informativa sulla privacy si evita l'uso simultaneo delle forme linguistiche maschile, femminile, di genere diverso e di altre identità di genere (m/f/d/altro). Tutte le formulazioni utilizzate si applicano ugualmente a tutti i generi.
Se avete suggerimenti per migliorare i testi di questa Informativa sulla privacy o se desiderate assumere un Responsabile della protezione dei dati esterno, vi preghiamo di contattare l'autore del testo: Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E..
1. Definizioni
Nella nostra Informativa sulla privacy, utilizziamo termini speciali provenienti da varie leggi sulla protezione dei dati. Vogliamo che la nostra dichiarazione sia di facile comprensione e perciò spieghiamo questi termini in anticipo.
Le seguenti definizioni devono essere interpretate o ampliate, a seconda dei casi, in base alla giurisprudenza del Tribunale dell'Unione Europea (TUE), della Corte di Giustizia dell'Unione Europea (CGUE), del Tribunale Federale Svizzero (TFS), della Corte Suprema del Regno Unito (UKSC) o in base alle leggi nazionali sulla protezione dei dati o alla giurisprudenza nazionale di uno stato o stato federale, inclusa, a titolo esemplificativo ma non esaustivo, la California, compresa la giurisprudenza, anche di common law, qualora ciò sia necessario per l'applicazione della legge nei singoli casi.
Usiamo i seguenti termini, tra gli altri, nella presente Informativa sulla privacy:
a) Dati personali
Dati Personali indica qualsiasi informazione riguardante una persona fisica identificata o identificabile. Una persona fisica identificabile è colui che può essere identificato, direttamente o indirettamente, in particolare mediante riferimento a un identificativo come il nome, un numero di identificazione, dati relativi all'ubicazione, un identificativo online o a uno o più elementi specifici dell'identità fisica, fisiologica, genetica, psichica, economica, culturale o sociale di tale persona fisica, o che deve essere considerato tale ai sensi della legislazione nazionale sulla protezione dei dati o della giurisdizione nazionale di uno stato o stato federale, anche ai sensi della common law.
b) Interessato
Interessato è qualsiasi persona fisica identificata o identificabile i cui Dati Personali sono trattati dal Titolare del trattamento, da un Responsabile del trattamento, da un'organizzazione internazionale o da un altro destinatario dei dati, nonché le persone che devono essere considerate tali ai sensi delle leggi nazionali sulla protezione dei dati o della giurisdizione nazionale di uno Stato o di uno Stato federale, compresa la giurisprudenza, anche ai sensi della common law.
c) Elaborazione
Il trattamento è qualsiasi operazione o insieme di operazioni, compiute con o senza l'ausilio di processi automatizzati e applicate a dati personali o insiemi di dati personali, come la raccolta, la registrazione, l'organizzazione, la strutturazione, la conservazione, l'adattamento o la modifica, l'estrazione, la consultazione, l'uso, la comunicazione mediante trasmissione, diffusione o qualsiasi altra forma di messa a disposizione, il raffronto o l'interconnessione, la limitazione, la cancellazione o la distruzione.
d) Limitazione del trattamento
La limitazione di trattamento è la marcatura dei Dati Personali conservati con l'obiettivo di limitarne il trattamento in futuro.
e) Profilazione
La profilazione è qualsiasi forma di trattamento automatizzato di dati personali consistente nell'utilizzo di tali dati per valutare determinati aspetti personali relativi a una persona fisica, in particolare per analizzare o prevedere aspetti riguardanti il rendimento professionale, la situazione economica, la salute, le preferenze personali, gli interessi, l'affidabilità, il comportamento, l'ubicazione o gli spostamenti di detta persona fisica.
f) Pseudonimizzazione
La pseudonimizzazione è il trattamento dei dati personali in modo tale che i dati personali non possano più essere attribuiti a un interessato specifico senza l'utilizzo di informazioni aggiuntive, a condizione che tali informazioni aggiuntive siano conservate separatamente e soggette a misure tecniche e organizzative intese a garantire che i dati personali non siano attribuiti a una persona fisica identificata o identificabile.
g) Titolare del trattamento
Il Titolare del trattamento è la persona fisica o giuridica, l'autorità pubblica, il servizio o altro organismo che, singolarmente o insieme ad altri, determina le finalità e i mezzi del trattamento di dati personali. Quando le finalità e i mezzi di tale trattamento sono determinati dal diritto dell'Unione o degli Stati membri, il titolare del trattamento o i criteri specifici applicabili alla sua designazione possono essere stabiliti dal diritto dell'Unione o degli Stati membri.
h) Processore
Un Responsabile del trattamento è una persona fisica o giuridica, un'autorità pubblica, un servizio o un altro organismo che tratta Dati Personali per conto del Titolare del trattamento.
i) Destinatario
Un Destinatario è una persona fisica o giuridica, un'autorità pubblica, un servizio o un altro organismo che riceve Dati Personali, che si tratti o meno di un Terzo. Tuttavia, le autorità pubbliche che possono ricevere Dati Personali nell'ambito di una particolare indagine conformemente al diritto dell'Unione o degli Stati membri non sono considerate destinatarie.
j) Terze parti
Un Terzo è una persona fisica o giuridica, autorità pubblica, servizio o altro organismo che non sia l'Interessato, il Titolare del trattamento, il Responsabile del trattamento e le persone autorizzate al trattamento dei Dati Personali sotto l'autorità diretta del Titolare o del Responsabile.
k) Consenso
Il consenso è qualsiasi manifestazione di volontà libera, specifica, informata e inequivocabile dell'interessato, con la quale lo stesso manifesta il proprio assenso, mediante dichiarazione o mediante un'azione positiva inequivocabile, che i dati personali che lo riguardano siano oggetto di trattamento.
2. Nome e indirizzo del Titolare
Il Titolare del trattamento ai sensi del Regolamento generale sulla protezione dei dati, di altre leggi sulla protezione dei dati applicabili negli Stati membri dell'Unione Europea e dello Spazio Economico Europeo, delle leggi britanniche sulla protezione dei dati, delle leggi svizzere sulla protezione dei dati (DSG, DSV), della legge sulla protezione dei dati della California (CCPA/CPRA), della legge sulla protezione dei dati della Cina (PIPL), nonché di leggi e disposizioni internazionali aventi natura di protezione dei dati è:
BIM Agile UG
Höll 4
88364 Wolfegg
Tel.: +4917641599655
eMail: info@bim-agile.com
Sito web: www.bim-agile.de
3. Raccolta di dati e informazioni generali
I nostri siti web raccolgono una serie di dati e informazioni generali ogni volta che i siti web vengono visitati da un interessato o da un sistema automatizzato. Questi dati e informazioni generali vengono memorizzati nei file di log del rispettivo server. Possono essere registrati, tra l'altro, (1) i tipi e le versioni di browser utilizzati, (2) il sistema operativo utilizzato dal sistema di accesso, (3) il sito web dal quale un sistema di accesso accede ai nostri siti web (il cosiddetto referrer), (4) i sottositi web cui si accede tramite un sistema di accesso sui nostri siti web, (5) la data e l'ora dell'accesso al sito web, (6) un indirizzo di protocollo internet (indirizzo IP), (7) il provider di servizi internet del sistema di accesso e (8) altri dati e informazioni analoghi utilizzati a fini di sicurezza in caso di attacchi ai nostri sistemi informatici.
Quando si utilizzano questi dati e informazioni generali, in genere non traiamo conclusioni sull'Interessato. Piuttosto, queste informazioni sono necessarie per (1) consegnare correttamente il contenuto dei nostri siti web, (2) ottimizzare il contenuto dei nostri siti web e la relativa pubblicità, (3) garantire la funzionalità a lungo termine dei nostri sistemi informatici e della tecnologia dei nostri siti web e (4) fornire alle autorità di polizia le informazioni necessarie per il perseguimento penale in caso di attacco informatico. Questi dati e informazioni raccolti in forma anonima vengono pertanto valutati da noi sia statisticamente che allo scopo di aumentare la protezione dei dati e la sicurezza dei dati nella nostra organizzazione, per garantire infine un livello ottimale di protezione dei Dati Personali da noi trattati. I dati dei file di log del server vengono memorizzati separatamente da tutti i Dati Personali forniti da un Interessato.
Lo scopo del trattamento è la prevenzione di pericoli e la garanzia della sicurezza IT, nonché le finalità summenzionate. La base giuridica è l'art. 6, par. 1, lett. f) del GDPR. Il nostro legittimo interesse è la protezione dei nostri sistemi di tecnologia dell'informazione. I file di log vengono cancellati dopo il raggiungimento delle finalità indicate.
4. Possibilità di contatto tramite il sito web e altri trasferimenti di dati e il vostro consenso
Il nostro sito web contiene informazioni che consentono un rapido contatto elettronico con la nostra organizzazione, nonché una comunicazione diretta con noi, che include anche un indirizzo generale della cosiddetta posta elettronica (indirizzo email) ed eventualmente un numero di telefono. Se un Interessato ci contatta tramite email, tramite un modulo di contatto, tramite un modulo di inserimento o in qualsiasi altro modo, i Dati Personali trasmessi dall'Interessato saranno memorizzati automaticamente. Tali Dati Personali a noi trasmessi su base volontaria da un Interessato vengono elaborati allo scopo di utilizzo o di contatto con l'Interessato.
Otteniamo il vostro consenso per la trasmissione, la conservazione e il trattamento dei vostri dati di contatto e delle vostre richieste e per contattarvi in conformità all'art. 6, par. 1, lett. a) del GDPR e all'art. 49, par. 1, co. 1, lett. a) del GDPR come segue:
Mediante la trasmissione dei Suoi Dati Personali, Lei acconsente volontariamente al Trattamento dei Dati Personali da Lei inseriti o trasmessi ai fini dell'elaborazione della richiesta e del contatto. Trasmettendoci i Suoi dati, Lei fornisce inoltre volontariamente il Suo Consenso esplicito ai sensi dell'art. 49, paragrafo 1, comma 1, lettera a) del GDPR al trasferimento di dati verso paesi terzi alle e da parte delle società indicate nella presente Informativa sulla privacy e per le finalità dichiarate, in particolare per tali trasferimenti verso paesi terzi per i quali esiste o meno una decisione di adeguatezza dell'UE/SEE e verso società o altri enti che non sono soggetti a una decisione di adeguatezza esistente sulla base di un'autocertificazione o di altri criteri di adesione e nei quali o per i quali sussistono rischi significativi e garanzie non adeguate per la protezione dei Suoi Dati Personali (ad esempio, a causa della Sezione 702 del FISA, dell'Ordine Esecutivo EO12333 e del Cloud Act negli Stati Uniti). Nel prestare il Suo Consenso volontario ed esplicito, Lei era consapevole che nei paesi terzi potrebbe non esserci un livello adeguato di protezione dei dati e che i Suoi diritti di interessato potrebbero non essere azionabili. Lei può revocare il Suo Consenso in materia di protezione dei dati in qualsiasi momento con effetto per il futuro. La revoca del Consenso non pregiudica la liceità del Trattamento basato sul Consenso prima della revoca stessa. Con una sola azione (inserimento e trasmissione), Lei fornisce diversi Consensi. Si tratta di Consensi ai sensi della normativa sulla protezione dei dati dell'UE/SEE, nonché ai sensi del CCPA/CPRA, della normativa ePrivacy e sui telemedia e di altre legislazioni internazionali, che sono richiesti, tra l'altro, come base giuridica per qualsiasi ulteriore Trattamento previsto dei Suoi Dati Personali. Con la Sua azione, Lei conferma altresì di aver letto e preso atto della presente Informativa sulla privacy.
5. Cancellazione e limitazione di routine dei Dati Personali
Trattiamo e conserviamo i Dati Personali per il periodo necessario a conseguire lo scopo del trattamento o se ciò è previsto dal legislatore europeo o da un altro legislatore in leggi o regolamenti cui siamo soggetti, o se esiste una base giuridica per il Trattamento.
Se lo scopo del trattamento non è più applicabile o se scade un periodo di conservazione prescritto dal legislatore europeo o da un altro legislatore competente, o se la base giuridica del trattamento non è più applicabile, i Dati Personali saranno regolarmente limitati o cancellati in conformità con le disposizioni di legge.
6. Diritti dell'Interessato ai sensi del GDPR
a) Diritto di conferma
Ciascun Interessato ha il diritto di ottenere dal Titolare del trattamento la conferma che sia o meno in corso un trattamento di Dati Personali che lo riguardano.
Se un Interessato desidera esercitare questo diritto, può contattarci in qualsiasi momento.
b) Diritto all'informazione
Ciascun Interessato ha il diritto di ottenere in qualsiasi momento dal Titolare del trattamento informazioni gratuite sui Dati Personali che lo riguardano e una copia di tali dati. Inoltre, il legislatore europeo ha riconosciuto all'Interessato l'accesso alle seguenti informazioni:
• le finalità del trattamento,
• le categorie di Dati Personali che vengono trattate,
i destinatari o le categorie di destinatari a cui i Dati Personali sono stati o saranno comunicati, in particolare se destinatari di paesi terzi o organizzazioni internazionali,
• ove possibile, il periodo di conservazione dei Dati Personali previsto oppure, se non è possibile, i criteri utilizzati per determinare tale periodo,
• l'esistenza del diritto di richiedere al Titolare del trattamento la rettifica o la cancellazione dei Dati Personali o la limitazione del trattamento dei Dati Personali che lo riguardano o di opporsi a tale trattamento,
• l'esistenza del diritto di proporre reclamo a un'autorità di controllo,
• se i Dati Personali non sono raccolti presso l'Interessato: Tutte le informazioni disponibili sull'origine dei dati,
• l'esistenza di processi decisionali automatizzati, compresa la profilazione di cui all'articolo 22, paragrafi 1 e 4, del GDPR e, almeno in tali casi, informazioni significative sulla logica utilizzata, nonché l'importanza e le conseguenze previste di tale trattamento per l'interessato.
Inoltre, l'Interessato ha il diritto di essere informato sull'eventuale trasferimento di Dati Personali verso un paese terzo o un'organizzazione internazionale. In tal caso, l'Interessato ha altresì il diritto di ottenere informazioni in merito alle adeguate garanzie connesse al trasferimento.
Se un Interessato desidera esercitare questo diritto, può contattarci in qualsiasi momento.
c) Diritto di rettifica
Ogni interessato ha il diritto di richiedere l'immediata rettifica dei dati personali inesatti che lo riguardano. Inoltre, l'interessato ha il diritto di richiedere il completamento dei dati personali incompleti, anche mediante una dichiarazione integrativa, tenendo conto delle finalità del trattamento.
Se un Interessato desidera esercitare questo diritto, può contattarci in qualsiasi momento.
d) Diritto alla cancellazione (diritto all'oblio)
Ciascun Interessato ha il diritto di ottenere dal Titolare la cancellazione dei Dati Personali che lo riguardano senza ingiustificato ritardo e il Titolare ha l'obbligo di cancellare i Dati Personali senza ingiustificato ritardo se sussiste uno dei seguenti motivi, a condizione che il Trattamento non sia necessario:
• I dati personali sono stati raccolti o altrimenti trattati per finalità per le quali non sono più necessari.
• L'Interessato revoca il Consenso su cui si basa il Trattamento ai sensi dell'art. 6, par. 1, lett. a) del GDPR, o dell'art. 9, par. 2, lett. a) del GDPR, e se non sussiste altro fondamento giuridico per il Trattamento.
• L'Interessato si oppone al Trattamento ai sensi dell'art. 21, par. 1, GDPR e non sussistono motivi legittimi prevalenti per procedere al Trattamento, oppure l'Interessato si oppone al Trattamento ai sensi dell'art. 21, par. 2, GDPR.
• I dati personali sono stati trattati illecitamente.
• La cancellazione dei dati personali è necessaria per adempiere a un obbligo legale previsto dal diritto dell’Unione o dalla normativa degli Stati membri a cui è soggetto il titolare del trattamento.
• I dati personali sono stati raccolti nell'ambito dei servizi della società dell'informazione offerti ai sensi dell'articolo 8, paragrafo 1, del GDPR.
Se sussiste uno dei motivi sopra indicati e un interessato desidera richiedere la cancellazione dei dati personali da noi conservati, può contattarci in qualsiasi momento.
Qualora abbiamo reso pubblici i Dati Personali e la nostra organizzazione sia tenuta a cancellarli ai sensi dell’art. 17 (1) del GDPR, adotteremo misure adeguate, ivi comprese misure tecniche, tenendo conto della tecnologia disponibile e dei costi di attuazione, per informare gli altri Titolari del trattamento che trattano i Dati Personali pubblicati che l’Interessato ha richiesto la cancellazione di tutti i link a tali Dati Personali o delle copie o repliche di tali Dati Personali da parte di tali altri Titolari del trattamento, nella misura in cui il trattamento non sia necessario.
e) Diritto di limitazione di trattamento
Ciascun Interessato ha il diritto di ottenere dal Titolare la limitazione del trattamento quando ricorre una delle seguenti ipotesi:
• L’esattezza dei dati personali è contestata dall’interessato, per un periodo che consenta al titolare del trattamento di verificarne l’esattezza.
• Il trattamento è illecito e l'Interessato si oppone alla cancellazione dei Dati Personali e chiede invece la limitazione del loro utilizzo.
• Il Titolare non ha più bisogno dei Dati Personali per le finalità del Trattamento, ma essi sono necessari all'Interessato per l'accertamento, l'esercizio o la difesa di un diritto in sede giudiziaria.
• L'Interessato si è opposto al Trattamento ai sensi dell'art. 21, par. 1, GDPR in attesa della verifica in merito all'eventuale prevalenza dei motivi legittimi del Titolare del trattamento rispetto a quelli dell'Interessato.
Se una delle condizioni di cui sopra viene soddisfatta e un Interessato desidera richiedere la limitazione del Trattamento dei Dati Personali da noi conservati, può contattarci in qualsiasi momento.
f) Diritto alla portabilità dei dati
Ogni interessato ha il diritto di ricevere i dati personali che lo riguardano, da lui forniti a un titolare del trattamento, in un formato strutturato, di uso comune e leggibile da dispositivo automatico. Ha inoltre il diritto di trasmettere tali dati a un altro Titolare del trattamento senza ostacoli da parte del Titolare del trattamento al quale i Dati Personali sono stati forniti, qualora il trattamento sia basato sul consenso ai sensi dell’art. 6, comma 1, lettera a) del GDPR o dell’art. 9, comma 2, lettera a) del GDPR o su un contratto ai sensi dell’art. 6, comma 1, lettera b) del GDPR e il trattamento sia effettuato con mezzi automatizzati, a meno che il trattamento non sia necessario per l’esecuzione di un compito di interesse pubblico o connesso all’esercizio di pubblici poteri di cui è investito il Titolare del trattamento.
Inoltre, nell'esercitare il proprio diritto alla portabilità dei dati ai sensi dell'art. 20, par. 1, del GDPR, l'Interessato ha il diritto di ottenere che i Dati Personali siano trasmessi direttamente da un Titolare del trattamento a un altro, ove tecnicamente fattibile e a condizione che ciò non pregiudichi i diritti e le libertà altrui.
Se un Interessato desidera esercitare questo diritto, può contattarci in qualsiasi momento.
g) Diritto di opposizione
Ciascun Interessato ha il diritto di opporsi in qualsiasi momento, per motivi connessi alla sua situazione particolare, al Trattamento dei Dati Personali che lo riguardano basato sulle lettere e) o f) dell'articolo 6, paragrafo 1, del GDPR. Ciò vale anche per la Profilazione basata su tali disposizioni.
In caso di opposizione, non tratteremo più i Dati Personali, a meno che non possiamo dimostrare l'esistenza di motivi legittimi cogenti per il Trattamento che prevalgono sugli interessi, sui diritti e sulle libertà dell'Interessato oppure per l'accertamento, l'esercizio o la difesa di un diritto in sede giudiziaria.
Qualora trattassimo i Dati Personali per finalità di marketing diretto, l’Interessato avrà il diritto di opporsi in qualsiasi momento al trattamento dei Dati Personali che lo riguardano per tali finalità di marketing. Ciò vale anche per la profilazione, nella misura in cui sia associata a tale pubblicità diretta. Qualora l’interessato si opponga al trattamento per finalità di marketing diretto, non tratteremo più i dati personali per tali finalità.
Inoltre, l’interessato ha il diritto, per motivi connessi alla sua situazione particolare, di opporsi al trattamento dei dati personali che lo riguardano da parte nostra a fini di ricerca scientifica o storica, o a fini statistici ai sensi dell’articolo 89, paragrafo 1, del GDPR, a meno che il trattamento non sia necessario per l’esecuzione di un compito di interesse pubblico.
Se un Interessato desidera esercitare questo diritto, può contattarci in qualsiasi momento. L'Interessato è inoltre libero, nel contesto dell'utilizzo di servizi della società dell'informazione e fatta salva la direttiva 2002/58/CE, di esercitare il proprio diritto di opposizione con mezzi automatizzati che utilizzano specifiche tecniche.
h) Decisioni automatizzate in singoli casi, compresa la profilazione
Ogni interessato ha il diritto di non essere sottoposto a una decisione basata esclusivamente sul trattamento automatizzato, compresa la profilazione, che produca effetti giuridici che lo riguardano o che incida in modo analogamente significativo sulla sua persona, a condizione che la decisione (1) non sia necessaria per la conclusione o l’esecuzione di un contratto tra l’interessato e il titolare del trattamento, oppure (2) sia autorizzata dal diritto dell’Unione o dello Stato membro a cui è soggetto il Titolare del trattamento e che preveda anche misure adeguate a salvaguardare i diritti, le libertà e gli interessi legittimi dell’interessato, oppure (3) sia basata sul consenso esplicito dell’interessato.
Se la decisione (1) è necessaria per la conclusione o l'esecuzione di un contratto tra l'Interessato e un Titolare del trattamento, oppure (2) si basa sul Consenso esplicito dell'Interessato, attueremo misure idonee a tutelare i diritti, le libertà e i legittimi interessi dell'Interessato, almeno il diritto di ottenere l'intervento umano da parte del Titolare del trattamento, di esprimere la propria opinione e di contestare la decisione.
Se un Interessato desidera esercitare questo diritto, può contattarci in qualsiasi momento.
i) Diritto di revocare il consenso ai sensi della normativa sulla protezione dei dati
Ciascun Interessato ha il diritto di revocare il Consenso al Trattamento dei Dati Personali in qualsiasi momento.
Se un Interessato desidera esercitare questo diritto, può contattarci in qualsiasi momento.
7. General purpose of Processing, categories of processed data and categories of recipients
The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.
The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.
A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.
8. Legal basis for the Processing
Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.
In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.
If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.
Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).
9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing
If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.
We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.
Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.
10. Duration for which the Personal Data is stored
The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.
11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision
We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.
12. Existence of automated decision-making
As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:
Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.
In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.
Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.
13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.
According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.
The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.
Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.
In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.
Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.
14. Right to lodge a complaint with a data protection supervisory authority
As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.
15. Data protection for applications and in the application process
We collect and process Personal Data of applicants in the application process. Processing may also take place electronically. This is particularly the case if an applicant submits relevant application documents to us electronically, for example by email or via a web form on our or third-party websites.
For applicant data, the purpose of data processing is to carry out a review of the application in the application process. For this purpose, we process all data provided by you. Based on the data submitted as part of the application, we check whether you will be invited to an interview (part of the selection process). Then, in the case of generally suitable applicants, in particular during the interview, we process certain other Personal Data provided by you that is essential for our selection decision.
The legal basis for data Processing is Art. 6 (1) (b) GDPR, Art. 9 (2) (b) and (h) GDPR, Art. 88 (1) GDPR and national legislation.
If we do not conclude an employment contract with the applicant, the application documents will be deleted no later than six months after notification of the rejection decision, provided that no other legitimate interests of the Controller stand in the way of deletion. Another legitimate interest in this sense is, for example, the provision of evidence in legal proceedings.
16. Registration or filling in input masks on our website and your Consent
You have the option of registering on our websites by providing Personal Data and/or filling out input masks. Which Personal Data is transmitted to us in the process is determined by the respective input mask used for registration or input. The Personal Data you enter will be processed exclusively for internal use by us and for our own purposes. However, we may pass on your Personal Data to one or more Processors, for example to parcel service providers, who also use your Personal Data exclusively for purposes that are attributable to us as the Controller. Disclosure may also take place if you have commissioned the disclosure from us. The legal basis is then Art. 6 (1) (b) GDPR.
When you register or enter data on our website, the IP address assigned by your internet service provider (ISP), the date and time of registration or entry may also be stored. This data is stored against the background that this is the only way to prevent misuse of our services and, if necessary, to make it possible to investigate criminal offenses. In this respect, the storage of this data is necessary for our security. The purpose of processing is the prevention and detection of misuse and the investigation of criminal offenses, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is in particular the protection of our information technology systems and the investigation of criminal offenses. This data is not disclosed to Third Parties unless there is a legal obligation to disclose it, or the disclosure serves the purpose of criminal prosecution.
The registration, entry and transmission of your Personal Data also enables us to offer you content or services which, due to the nature of the matter, can only be offered to registered persons or persons known to us. You are free to change the Personal Data provided during registration at any time or to have it completely deleted from our database. The purposes of processing are the receipt of data by us and the use of your data for further Processing, for communication with you and the illustration or implementation of the registration or input purposes. The legal basis is your Consent in accordance with Art. 6 (1) (a) GDPR and/or Art. 49 (1) (1) (a) GDPR.
By entering and transmitting your data, you voluntarily consent to the Processing of the Personal Data you have entered. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When giving your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.
Upon request, we will provide any Data Subject at any time with information about which Personal Data about the Data Subject is stored. We will also correct or delete Personal Data at the request or notice of the Data Subject, provided that this does not conflict with any statutory retention obligations or other reasons justifying Processing. All our employees are available to you as contact persons in this context.
17. Data protection provisions about the application and use of Complianz - GDPR/CCPA Cookie Consent
Complianz - GDPR/CCPA Cookie Consent is a WordPress plugin that supports compliance with data protection regulations (GDPR and CCPA) by providing a user-friendly solution for managing cookie Consents. This plugin helps website operators to obtain and document legally required Consents for data processing and cookie use from website visitors. It processes and stores information about users' Consent to cookies and their IP addresses.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Complianz - GDPR/CCPA Cookie consent is to comply with data protection laws through the use of cookie consent tools. Processing is based on Art. 6 (1) (c) GDPR, as the Processing is necessary for compliance with a legal obligation to which our organisation is subject.
The criteria for determining the duration for which the Personal Data is processed are the statutory or contractual retention periods. The use of Personal Data is required by law, as it is necessary to fulfill legal obligations in the area of data protection and Consent management. Users are required to indicate their cookie preferences or reject cookies, and this information must be stored to properly document the decision.
Further information about Complianz - GDPR/CCPA Cookie consent can be found at https://complianz.io/.
18. Data protection provisions for webinars and online meetings
We organize webinars and invite customers, interested parties, service providers and suppliers as well as their and our employees to online meetings. We use various third-party providers (operators of online meeting applications, application providers). You can understand which third-party provider we use for a specific webinar or online meeting from the participation link. You can find the privacy policy and other legally required information on the website of the respective third-party provider.
When using systems for webinars and online meetings, personal data such as names, e-mail addresses, telephone numbers, sound recordings, film recordings, photographs, usage data (e.g., time and duration of meetings, chat logs), content data (e.g., files, notes, messages) and location data may be processed. This information is necessary to provide the services, improve the user experience, provide support and ensure the security and compliance of the services.
Purposes for which the personal data are to be processed and the legal basis for the processing: The purpose of the processing is the use, provision and administration of systems for webinars and online meetings for communication. The processing is based on consent pursuant to Art. 6 (1) (a) GDPR, or explicit consent pursuant to Art. 49 (1) (1) (a) GDPR, the performance of a contract (Art. 6 (1) (b) GDPR) to which the data subject is party, and legitimate interests (Art. 6 (1) (f) GDPR), such as the improvement of our services and the use and provision of modern communication tools.
For the processing of your personal data, we obtain your consent in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:
By registering, logging in and/or participating in a webinar or online meeting, you expressly agree that your personal data may be processed for the purposes of registration, planning, organization and implementation of the webinar or online meeting, which includes transmission to a third-party provider (possibly located in a third country), and that sound recordings, film recordings or photographs may be transmitted to other participants and/or published as part of the webinar or online meeting. You grant multiple consents with a single action. By registering, logging in and/or participating, you also voluntarily give your explicit consent in accordance with Art. 49 (1) (1) (a) GDPR for data transfers to third countries for the purposes of registration, planning, organization and implementation of the webinar or online meeting, in particular for such transfers to third countries for which there is or is not an adequacy decision of the EU/EEA and to companies or other entities that are not subject to an existing adequacy decision due to self-certification or other accession criteria, and in or for which there are significant risks and no appropriate safeguards for the protection of your personal data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). We hereby inform you in advance of giving your voluntary and explicit consent that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable, and that published personal data may not be deleted, modified or anonymized at all, only to a limited extent and/or with a time delay. You give your consent voluntarily. You are not obliged to give your consent and may choose not to attend or participate in the webinar or online meeting, which will be regarded by us as a refusal of our request for consent. You can withdraw your consent under data protection law in whole or in part at any time with effect for the future, in particular by deactivating or switching off your audio transmissions, video transmissions or photo transmissions during the webinar or online meeting or by not activating them in the beginning. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. By your act, you also confirm that you have read and acknowledged this privacy policy.
The company operating the service may be located in a third country. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company operating the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company operating the service or statutory or contractual retention periods. The provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obliged to provide us or the company operating the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
19. Data protection provisions about the application and use of Calendly
Calendly offers a user-friendly online scheduling software that allows us to organize meetings and appointments efficiently. The platform helps us to synchronize the availability of all participants, send automatic reminders and integrate the planning of meetings directly into our calendars. Calendly significantly improves the coordination of internal and external meetings and helps to save time and increase productivity.
When using Calendly, Personal Data such as names, email addresses and calendar information are processed. This data enables us to automate appointment scheduling, send personalized invitations and maximize the efficiency of our appointment scheduling.
The company that operates the service and thus the recipient of personal data is: Calendly, Inc., 115 E Main St., Ste A1B, Buford, GA 30518, USA.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to optimize scheduling and improve organizational efficiency. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in simplifying and increasing the efficiency of planning processes for internal and external meetings.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Calendly, LLC, can be found at https://calendly.com.
20. Data protection provisions about the application and use of Google Chrome
We use Google Chrome web browser to use web-based applications, to display Internet content and to integrate browser-based business services. Google Chrome, which is provided by Google, offers numerous functions, including synchronization via Google accounts, integration with other Google services, automated form entries, voice control and the use of extensions and security technologies. When using Google Chrome, personal data may be processed, especially if the browser is linked to a Google account or users voluntarily activate synchronization services and extensions. The processed data includes IP addresses, search queries, browsing history, installed extensions, location data, language settings, and technical device information.
If the user is logged in with a Google account, Chrome activities such as the history of visited pages, bookmarks, passwords, and other browser settings can be synchronized across devices and stored on Google servers. In addition, Chrome collects diagnostic data and usage statistics to improve the stability, security, and performance of the browser, if this function is activated. Personal data is also processed locally or on the server when forms are automatically completed (e.g., addresses or credit card details). Chrome can also use third-party tools such as Safe Browsing or translation services, which also trigger data processing operations.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The processing serves the secure, stable and personalized use of the web browser, the synchronization of user preferences, the improvement of browser performance, the protection against harmful content and the integration with other Google services. Processing is carried out on the basis of Art. 6 (1) (b) GDPR, i.e., for the performance of a contract to which the data subject is party, and Art. 6 (1) (f) GDPR. The legitimate interest lies in the secure provision of Internet functions, technical stability, user-friendliness, and the integration of services to optimize online experience.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide personal data, you may not be able to use our services or those of the company that operates the service.
Further information and the applicable data protection provisions of Google Chrome can be retrieved at https://policies.google.com/privacy.
21. Data protection provisions about the application and use of Make.com
We use Make.com, in particular webhook mechanisms, to automate processes between applications and systems. This integration enables us to automatically send data to other services or trigger actions in the event of defined events (e.g., new orders, form submissions, ticket changes). Personal data may be transmitted and processed during use. The data processed includes names, email address, telephone number, order data, form entries, IP address, timestamp, device data, URL paths of events and metadata on actions.
Processing is automated via Make.com's cloud-based infrastructure. Triggers on our website or in our systems send JSON-based webhook messages to Make. Rules are executed there to forward, transform, or feed data into third-party applications such as CRM systems, ticketing systems, or databases.
The company that operates the service and therefore the recipient of the personal data is: Celonis, Inc., One World Trade Center, 87th Floor, New York, NY 10007, USA.
The company that operates the service is located in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
Purposes for which the personal data is to be processed and the legal basis for the processing: The purpose of the processing is the central and error-free automation of business processes by forwarding data, triggering follow-up activities, and integrating various IT systems via webhooks. The processing is carried out on the basis of Art. 6 (1) (b) GDPR, for the performance of a contract to which the data subject is party or in order to take steps prior to entering into a contract and on the basis of Art. 6 (1) (f) GDPR. The legitimate interest lies in the efficient, consistent, and secure integration of digital processes, the minimization of manual interfaces and the avoidance of errors and delays.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract or necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Make can be found at https://www.make.com/.
22. Data protection provisions about the application and use of Microsoft Dynamics 365
We use Microsoft Dynamics 365 to map and optimize business processes in the areas of customer management (CRM), sales, marketing, service, and finance. Dynamics 365 is a cloud-based enterprise solution that integrates various applications and provides them via a unified platform. When using Dynamics 365, we process personal data, in particular: first name and last name, email address, telephone number, professional contact details, customer numbers, communication content, contract data and offer data, interaction history, IP addresses, time stamps of system access, user IDs, device data, and browser information. Data processing is carried out for the purpose of organizing customer relationships, sales communication and support communication, preparing quotations and processing orders, documenting business transactions, and automating internal processes.
The company that operates the service and thus the recipient of the personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and the EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as the contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, United Kingdom. The representative pursuant to Art. 14 of the Federal Act on Data Protection (DSG) in Switzerland is: Microsoft Schweiz GmbH, Seestraße 356, 8038 Zurich, Switzerland.
The company that operates the service is located in a third country, namely the USA. Transfers to third countries may be based on the conclusion of standard contractual clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service is a certified member of the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework. Further information can be found at dataprivacyframework.gov/list. You can request a copy of the appropriate or adequate safeguards from us.
Purposes for which the personal data will be processed and the legal basis for the processing: The purpose of the processing is the digital management and analysis of customer data, sales data, marketing data, and business data, as well as the efficient organization of internal processes. The processing is carried out on the basis of Art. 6 (1) (b) GDPR for the performance of a contract to which the data subject is party or in order to take steps prior to entering into a contract, as well as on the basis of Art. 6 (1) (f) GDPR. The legitimate interest lies in improving customer relationships, automating work processes, ensuring the traceability of business interactions, and centralized data storage.
The criteria for determining the period for which personal data will be processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is neither required by law nor contractually required nor necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide this data, you may not be able to use our services or those of the company that operates the service.
Further information and the applicable privacy policy of Microsoft Dynamics 365 can be found at https://microsoft.com/.
23. Data protection provisions about the application and use of Microsoft Edge
We use the Microsoft Edge web browser. When using the browser, personal data may be processed by Microsoft, in particular when using functions such as synchronization with the Microsoft account, the use of extensions, search integration via Bing or the personalized display of content. When you visit a website, Microsoft Edge processes various technical information that is required to display content and interact with online services. This includes IP addresses, browser types and versions, language settings, operating systems used, device identifiers, location data, cookies, stored form data, and URLs visited.
Microsoft Edge can also be linked to other Microsoft services, e.g., for protection against malicious websites (SmartScreen), Microsoft 365 accounts or the synchronization of bookmarks and passwords. Personal data may be transmitted to Microsoft for identification, usage analysis, and security enhancement. Users can activate or deactivate these functions in the browser settings.
The company that operates the service and thus the recipient of personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Microsoft Schweiz GmbH, Seestrasse 356, 8038 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of processing is to provide a modern web browser with advanced features for display, interaction and security when using online content. The processing is carried out on the basis of Art. 6 (1) (f) GDPR. The legitimate interest lies in the secure, convenient, and feature-rich use of web services, the synchronization of cross-device settings and the improvement of browser performance and browser security.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide the company that operates the service with personal data. However, if you do not provide personal data, certain functions of the browser may not be fully usable.
Further information and the applicable data protection provisions of Microsoft may be retrieved under https://privacy.microsoft.com/.
24. Data protection provisions about the application and use of Google Meet
Google Meet is a video conferencing service developed by Google LLC that enables users to conduct video conferences and online meetings. As part of Google Workspace, Google Meet provides a secure and reliable platform for businesses, educational institutions and individuals to promote communication and collaboration. The service supports features such as screen sharing, real-time captioning and integration with Google Calendar to make it easier to plan and conduct virtual meetings.
When using Google Meet, Personal Data such as names, email addresses, video images and audio recordings, as well as meeting data (such as participant lists, date and time of the meeting) are processed. This information is necessary to provide the video conferencing service, improve the user experience and ensure the security of the meetings.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the video conferencing service. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the promotion of digital communication and collaboration.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Meet may be retrieved under https://policies.google.com/privacy.
25. Data protection provisions about the application and use of Microsoft Teams
Microsoft Teams is a communication and collaboration tool within the Microsoft 365 suite designed specifically for business use. It enables teams to work together effectively, no matter where they are, through features such as chat, video calls, meetings, file sharing and integration with other Microsoft products and services. Microsoft Teams promotes teamwork through digital spaces that enable seamless communication and collaboration, regardless of whether team members are in the same office or spread across various locations worldwide.
When using Microsoft Teams, Personal Data such as names, email addresses, telephone numbers, usage data (e.g., time and duration of meetings, chat logs), content data (e.g., files, notes, messages) and location data are processed. This information is necessary to provide the services, improve the user’s experience, provide support and ensure the security and compliance of the services.
The company that operates the service and thus the recipient of personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Microsoft Schweiz GmbH, Seestrasse 356, 8038 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use, provide, manage and improve Microsoft Teams for communication. Processing is based on the performance of a contract (Art. 6 (1) (b) GDPR) to which the Data Subject is party and on legitimate interests (Art. 6 (1) (f) GDPR), such as the improvement of our services and the use and provision of modern communication tools.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Microsoft Teams can be found at https://privacy.microsoft.com.
26. Data protection provisions about the application and use of WhatsApp
WhatsApp LLC offers a widely used instant messaging service that enables users to send and receive text messages, voice messages, images, videos and documents. Users can also make voice and video calls. WhatsApp is characterized by end-to-end encryption, which ensures the security and privacy of communication between users.
When using WhatsApp, Personal Data such as telephone numbers, profile names, profile pictures, online status information and location data are processed. In addition, information about interactions between users, such as messages and call data, is transmitted in encrypted form and can be used by WhatsApp to improve the service and ensure security.
The company that operates the service and thus the recipient of personal data is: WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, The representative under national law in the United Kingdom is: WhatsApp Ltd., 57 Garth Road, London, England, NW2 2NH, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing lies in the use of the messaging service and the associated functions. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of an efficient platform, the improvement of our services and ensuring the security of users and their data.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of WhatsApp can be found at https://www.whatsapp.com.
27. Data protection provisions about the application and use of Google Fonts
Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.
When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Fonts can be found at https://policies.google.com/privacy.
28. Data protection provisions about the application and use of Canva
Canva is an online design and publishing platform that provides us with a wide range of tools and resources for creating visual content. Canva allows us to create professional designs. The platform provides access to an extensive library of templates, images and design elements that support the creation of content for our projects and communication channels.
When using Canva, Personal Data such as names, email addresses, design preferences and usage data are processed. This information allows us to create individual accounts, save personalized designs and optimize experiences.
The company that operates the service and thus the recipient of personal data is: Canva Pty Ltd, 110 Kippax St, Surry Hills NSW 2010, Australia. For data subjects in the EU and EEA, European Data Protection Office (EDPO), Ground Floor, 71 Lower Baggot Street, Dublin, D02 P593, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: European Data Protection Office UK (EDPO UK), 8 Northumberland Avenue, London WC2N 5BY, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of a platform for the creation and management of design content. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the use of an efficient and user-friendly design tool for professional purposes.
The company that operates the service is based in a third country. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The company that operates the service is located in a third country. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. Canva Pty Ltd may have entered into one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and Canva's applicable data protection provisions can be found at https://www.canva.com.
29. Data protection provisions about the application and use of Figma
Figma is an innovative design and prototyping software that enables teams to collaborate and create, test and share designs in real time. As a browser-based platform, Figma offers a wide range of tools for UI/UX design, graphic design, and wireframing that make the design process more efficient and interactive. Figma is used by designers, developers and product teams in various industries to create digital products and services.
When using Figma, Personal Data such as names, email addresses, job titles and usage data are processed. This information is necessary to create and manage user accounts, provide and personalize the service, make support requests and offer users a collaborative design environment.
The company that operates the service and thus the recipient of personal data is: Figma, Inc., 760 Market St, Floor 10, San Francisco, CA 94102, USA. For data subjects in the EU and EEA, Figma GmbH, Kurfürstendamm 15, 10719 Berlin acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Figma UK Ltd., 9 Devonshire Square, London, EC2M 4YF, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the design tool. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience and providing an effective and collaborative design tool.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Figma may be retrieved under https://www.figma.com.
30. Data protection provisions about the application and use of Google Calendar
Google Calendar is a comprehensive online calendar service from Google LLC that allows users to plan appointments, organize events, set reminders and manage their schedule. The platform supports synchronization across different devices and offers features such as sharing calendars with others, inviting participants to events and integration with other Google services to improve productivity and organization in everyday and professional environments.
When using Google Calendar, Personal Data such as names, email addresses, calendar events, participant lists, and reminder details are processed. This information is necessary to provide the calendar service, to offer users a personalized experience and to facilitate communication and coordination between event participants.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the calendar service and scheduling. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party or for the initiation of a contract, and on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of scheduling and organization of appointments.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Calendar can be found at https://policies.google.com/privacy.
31. Data protection provisions about the application and use of Google Docs
Google Docs is part of Google Workspace, a comprehensive suite of cloud-based productivity tools that allow users to create, edit and collaborate on documents in real time. Google Docs offers features such as word Processing, spreadsheets, presentation creation and more, all within an online environment. It supports collaboration between users through commenting features, editing history and the ability to manage access rights.
When using Google Docs, Personal Data such as names, email addresses, document content and editing activities are processed. This information is necessary to provide the service, enables collaboration between users and offers a personalized user experience.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the document editing and collaboration service. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, where the legitimate interest is to promote productivity and collaboration and to provide an efficient and secure document management service.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Docs can be found at https://policies.google.com/privacy.
32. Data protection provisions about the application and use of Google Gmail
Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.
When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Gmail can be found at https://policies.google.com/privacy.
33. Data protection provisions about the application and use of Google Sheets
Google Sheets is an online spreadsheet program that is part of Google Workspace. It allows users to create, edit and collaborate on spreadsheets in real time, regardless of their location. Google Sheets supports a variety of features, including formulas, charts, tables and script automation with Google Apps Script to simplify complex data analysis tasks.
When using Google Sheets, Personal Data such as names, email addresses, content of the created or edited spreadsheets and user interactions within the spreadsheets are processed. This information is necessary to provide and use the service, to enable collaboration between users and to offer a personalized user experience.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the spreadsheet service. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, where the legitimate interest is to promote productivity and collaboration and to provide an efficient and user-friendly spreadsheet management service.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Sheets can be found at https://policies.google.com/privacy.
34. Data protection provisions about the application and use of Google Workspace
Google Workspace is a comprehensive suite of cloud-based productivity and collaboration tools. It includes a variety of applications such as Gmail, Google Docs, Google Sheets, Google Slides, Google Drive, Google Calendar and Google Meet that enable businesses, educational institutions and teams to collaborate, communicate and manage projects efficiently. Google Workspace provides seamless integration between its numerous services to create a productive work environment that is accessible from anywhere.
When using Google Workspace, Personal Data such as names, email addresses, calendar events, document content and communication data are processed. This information is necessary to provide the services, to enable collaboration and communication between users and to offer a personalized user experience.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize productivity and collaboration services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in promoting the efficiency, productivity and collaboration of teams and organizations.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Workspace can be found at https://policies.google.com/privacy.
35. Data protection provisions about the application and use of Miro
We use Miro as a digital whiteboard tool for conducting workshops, brainstorming sessions, teamwork and visual collaboration. Miro enables teams to work together on projects, develop ideas, structure content and create graphical representations in real time or asynchronously. In the course of using this tool, personal data may be processed, particularly when users register, post content on boards or interact with each other via integrated communication functions. The data processed includes names, email addresses, company affiliation, user IDs, team assignments, profile pictures, IP addresses, time zones, usage activities and content added to Miro boards by users themselves.
In addition, Miro may process technical information about the browser used, the endpoint, log files and access data in order to ensure the functionality of the platform. If collaboration functions such as comments, polls or chats are used, Miro also stores this content to provide the services. In the paid version, billing data and license management information may also be collected. Processing takes place both automatically via Miro's cloud infrastructure and manually by the support team to assist with usage or to solve problems. The data can be stored in data centers outside the EU.
The company that operates the service and thus the recipient of personal data is: RealtimeBoard, Inc. dba Miro, ATTN: Privacy Team, 201 Spear St, Suite 1100, San Francisco, CA 94105, USA. For data subjects in the EU and EEA, RealtimeBoard B.V., ATTN: Data Protection Team, Singel 542, 1017 AZ Amsterdam, The Netherlands, acts as contact and representative within the meaning of Art. 27 GDPR.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of processing is the provision of a digital collaboration tool, the management of user accounts, the facilitation of joint visual work processes and the technical and security-related maintenance of the service. Processing is carried out on the basis of Art. 6 (1) (b) GDPR, i.e., for the performance of a contract to which the data subject is party, and Art. 6 (1) (f) GDPR. The legitimate interest lies in efficient digital collaboration, the optimization of work processes, quality assurance and the security and integrity of the platform.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide personal data, you may not be able to use our services or those of the company that operates the service.
Further information and the applicable data protection provisions of Miro may be retrieved under https://miro.com/legal/privacy-policy/.
36. Data protection provisions about the application and use of monday.com
monday.com is a versatile work management platform that enables teams to plan, track and efficiently manage projects. As a cloud-based software, monday.com provides solutions for task management, project planning, CRM, time tracking and more to drive productivity and collaboration within teams and organizations. With a user-friendly interface and customizable workflows, monday.com helps companies of all sizes across industries organize their work and achieve goals.
When using monday.com, Personal Data such as names, email addresses, job titles, contact details, usage data (e.g., how and when the services are used), and payment information are processed. This information is necessary to provide the services, manage user accounts, make support requests and improve the user experience.
The company that operates the service and thus the recipient of personal data is: monday.com Ltd., 6 Yitzhak Sadeh Street, Tel Aviv, 6777506, Israel. For data subjects in the EU and EEA, monday.com GmbH, Leopoldstr. 244, 80807 München, Germany acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Monday.com UK 2020 Ltd., 30 Old Bailey, London EC4M 7AU, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the work platform. Processing is based on the performance of a contract (Art. 6 (1) (b) GDPR) to which the Data Subject is party, the user's Consent (Art. 6 (1) (a) GDPR) or on legitimate interests (Art. 6 (1) (f) GDPR), such as the use of an efficient platform, the improvement of our services, the provision of customer support and ensuring system security.
The company that operates the service and thus the recipient of the Personal Data is based in a country that has been recognized by the European Commission as having an adequate level of data protection. Therefore, no additional guarantees are required for the transfer of data.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of monday.com can be found at https://monday.com.
37. Data protection provisions about the application and use of AVG
AVG provides a range of security solutions, including antivirus software, malware protection and web security, to protect our devices and data from online threats. When using AVG, personal data such as name, email address, device information, IP addresses and usage data is processed to provide security features and to detect and prevent threats. This data helps to identify potential security incidents and protect our devices from viruses, spyware and other malware.
The company that operates the service and thus the recipient of personal data is: Avast Software s.r.o., Pikrtova 1737/1a, 140 00 Prague 4, Czech Republic. The representative under national law in the United Kingdom is: NortonLifeLock UK Limited, 100 New Bridge Street, London, EC4V 6JA, United Kingdom.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is to protect against malware and security threats. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in maintaining the security of the devices and networks.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of AVG can be found at https://www.avg.com/.
38. Data protection provisions about the application and use of Auth0
Auth0 enables organizations to create secure, seamless and scalable login experiences for their users by providing a wide range of authentication methods and security features. These services support various authentication standards such as OAuth, OpenID Connect and SAML and enable easy integration into existing applications.
When using Auth0, Personal Data is processed to provide authentication services. This includes information such as email addresses, usernames and customer-specific data that is transmitted as part of the authentication process.
The company that operates the service and thus the recipient of personal data is: Auth0, LLC, 100 First Street, Floor 6, San Francisco, CA 94105, USA. For data subjects in the EU and EEA, Okta GmbH, Friedrich-Ebert-Anlage 49, OG, 60308 Frankfurt am Main, Germany acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Okta UK Limited, 20 Farringdon Road, London EC1M 3HE, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: Personal Data are processed for the purpose of providing and improving authentication services and ensuring IT security. This includes the management of user identities, the authentication and authorization of users and the use of security features. The legal basis for Processing is Art. 6 (1) (b) GDPR for contracts to which the Data Subject is a party and Art. 6 (1) (f) GDPR (legitimate interest) for the Processing operations that serve to improve the security and efficiency of our services and IT security.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the statutory or contractual retention periods. The provision of Personal Data is required by law or contract or is necessary for the conclusion of a contract. You are obliged to provide us with Personal Data for this Processing activity.
Further information and the applicable data protection provisions of Auth0 can be found at https://auth0.com.
39. Data protection provisions about the application and use of Microsoft Defender for Office 365
We use Microsoft Defender for Office 365 to protect our email communications and connected Office applications from cyberthreats such as phishing, malware, ransomware, spam, and other security-related attacks. The service is fully integrated into Microsoft 365 and analyzes incoming and outgoing emails as well as content within SharePoint, OneDrive, and Microsoft Teams. As part of these protection mechanisms, personal data is processed, in particular data contained in email content, attachments, subject lines, sender data and recipient addresses as well as metadata. In addition, IP addresses, time stamps, device information, login histories and usage data are processed.
Processing is used to identify potential threats, apply protection policies, perform real-time analysis, and notify and log security events. Microsoft Defender for Office 365 uses artificial intelligence and machine learning to detect threats at an early stage and defend against them automatically. Data processing is automated via the Microsoft cloud infrastructure. Administrators can view security reports, receive alerts, and adjust policies via a central portal.
The company that operates the service and thus the recipient of personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Microsoft Schweiz GmbH, Seestrasse 356, 8038 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of processing is to protect against security-related threats in email communication and within the Microsoft 365 environment, to detect and defend against attacks, to analyze security-related incidents and to comply with internal company security requirements. Processing is carried out on the basis of Art. 6 (1) (f) GDPR. The legitimate interest lies in the protection of sensitive communication channels, the prevention of data loss, the integrity of our systems and the protection of our employees and communication partners.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide personal data, you may not be able to use our services or those of the company that operates the service.
Further information and the applicable data protection provisions of Microsoft Defender for Office 365 can be retrieved at https://privacy.microsoft.com/.
40. Data protection provisions about the application and use of Microsoft Entra
We use Microsoft Entra to manage identities, access rights and authentication processes. Microsoft Entra is part of the Microsoft cloud platform and includes functions such as single sign-on, multi-factor authentication, role-based access control and identity protection. When using this service, personal data is processed, particularly in the context of logging in, managing user accounts and authorizing access to internal or external resources. The data processed includes first names, surnames, usernames, email addresses, IP addresses, device identifiers, authentication data, roles, group memberships, location data, log data and timestamps of login information and access events.
Data processing is automated via Microsoft's cloud-based infrastructure. The identity data and access information are used to enable authorized access to services and data, prevent unauthorized access and ensure that only authorized persons can perform certain actions. In addition, Microsoft Entra uses analysis functions to detect potential security risks, identify anomalies in user behavior and initiate appropriate protective measures. The service is provided via Microsoft Azure and can be integrated into other Microsoft systems and third-party applications.
The company that operates the service and thus the recipient of personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Microsoft Schweiz GmbH, Seestrasse 356, 8038 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of processing is the central management of digital identities, the protection of user accounts, the authorization of access to applications and resources and the performance of secure login procedures. The processing is carried out on the basis of Art. 6 (1) (b) GDPR, i.e., for the performance of a contract to which the data subject is party, and Art. 6 (1) (f) GDPR. The legitimate interest lies in secure, controlled and traceable user administration, the prevention of misuse and the consistent implementation of IT security guidelines.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide personal data, you may not be able to use our services or those of the company that operates the service.
Further information and the applicable data protection provisions of Microsoft Entra may be retrieved under https://privacy.microsoft.com/.
41. Data protection provisions about the application and use of Google Analytics
Google Analytics is a tool from Google LLC that provides operators of websites and apps with detailed statistics on traffic and user behavior. It enables the collection and analysis of data on website visits, user interactions and conversion rates, which helps operators to understand and optimize their online presence. Google Analytics uses cookies to collect information about user behavior, including page views, time spent on the site and the paths users take on the site.
When using Google Analytics, Personal Data such as IP addresses, browser information and interaction data are processed. This data helps website operators to measure the performance of their website, improve the user experience and develop targeted marketing strategies.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the analysis and optimization of websites, apps, and advertising. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the website, increasing user-friendliness and the effectiveness of online marketing.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Analytics can be found at https://policies.google.com/privacy.
42. Data protection provisions about the application and use of Google AdSense
Google AdSense is an advertising program from Google LLC that enables website operators and bloggers to generate revenue by placing targeted ads on their websites. These ads can include text, images, video or interactive media content and are selected based on the content of the website and the interests of the visitors. AdSense uses algorithms to determine the most relevant and best performing ads for each page, optimizing both the user experience and monetization opportunities for publishers.
When using Google AdSense, Personal Data such as IP addresses, cookies and other identifiers are processed, which originates from the interaction of users with the advertisements and the websites visited. This data helps to measure the effectiveness of advertising, personalizing ads and prevent fraud.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the AdSense service, the analysis and optimization of advertising campaigns and the generation of revenue for publishers. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the effective delivery and personalization of advertising, which is beneficial for advertisers as well as publishers and website visitors.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google AdSense may be retrieved under https://policies.google.com/privacy.
43. Data protection provisions about the application and use of Google Ads
Google Ads, formerly known as Google AdWords, is an online advertising program from Google LLC that allows businesses to place targeted ads to increase their visibility on the internet. Google Ads offers various advertising formats, including search ads, display ads, YouTube video ads and more, which allow companies to reach potential customers on Google search results pages, partner websites and other platforms in the Google network.
When using Google Ads, Personal Data such as IP addresses, cookies and other identifiers resulting from interaction with advertisements are processed. This data helps to measure the effectiveness of advertising campaigns, to precisely address target groups and to personalize advertisements based on the interests and behaviour of users.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the analysis and optimization of online advertising campaigns. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the effective design and delivery of advertising campaigns that are relevant to both advertisers and users.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Google Ads can be found at https://policies.google.com/privacy.
44. Data protection provisions about the application and use of Meta Ads Conversion Tracking (MetaPixel)
Meta Ads Conversion Tracking, also known as Meta Pixel, is a tracking tool that allows us to measure and optimize the performance of ads on Meta's platforms (Facebook, Instagram, etc.). Meta Ads Conversion Tracking collects personal data such as IP addresses, pages visited and interactions with the ads. This data helps us to analyze the effectiveness of our advertising and to target ads for users who are most likely to convert. Meta Pixel also contributes to the personalization of ads and enables us to monitor and adjust the results of advertising measures.
The company that operates the service and thus the recipient of personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent's Place, London, NW1 3FG, United Kingdom.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is to optimize and measure advertising on Meta's platforms. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the effective placement of advertising and the improvement of campaign performance.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions can be found at https://facebook.com.
45. Data protection provisions about the application and use of Imagify
Imagify is a WordPress plugin that can be used to automatically optimize and reduce the size of images to improve website loading times. The plugin offers functions such as compressing images without any visible loss of quality and converting them to modern formats. Imagify processes images and can collect data such as IP addresses and information about image Processing.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Imagify is to optimize images to improve page load times and general website performance. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in the use of a more efficient and faster web usage experience through improved image loading times.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
Further information about Imagify can be found at https://imagify.io/.
46. Data protection provisions about the application and use of Limit Login Attempts
Limit Login Attempts is a WordPress plugin designed to increase the security of WordPress websites by limiting the number of “login attempts” a user can make within a certain period of time. It helps prevent brute force attacks by blocking IP addresses that repeatedly make incorrect login attempts. The plugin can capture IP addresses, login attempt details and timestamps.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Limit Login Attempts is to increase the security of websites and prevent unauthorized access attempts. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in ensuring the security of the website and protection against unauthorized access by Third Parties.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
More information about Limit Login Attempts can be found in the WordPress plugin repository at WordPress.org.
47. Data protection provisions about the application and use of Limit Login Attempts Reloaded
Limit Login Attempts Reloaded is a security plugin for WordPress that aims to protect the website from brute force attacks by limiting the number of failed login attempts. The plugin logs IP addresses and attempts to detect patterns in access behavior to identify and block unauthorized login attempts. It also records timestamps and specific details of login attempts.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Limit Login Attempts Reloaded is to protect WordPress websites from unauthorized access by monitoring and limiting login attempts. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in securing the website and preventing brute force attacks.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
More information about Limit Login Attempts Reloaded can be found in the WordPress plugin repository at WordPress.org.
48. Data protection provisions about the application and use of Premium Addons for Elementor
Premium Addons for Elementor is an advanced plugin for the WordPress page builder tool Elementor. It offers additional widgets and functions that extend the design options and functionality of Elementor pages. The plugin does, in general, not collect any Personal Data from end users, unless specific widgets are used that could collect such information, such as contact forms or newsletter subscriptions.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Premium Addons for Elementor is the use of extended design options and functionalities for websites created with Elementor. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in the improvement of the user experience and the use of additional functions that meet the requirements of website operators and their target groups.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
Further information about Premium Addons for Elementor can be found at https://premiumaddons.com/.
49. Data protection provisions about the application and use of Rank Math SEO
Rank Math SEO is a WordPress plugin that aims to improve the search engine optimization (SEO) of websites. It offers a variety of features such as optimizing meta tags, creating sitemaps, managing redirects, and analyzing SEO performance. Rank Math SEO processes data such as content metadata, SEO settings, user interactions and Personal Data contained in the website's SEO information.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Rank Math SEO is to optimize the website for search engines to increase visibility and ranking. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in improving the online presence of the website, which leads directly to improved traffic and increased business results.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
Further information about Rank Math SEO can be found at https://rankmath.com/.
50. Data protection provisions about the application and use of Translate Multilingual sites - TranslatePress
TranslatePress is a WordPress plugin that makes it possible to create and manage multilingual websites. It translates content directly on the website, allowing users to change the language of their website easily and efficiently. TranslatePress does not collect or store any Personal Data through the translation functionality. However, translations of content containing Personal Data, such as names or contact information in forms, may be processed and temporarily stored to enable the multilingualism of the website.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using TranslatePress is to use a user-friendly solution to create multilingual websites, which improves the global reach and accessibility of the website. The Processing of Personal Data that may be indirectly affected by the translation process is based on Art. 6 (1) (f) GDPR, based on the legitimate interest of the website operator to make its content accessible to a wider audience.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
Further information about the plugin and the applicable data protection provisions of TranslatePress can be found at WordPress.org.
51. Data protection provisions about the application and use of UpdraftPlus
UpdraftPlus is a WordPress plugin for backing up and restoring websites. UpdraftPlus allows users to easily back up their website data, including files, databases, plugins and themes, and restore it to the same location or a new location if required. UpdraftPlus also offers automated backup features and supports cloud storage solutions such as Google Drive, Dropbox and Amazon S3. When using UpdraftPlus, Personal Data such as names, email addresses and payment information (for premium versions or add-ons) are processed. In addition, information on website configurations and backup data may be collected. This data is necessary to provide the services, manage user accounts, provide support and improve the functionality of the plugin.
The company that operates the service and thus the recipient of personal data is: UPDRAFT WP SOFTWARE LIMITED, Tramshed Tech Griffin Street, High Street, Newport, Wales, NP20 1FX, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing is to use the backup and restore functions for WordPress websites. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as ensuring the integrity and security of user data and websites.
The developer of the application is based in a country that has been recognized by the European Commission as having an adequate level of data protection. Therefore, no additional guarantees are required for the transfer of data.
The criteria for determining the duration for which the Personal Data is processed are the statutory or contractual retention periods. The provision of Personal Data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. However, if you do not provide it, you may not be able to use the services.
Further information and the applicable data protection provisions of UpdraftPlus can be found at https://updraftplus.com.
52. Data protection provisions about the application and use of Complianz - Terms and Conditions
Complianz - Terms and Conditions is a WordPress plugin that helps website operators to generate and manage legally binding terms and conditions. The tool facilitates the creation of customizable terms and conditions that are specifically tailored to the legal requirements and individual situation of the website. The plugin does not collect any Personal Data but merely provides a platform where users can enter their own data to create relevant documents. However, these documents may contain Personal Data.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Complianz - Terms and Conditions is to use a tool to create and manage legally compliant terms and conditions for websites to comply with legal requirements. Processing is based on Art. 6 (1) (c) GDPR, as Processing is necessary for compliance with a legal obligation to which our organisation is subject.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is required by law or contract or is necessary for the conclusion of a contract. You are obliged to provide us with Personal Data for this Processing activity.
Further information about Complianz - Terms and Conditions can be found at WordPress.org.
53. Data protection provisions about the application and use of Element Pack Elementor Addons
Element Pack Elementor Addons is a plugin for Elementor that provides additional widgets and features for the Elementor Page Builder. This plugin allows users to enrich their websites with advanced elements such as headers, footers, dynamic grids, carousels, and many other features. The plugin does not store any Personal Data other than that which users insert into the website elements, such as contact information in forms or dynamic content pulled from specific data sources.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Element Pack Elementor Addons is to use advanced design options for websites that use the Elementor Page Builder. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user-friendliness and aesthetic quality of websites.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
More information about Element Pack Elementor addons can be found at WordPress.org.
54. Data protection provisions about the application and use of Elementor
Elementor is a WordPress plugin that allows users to design websites with an intuitive drag-and-drop editor. It offers a wide range of design templates, widgets and features that make it easy to create professional-looking websites without coding knowledge. Elementor is used by web design professionals and beginners alike to develop responsive, mobile-friendly websites.
When using Elementor, Personal Data such as names, email addresses and usage data are processed, especially when users create an account to access advanced features or support. This information is necessary to manage user accounts, make support requests and offer users personalized services and updates.
The developer of the application is: Elementor Ltd, PO-Box 657, 44 Shlomo ha-Melekh St., Ramat Gan 5252165, Israel.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the website. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience and providing an efficient and user-friendly website.
The developer of the application is based in a country that has been recognized by the European Commission as having an adequate level of data protection. Therefore, no additional guarantees are required for the transfer of data.
The criteria for determining the duration for which the Personal Data is processed are the statutory or contractual retention periods. The provision of Personal Data is neither required by law or contract nor necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. However, if you do not provide it, you may not be able to use the services.
Further information and the applicable data protection provisions of Elementor may be retrieved under https://elementor.com.
55. Data protection provisions about the application and use of ElementsKit Elementor addons
ElementsKit Elementor addons is a plugin for the WordPress page builder Elementor that offers a variety of widgets, modules, and layout options. These extensions allow users to customize their pages and make them functional, including forms, headers and footers, and tabs. The plugin does not collect any Personal Data, but it may support the creation of content that includes such data, depending on the specific features that are implemented.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using ElementsKit Elementor addons is to extend the functionality and customizability of the Elementor Page Builder. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in the use of extended design options and interaction options for developers and operators, which improves the user experience and the functionality of the websites.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
Further information about ElementsKit Elementor addons can be found at https://wpmet.com.
56. Data protection provisions about the application and use of Envato Elements
Envato Elements is a WordPress plugin that gives users access to an extensive library of graphic templates, photos, videos, music, and other digital assets that can be used to design their websites. The plugin facilitates the integration of these resources directly into WordPress to simplify the web design process. While the plugin does not store any Personal Data, it can provide access to resources hosted on Envato’ s servers that contain or process Personal Data.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Envato Elements is to provide a wide range of design resources that users can use to improve their websites. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in improving the aesthetics and functionality of websites.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
Further information about Envato Elements can be found at https://elements.envato.com.
57. Data protection provisions about the application and use of Essential Addons for Elementor
Essential Addons for Elementor is an extension plugin for the Elementor Page Builder that provides a variety of additional widgets and modules to extend the functionality and design of websites built with Elementor. The plugin allows users to add more sophisticated layouts and features, such as forms, advanced galleries, content tables and more. Essential Addons does not collect any Personal Data from users, but it may support the integration of such features that collect Personal Data, depending on the specific application by the website operator.
The application is installed on our own IT infrastructure. We are the company operating the service.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using Essential Addons for Elementor is to extend the design options within the Elementor Page Builder. Processing is based on Art. 6 (1) (f) GDPR. Our legitimate interest lies in the use of advanced design options and functionality options for web developers and website operators to create more appealing and functional websites.
The criteria for determining the duration for which the Personal Data is processed are internal, statutory, or contractual retention periods. The use of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us with Personal Data. If you do not provide it, you may not be able to use our services, functionality, or the plugin.
More information about Essential Addons for Elementor can be found at https://wpdeveloper.net/.
58. Data protection provisions about the application and use of Facebook
Facebook is a social network that offers people the opportunity to connect, share content and communicate online. Users can create profiles, post photos and videos, exchange messages and organize themselves into groups. Facebook also offers companies and organizations a platform for advertising and interacting with their target group.
When using Facebook, Personal Data such as names, email addresses, telephone numbers, usage data, location information, and information on shared content is processed. This data is necessary to provide the platform, offer personalized content and advertising, ensure user safety, and develop new services.
The company that operates the service and thus the recipient of personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent's Place, London, NW1 3FG, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the social network functions and network services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience, providing personalized content and advertising and ensuring the security of the network.
The company that operates the service is located in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Facebook can be found at https://facebook.com.
59. Data protection provisions about the application and use of Instagram
Instagram is a widely used social network that allows users to share photos and videos, post stories, and interact with followers and friends. Instagram offers a variety of features, including direct messages, IGTV for longer videos, Instagram Live for real-time broadcasts and a Discover page to find added content and users.
When using Instagram, Personal Data such as names, email addresses, telephone numbers, user content (photos, videos, comments, etc.), location data, usage information and, in certain cases, payment information is processed. This data helps to provide the service, ensure the security of the platform, offer personalized advertising, and improve the user experience.
The company that operates the service and thus the recipient of personal data is: Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA. For data subjects in the EU and EEA, Meta Platforms Ireland Ltd., Merrion Road, Dublin D04 X2K5, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Meta Platforms Technologies UK Ltd, 10 Brock Street, Regent's Place, London, NW1 3FG, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of the social network functions. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, where our legitimate interest lies in the improvement and personalization of the user experience, the provision of customer support and ensuring the security and integrity of the platform, as well as in the use of the platform and marketing.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Instagram can be viewed at https:// instagram.com.
60. Data protection provisions about the application and use of LinkedIn
LinkedIn is a social network for professional contacts and career development. The platform allows users to create a professional profile, network with colleagues, business partners and potential employers, share professional experiences and skills, and keep up to date with industry news. LinkedIn also provides tools for companies and recruiters to source talent, post job ads and build a brand presence.
When using LinkedIn, Personal Data such as names, email addresses, professional titles and experience, educational background, skills, interests, and platform usage data are processed. This information is necessary to provide and use the service to create networking opportunities, to present personalized content and job offers and to ensure the security of user data.
The company that operates the service and thus the recipient of the Personal Data is: LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of network and career services. Processing is based on the Consent of the user (Art. 6 (1) (a) GDPR), the performance of a contract (Art. 6 (1) (b) GDPR) to which the Data Subject is party and on legitimate interests (Art. 6 (1) (f) GDPR), such as marketing and recruitment.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of LinkedIn Corporation can be found at https://www.linkedin.com.
61. Data protection provisions about the application and use of TikTok
TikTok, a platform for short video clips that enjoys great popularity worldwide, enables users to create, share and discover creative content. Users can dance, sing, perform art or participate in trends on TikTok and interact with a global community.
When using TikTok, Personal Data such as names, email addresses, telephone numbers, dates of birth, profile information, user content (videos, comments), location data, and information from social networks are processed. This data is required to provide the services, personalize the platform, enable user interactions, and improve support.
The company that operates the service and thus the recipient of personal data is: TikTok Pte. Ltd., 1 Raffles Quay, No. 26-10, South Tower, 048583, Singapore. For data subjects in the EU and EEA, TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London, EC1A 9HP, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing is the use of the video platform. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of a global platform for advertising and increasing our market presence.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of TikTok may be retrieved under https://www.tiktok.com.
62. Data protection provisions about the application and use of X (formerly Twitter)
X (formerly known as Twitter) is a global platform for public self-expression and real-time conversation. Users can create and share short messages, called tweets, which can include text, images, videos, and links. The platform allows users to follow breaking news, interact with others and participate in global discussions.
When using X, several types of Personal Data are processed, including usernames, email addresses, telephone numbers and location data. This information can be used for account creation, personalization of content, provision of advertising, security purposes and for analytical evaluations.
The company that operates the service and thus the recipient of personal data is: X Corp., 865 FM-1209, Building 2, Bastrop, TX 78602, USA. For data subjects in the EU and EEA, X Internet Unlimited Company, 1 Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: X Schweiz GmbH, c/o Wasag Treuhand AG, Normannenstrasse 8, 3018 Bern, Switzerland.
The Processing of Personal Data takes place, among other things, on the basis of the user's Consent (Art. 6 (1) (a) GDPR), for the performance of a contract (Art. 6 (1) (b) GDPR) to which the Data Subject is a party, or on the basis of legitimate interests (Art. 6 (1) (f) GDPR), such as the use of the platform and the improvement of communication with the public.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of X can be found at https://twitter.com/.
63. Data protection provisions about the application and use of XING
XING is a social network that specializes in professional contacts and career networking. It enables its users to create professional profiles, maintain contacts, exchange information about professional opportunities and keep up to date with industry news. XING serves as a platform for specialists and managers from a wide range of industries to present their professional identity online, network with colleagues and discover new career opportunities.
When using XING, Personal Data such as names, professional contact information, employment history, education history, and photos are processed. This information is required to provide network functions, to create and manage user profiles, to offer personalized recommendations and to enable communication between users.
The company that operates the service and thus the recipient of personal data is: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing is the use of the social network. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of the platform, the exchange with the public and the provision of services that support professional exchange.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of XING may be retrieved under https://privacy.xing.com.
64. Data protection provisions about the application and use of YouTube
YouTube is a video sharing and viewing platform used by individuals, artists, businesses, and media companies to publish a variety of content such as music videos, vlogs, educational material and much more. YouTube offers users the ability to upload, share, comment and interact with a broad community.
When using YouTube, Personal Data such as IP addresses, user interactions (e.g., videos viewed, comments), location data (if enabled for services) and information from linked Google accounts are processed. This information is required to provide personalized content and advertising, enable user interactions, keep the platform secure and improve the user experience.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing lies in the use of the video sharing services. Processing is based on the performance of a contract pursuant to Art. 6 (1) (b) GDPR, to which the Data Subject is a party, and on legitimate interests pursuant to Art. 6 (1) (f) GDPR, such as the use of an efficient video platform, the improvement of the user experience, the use of personalized advertising and the use of embedded videos on our website.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of YouTube can be found at https://policies.google.com.
65. Data protection provisions about the application and use of Apple
We use various Apple products and services in our organisation and on our website. These include the use of Apple hardware (such as iPads and MacBooks), software solutions and cloud services to optimize our business processes, facilitate communication and provide improved services to our customers. Apple products and services enable us to process, store, and transmit data efficiently to improve the user experience.
This includes, for example, the use of iCloud for data backups, the use of Apple ID to personalize the user experience and the integration of Apple Pay as a secure payment method. Apple, Inc. collects and processes Personal Data to provide these services. This may include information about device usage, location data, purchase history, and app usage data.
The company that operates the service and thus the recipient of personal data is: Apple, Inc., One Apple Park Way, Cupertino, CA 95014, USA. For data subjects in the EU and EEA, Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Irland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Apple Switzerland AG, Löwenstrasse 29, 8001 Zürich, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of data processing is the use of Apple products and services. The legal basis for Processing is Art. 6 (1) (b) GDPR, for contracts to which the Data Subject is a party, and Art. 6 (1) (f) GDPR (legitimate interest) for the Processing necessary to improve our services and products. The legitimate interests include ensuring the security of the services, improving the products and services, and ensuring a personalized user experience.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. Apple may be a certified member of one or more of the Data Privacy Frameworks. You can find more information at https://www.dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Apple, Inc. can be found at https://www.apple.com.
66. Data protection provisions about the application and use of Asus
Asus is a leading manufacturer of computers, laptops, and networking equipment. When using Asus’s products, personal data such as device information, e-mail addresses, serial numbers, and support requests are processed in order to support products, improve customer service and provide support services. This data is used to organize repairs, provide software updates and improve the user experience.
The company that operates the service and thus the recipient of personal data is: ASUSTeK Computer, Inc., 15, Li-Te Road, Beitou District, Taipei 112, Taiwan. For data subjects in the EU and EEA, ASUS Netherlands B.V., Paasheuvelweg 25, 1105 BP Amsterdam, The Netherlands, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: ASUSTeK (UK) Limited, 1st Floor, Focus 31, West Wing, Mark Road, Hemel Hempstead, HP2 7BW, United Kingdom.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the use and provision of product support, the performance of repairs and the provision of software updates. Processing is based on Art. 6 (1) (b) GDPR, as it is necessary for the performance of a contract to which the data subject is a party, and on Art. 6 (1) (f) GDPR, where the legitimate interest lies in the provision of support and software updates.
The company that operates the service is located in a third country, namely Taiwan. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Asus may be retrieved under https://www.asus.com/.
67. Data protection provisions about the application and use of Autodesk
Autodesk develops software solutions for architecture, engineering, construction, design, manufacturing, and entertainment. Autodesk's product range includes well-known software such as AutoCAD, Revit, Maya and 3ds Max, which enable the creation of high-quality designs, models, and animations. Autodesk products help users visualize, simulate, and analyze their ideas to make better decisions and develop innovative solutions.
When using Autodesk products, Personal Data is processed to provide, personalize and improve the software. This may include information such as names, email addresses, usage data, and settings.
The company that operates the service and thus the recipient of personal data is: Autodesk, Inc., The Landmark, One Market, Suite 400, San Francisco, CA 94105, USA. For data subjects in the EU and EEA, Autodesk Ireland Operations Unlimited, 1 Windmill Lane, 2nd Floor, Dublin D02 F206, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Autodesk Ltd., Talbot Way, Small Heath Business Park, Birmingham, B10 0HJ, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: Personal Data are processed for the purpose of using and personalizing the software products and services. This includes license management, technical support, product development, and the use of training resources. The legal basis for Processing is Art. 6 (1) (b) GDPR for contracts to which the Data Subject is a party and Art. 6 (1) (f) GDPR (legitimate interest) for Processing that serves to improve the user experience and product quality and use by us.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
For more information and Autodesk's applicable Privacy Policy, please visit https://www.autodesk.com.
68. Data protection provisions about the application and use of Canon
Canon is a manufacturer of imaging systems and optical products, including cameras, printers and scanners. When using Canon products, personal data such as contact information, device information and usage data is processed to improve customer service, provide product support and process warranty claims. This data is used to manage repairs, provide software updates and improve the user experience.
The company that operates the service and thus the recipient of personal data is: Canon U.S.A., Inc., One Canon Park, Melville, NY 11747, USA. For data subjects in the EU and EEA, Canon Europa N.V., Bovenkerkerweg 59, 1185 XB Amstelveen, The Netherlands, acts as contact and representative within the meaning of Art. 27 GDPR.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the use and provision of support services, the management of guarantees and the provision of software updates. Processing is based on Art. 6 (1) (b) GDPR, as it is necessary for the performance of a contract to which the data subject is a party, and on Art. 6 (1) (f) GDPR, where the legitimate interest lies in the use of support services.
The company that operates the service and thus the recipient of the Personal Data is based in a country that has been recognized by the European Commission as having an adequate level of data protection. Therefore, no additional guarantees are required for the transfer of data.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and Canon's applicable privacy policy can be found at https://www.canon.com/.
69. Data protection provisions about the application and use of HP / Hewlett Packard
Hewlett Packard (HP) is a technology company that offers a wide range of products and services, including printers, PCs, mobile devices, data storage solutions and cloud-based services.
When using HP products and services, Personal Data such as names, addresses, email addresses, telephone numbers, product and service information, usage data and, in certain cases, payment information is processed. This information is necessary to administer user accounts, provide products and services, enable customer support, make product enhancements, and provide personalized experiences.
The company that operates the service and thus the recipient of personal data is: HP, Inc., 1501 Page Mill Road, Palo Alto, CA 94304, USA. For data subjects in the EU and EEA, HP Europe B.V., Wegalaan 9–21, 2132 JD Hoofddorp, Netherlands, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: HP UK Limited, Earley West, 300 Thames Valley Park Drive, Reading, Berkshire, RG6 1PT, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: HP Schweiz GmbH, Glatt Tower, Neue Winterthurerstrasse 99, 8304 Wallisellen, Switzerland.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of technology products and technology services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the improvement of our products and services, the use of customer support and the use of new and efficient technologies.
The company that operates the service is located in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of HP may be retrieved under https://www.hp.com.
70. Data protection provisions about the application and use of Lenovo
Lenovo is a leading global provider of computers and other technological devices. When using Lenovo products and services, personal data such as serial numbers, contact information and usage data is processed to improve support, process warranty claims and provide customer service. This data is used to manage repairs and maintenance services, provide software updates and offer personalized services.
The company that operates the service and thus the recipient of personal data is: Lenovo Group Limited, 10 Xibeiwang East Road, Haidian District, Beijing 100094, China. For data subjects in the EU and EEA, Lenovo Global Technology International B.V., De Entree 250, Unit A, 1101 EE Amsterdam, Netherlands, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Lenovo Technology (United Kingdom) Limited, Third Floor, 25 Templer Avenue, Farnborough, GU14 6FE, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Lenovo (Schweiz) GmbH, Baslerstrasse 60, 8048 Zürich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the management of customer service requests, the provision of product updates and the improvement of the user service. Processing is based on Art. 6 (1) (b) GDPR, as it is necessary for the performance of a contract to which the data subject is a party, and on Art. 6 (1) (f) GDPR, where the legitimate interest is the improvement of customer support and maintenance of devices.
The company that operates the service is based in a third country, namely Hong Kong. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and Lenovo's applicable privacy policy can be found at https://www.lenovo.com/.
71. Data protection provisions about the application and use of Samsung
Samsung is a leading provider of electronics and technology products, including smartphones, televisions and home appliances. When using Samsung products, personal data such as contact information, device settings, usage data and location information is processed to improve service, provide software updates and support customer service. This data is used to manage repairs, deliver personalized content and optimize the user experience.
The company that operates the service and thus the recipient of personal data is: Samsung Electronics Co., Ltd., 129, Samsung-ro, Yeongtong-gu, Suwon-si, Gyeonggi-do, 16677, South Korea. For data subjects in the EU and EEA, Samsung Electronics Austria GmbH, Praterstrasse 31, 14th floor, A-1020 Vienna, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Samsung Electronics (UK) Limited, Samsung House, 2000 Hillswood Drive, Chertsey, Surrey, KT16 0RS, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Samsung Electronics Switzerland GmbH, Giesshübelstrasse 30, 8045 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the use and provision of product support, the performance of repairs and the provision of software updates. Processing is based on Art. 6 (1) (b) GDPR, as it is necessary for the performance of a contract to which the data subject is a party, and on Art. 6 (1) (f) GDPR, where the legitimate interest lies in the provision of repair and support services.
The company that operates the service is located in a third country, namely South Korea. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is neither legally nor contractually required, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with personal data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Samsung can be found at https://www.samsung.com/.
72. Data protection provisions about the application and use of ChatGPT
ChatGPT is an advanced AI-driven platform that enables natural and informative conversations. This technology supports us in a wide range of applications, including customer service, education, content creation and much more. By interacting with ChatGPT, users can ask questions, receive creative input or find support in solving complex tasks. OpenAI relies on the latest developments in artificial intelligence and machine learning to provide a conversation experience that is as human-like and understanding as possible.
When using ChatGPT, data such as the text entered, questions and contextual information of the conversation are processed. This information enables the AI to generate relevant and personalized responses. The data collected is used to improve the model, increase response quality and create a better user experience.
The company that operates the service and thus the recipient of personal data is: OpenAI OpCo, LLC, 3180 18th Street, San Francisco, CA 94110, USA. For data subjects in the EU and EEA, OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: OpenAI UK Ltd., Suite 1, 3rd Floor, 11-12 St. James’s Square, London, SW1Y 4LB, United Kingdom.
Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of an AI-controlled system. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the development, improvement and provision of innovative services and in increasing economic efficiency.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. OpenAI may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of OpenAI can be found at https://openai.com.
73. Data protection provisions about the application and use of Claude
Claude is an AI-powered text generation platform developed by Anthropic. Claude offers services for the automated creation of texts and the editing of content. When using Claude, personal data such as interaction data and the texts entered are processed to generate personalized and contextual responses. This data is also used to improve the performance of the AI and ensure that the results are relevant and helpful.
The company that operates the service and thus the recipient of personal data is: Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA. For data subjects in the EU and EEA, Anthropic Ireland, Ltd., 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the provision, use and improvement of AI-supported texts. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the improvement of performance, user experience and economic efficiency as well as in the use of AI-supported solutions.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is not required by law or contract or necessary for the conclusion of a contract. You are not obliged to provide us with personal data for this processing operation.
Further information and the applicable data protection provisions can be found at https://claude.ai/.
74. Data protection provisions about the application and use of Gamma
Gamma is a platform for data-driven work that enables users to support AI-supported decision making and optimize spending and designs. When using Gamma, personal data such as usage data and interaction data is processed to enable the provision of customized content. This data helps to deliver personalized and relevant results based on user preferences.
The company that operates the service and thus the recipient of personal data is: Gamma Tech, Inc., 2261 Market Street 4544, San Francisco, CA 94114, USA. For data subjects in the EU and EEA, Data Protection Representative Limited (DataRep), 3rd and 4th Floor, Altmarkt 10 B/D, 01067 Dresden, Germany, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Data Protection Representative Limited (DataRep), 107-111 Fleet Street, London, EC4A 2AB, United Kingdom.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the use of systems and the optimization of decision-making processes and strategic recommendations. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the improvement of analysis processes and the personalization of recommendations and spending as well as in the use of AI-supported solutions.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is not required by law or contract or necessary for the conclusion of a contract. You are not obliged to provide us with personal data for this processing operation.
Further information and the applicable data protection provisions can be found at https://gamma.app/.
75. Data protection provisions about the application and use of Google Gemini
Google Gemini is an AI-powered platform developed by Google to deliver personalized and accurate search results and responses to queries. When using Google Gemini, personal data such as search queries, interaction data, inputs, IP addresses and device information are processed to provide relevant and customized answers. This data is also used to optimize the user experience and improve the accuracy of search results.
The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is to improve search results and provide personalized answers. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the personalization of search results and the optimization of the user experience as well as in the use of AI-supported solutions.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is not required by law or contract or necessary for the conclusion of a contract. You are not obliged to provide us with personal data for this processing operation.
Further information and the applicable data protection provisions can be found at https://gemini.google.com/.
76. Data protection provisions about the application and use of Groq
Groq is a platform developed specifically for machine learning and AI model training. When using Groq, personal data such as usage data and interaction data is processed to support and optimize the training of AI models. This data helps to improve the performance of the models and ensures that users receive customized, more efficient solutions.
The company that operates the service and thus the recipient of personal data is: Groq, Inc., 301 Castro Street, Suite 200, Mountain View, CA 94041, USA. For data subjects in the EU and EEA, DP-Dock GmbH, Attn: Groq, Inc., Ballindamm 39, 20095 Hamburg, Germany, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: DP Data Protection Services UK Ltd., Attn: Groq, Inc., 16 Great Queen Street, Covent Garden, London, WC2B 5AH, United Kingdom.
Purposes for which personal data are to be processed and the legal basis for the processing: The purpose of the processing is the training of AI models and the improvement of machine learning processes. Processing is based on Art. 6 (1) (f) GDPR, whereby the legitimate interest lies in the increase in optimization and efficiency as well as in the use of AI-supported solutions.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may have concluded one of the EU Standard Contractual Clauses with us. You can request a copy of the suitable or appropriate safeguards from us.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of personal data is not required by law or contract or necessary for the conclusion of a contract. You are not obliged to provide us with personal data for this processing operation.
Further information and the applicable data protection provisions can be found at https://groq.com/.
77. Data protection provisions about the application and use of Microsoft Copilot
We use Microsoft Copilot within our organization as an AI-supported assistance tool for productive work - for example, when creating texts, summaries, suggestions or data analysis in documents, e-mails and applications. The service helps us to complete tasks more efficiently, provide knowledge information and creative impetus and automate recurring processes. Personal data can be processed during the process - especially data contained in the work content. Processed data includes employee names, email content, document texts, formulations, context data, metadata on files (including access, processing time), IP addresses, device data and log data on usage.
Processing is automated via the Microsoft 365 cloud infrastructure. Copilot accesses contextual content from Word, Outlook, Excel, PowerPoint and Teams to generate suitable suggestions. The data processing steps take place within the Microsoft environment and are subject to technical and organizational security measures such as encryption, role-based access rights and audit logs.
The company that operates the service and therefore the recipient of the personal data is: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. For data subjects in the EU and EEA, Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Microsoft Limited, Microsoft Campus, Thames Valley Park, Reading, RG6 1WG, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Microsoft Schweiz GmbH, Seestrasse 356, 8038 Zurich, Switzerland.
The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service is a certified member of the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. Data Privacy Framework. You can find more information at dataprivacyframework.gov/list. You can request a copy of the suitable or appropriate safeguards from us.
Purposes for which the personal data are to be processed and the legal basis for the processing: The purpose of the processing is to support employees in the creation of content, to automate workflows, to improve productivity and to increase efficiency in teamwork. The processing is carried out on the basis of Art. 6 (1) (b) GDPR, for the performance of a contract to which the data subject is party and on the basis of Art. 6 (1) (f) GDPR. The legitimate interest lies in the modern, AI-supported work organization, the quality assurance of results and the relief of routine tasks.
The criteria for determining the duration for which the personal data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract or necessary for the conclusion of a contract. You are not obliged to provide us or the operating company with personal data. However, if you do not provide personal data, you may not be able to use our services or those of the company operating the service.
Further information and the applicable data protection provisions of Microsoft Copilot and Microsoft 365 can be found at https://www.microsoft.com.
This privacy policy was created using a specialized generator that was developed by legal experts in IT law, external data protection consulting and the ISO 27701 certification authority to ensure legally secure wording.