🌱 Join Germany’s largest tree planting tour in 2026: Secure your spot now!

Privacy Policy

1. DATA PROTECTION AT A GLANCE

General information

Hello and welcome to our website. This privacy policy provides you with a simple overview of the type, scope and purpose of the collection and processing of personal data when you visit and use our website, the associated pages, functions and content, as well as our external online presences.

This privacy policy is based on the terminology used by the European General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The relevant definitions can be found, for example, in Art. 4 GDPR.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. The operator’s contact details can be found in the section “Information on the controller” in this privacy policy.

How do we collect your data?

Some of your data is collected when you provide it to us. This may, for example, be data that you enter in a contact form.

Other data is collected automatically or after your consent when you visit the website by our IT systems. This mainly includes technical data, such as your browser, operating system or the time at which a page is accessed. This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour.

What rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request that this data be corrected or deleted. If you have given consent to data processing, you may revoke this consent at any time with effect for the future. You also have the right, under certain circumstances, to request that the processing of your personal data be restricted. In addition, you have the right to lodge a complaint with the competent supervisory authority.

You may contact us at any time regarding this and any further questions on the subject of data protection.

Analysis tools and third-party tools

When you visit this website, your browsing behaviour may be statistically analysed. This is mainly done using so-called analysis programs. Detailed information about these analysis programs can be found in the following privacy policy.

2. GENERAL INFORMATION AND MANDATORY INFORMATION

Data protection

The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this is done.

Please note that data transmission over the Internet, for example communication by email, may have security vulnerabilities. Complete protection of data against access by third parties is not possible.

Information on the controller

The controller responsible for data processing on this website is:

PLANT-MY-TREE®
Managing Director: Sören Brüntgens
Hochstr. 1, 45472 Mülheim, Germany
Tel.: +49 (0) 20830664810
Email: info@plant-my-tree.de

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data, such as names, email addresses or similar information.

Storage period

Unless a more specific storage period is stated in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you make a legitimate request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data, such as tax or commercial law retention periods. In the latter case, deletion takes place after these reasons cease to apply.

General information on the legal bases for data processing on this website

If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR if special categories of data pursuant to Art. 9(1) GDPR are processed. In the case of express consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your end device, data processing is also carried out on the basis of Section 25(1) TDDDG. Consent may be revoked at any time.

If your data is required for the performance of a contract or for pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data if this is required to fulfil a legal obligation on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. The relevant legal bases in each individual case are explained in the following sections of this privacy policy.

Data protection officer

We have appointed a data protection officer.

LIEBENSTEIN Confidential GmbH
Prof. Dr. Hans-Hermann Dirksen
Eschersheimer Landstr. 351
60320 Frankfurt am Main, Germany
Phone: +49 69 2729-5921
Fax: +49 69 2729-5923
Email: mail@liebenstein-confidential.de

Information on data transfers to third countries that are not considered secure under data protection law and transfers to US companies that are not DPF-certified

We use tools from companies based in third countries that are not considered secure under data protection law, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). If these tools are active, your personal data may be transferred to and processed in these countries. We point out that no level of data protection comparable to that of the EU can be guaranteed in third countries that are not considered secure under data protection law.

The USA is generally regarded as a secure third country if the recipient is certified under the EU-US Data Privacy Framework or has suitable additional safeguards. Information on transfers to third countries, including the recipients of the data, can be found in this privacy policy.

Recipients of personal data / processing on behalf of the controller

In the course of our business activities, we work with various external parties. In some cases, personal data must be transferred to these external parties. We only transfer personal data to external parties if this is necessary for the performance of a contract, if we are legally obliged to do so, if we have a legitimate interest pursuant to Art. 6(1)(f) GDPR, or if another legal basis permits the transfer.

When using processors, we only pass on personal data of our customers on the basis of a valid data processing agreement. If we commission third parties to process data on the basis of a processing agreement, this is done on the basis of Art. 28 GDPR. These processors are carefully selected, commissioned, bound by our instructions and regularly monitored.

In the case of joint processing, an agreement on joint controllership is concluded pursuant to Art. 26 GDPR.

3. YOUR RIGHTS

You have the following rights in relation to your personal data:

  • pursuant to Art. 15 GDPR, the right to request confirmation as to whether data concerning you is being processed and to obtain information about this data, as well as further information and a copy of the data;
  • pursuant to Art. 16 GDPR, the right to request completion of your data or correction of incorrect data concerning you;
  • pursuant to Art. 17 GDPR, the right to request the immediate deletion of data concerning you, or alternatively, pursuant to Art. 18 GDPR, the right to request restriction of processing;
  • pursuant to Art. 20 GDPR, the right to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format and to request its transmission to another controller;
  • pursuant to Art. 77 GDPR, the right to lodge a complaint with the competent supervisory authority.

4. INFORMATION, CORRECTION AND DELETION

Within the framework of the applicable legal provisions, you have the right at any time to receive information free of charge pursuant to Art. 15 GDPR about your stored personal data, its origin and recipients, and the purpose of the data processing, and, where applicable, a right to correction or deletion of this data. Under German statutory requirements, retention periods are generally six years pursuant to Section 257(1) HGB and ten years pursuant to Section 147(1) AO for business and tax-relevant documents.

You may contact us at any time regarding this and any further questions about personal data.

5. RIGHT TO RESTRICTION OF PROCESSING

You have the right to request the restriction of the processing of your personal data. You may contact us at any time to exercise this right. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the verification, you have the right to request restriction of the processing of your personal data.
  • If the processing of your personal data was or is unlawful, you may request restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to request restriction of processing instead of deletion.
  • If you have lodged an objection pursuant to Art. 21(1) GDPR, a balancing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to request restriction of the processing of your personal data.

If you have restricted the processing of your personal data, such data may, apart from being stored, only be processed with your consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.

6. REVOCATION OF YOUR CONSENT TO DATA PROCESSING

Many data processing operations are only possible with your express consent. You may revoke consent that you have already given at any time. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation.

7. RIGHT TO OBJECT TO DATA COLLECTION IN SPECIAL CASES AND TO DIRECT ADVERTISING (ART. 21 GDPR)

IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RELEVANT LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT ADVERTISING PURPOSES, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSES OF SUCH ADVERTISING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL THEN NO LONGER BE USED FOR DIRECT ADVERTISING PURPOSES.

You may inform us of your objection using the following contact details:

PLANT-MY-TREE®
Managing Director: Sören Brüntgens
Hochstr. 1, 45472 Mülheim, Germany
Tel.: +49 (0) 20830664810
Email: info@plant-my-tree.de

8. RIGHT TO DATA PORTABILITY

You have the right to have data that we process automatically on the basis of your consent or in fulfilment of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request direct transfer of the data to another controller, this will only take place where technically feasible.

9. RIGHT TO LODGE A COMPLAINT WITH THE COMPETENT SUPERVISORY AUTHORITY

In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, workplace or the place of the alleged infringement. This right to lodge a complaint exists without prejudice to other administrative or judicial remedies.

The competent state data protection officer can be contacted at:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44, 40102 Düsseldorf, Germany
Telephone: 0211/38424-0
Fax: 0211/38424-999
Email: poststelle@ldi.nrw.de

10. OBJECTION TO ADVERTISING EMAILS

We hereby object to the use of contact data published in the context of the legal notice obligation for the purpose of sending unsolicited advertising and information materials. The operators of this website expressly reserve the right to take legal action in the event of unsolicited advertising information, such as spam emails.

11. DATA COLLECTION ON THIS WEBSITE

Cookies

Our websites use so-called cookies. Cookies are small data packages and do not damage your end device. They are stored on your device either temporarily for the duration of a session, known as session cookies, or permanently, known as permanent cookies. Session cookies are automatically deleted after the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or your web browser automatically deletes them.

Cookies may originate from us, known as first-party cookies, or from third-party companies, known as third-party cookies. Third-party cookies enable the integration of certain services provided by third-party companies within websites, for example cookies for payment services.

Cookies have different functions. Many cookies are technically necessary because certain website functions would not work without them, such as shopping cart functions or the display of videos. Other cookies may be used to analyse user behaviour or for advertising purposes.

Cookies that are required to carry out the electronic communication process, to provide certain functions requested by you, or to optimise the website are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is stated. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be revoked at any time.

You can set your browser so that you are informed about the setting of cookies, allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or generally, and activate automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted.

Consent with Cookiebot

Our website uses Cookiebot’s consent technology to obtain your consent to the storage of certain cookies on your end device or to the use of certain technologies and to document this consent in a data-protection-compliant manner. The provider is Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark.

When you enter our website, a connection to Cookiebot’s servers is established in order to obtain your consent and other declarations regarding cookie use. Cookiebot then stores a cookie in your browser in order to assign the consent given or its revocation to you. The data collected in this way is stored until you request deletion, delete the Cookiebot cookie yourself, or the purpose for data storage no longer applies. Mandatory statutory retention obligations remain unaffected.

Cookiebot is used to obtain the legally required consent for the use of cookies. The legal basis is Art. 6(1)(c) GDPR.

Processing on behalf of the controller

We have concluded a data processing agreement for the use of the above-mentioned service. This is a contract required under data protection law that ensures that the service provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These include:

  • browser type and browser version;
  • operating system used;
  • referrer URL;
  • host name of the accessing computer;
  • time of the server request;
  • IP address.

This data is not merged with other data sources. The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of the website.

SSL or TLS encryption

For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the browser address line changes from “http://” to “https://” and by the lock symbol in your browser line.

If SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Encrypted payment transactions on this website

If, after concluding a paid contract, there is an obligation to provide us with your payment data, such as account numbers for direct debit authorisations, this data is required for payment processing. Payment transactions using common means of payment are carried out exclusively via an encrypted SSL or TLS connection.

Contact form

If you send us enquiries via the contact form, your details from the enquiry form, including the contact details you provide there, will be stored by us for the purpose of processing the enquiry and in the event of follow-up questions. We do not pass on this data without your consent.

The processing of this data is carried out on the basis of Art. 6(1)(b) GDPR if your enquiry is related to the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of enquiries addressed to us pursuant to Art. 6(1)(f) GDPR or on your consent pursuant to Art. 6(1)(a) GDPR, where this has been requested.

Enquiries by email, telephone or fax

If you contact us by email, telephone or fax, your enquiry, including all resulting personal data such as name and enquiry, will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.

The processing of this data is carried out on the basis of Art. 6(1)(b) GDPR if your enquiry is related to the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of enquiries addressed to us pursuant to Art. 6(1)(f) GDPR or on your consent pursuant to Art. 6(1)(a) GDPR, where this has been requested.

Communication via WhatsApp

For contacting and communicating with customers, interested parties and other third parties, we also use the instant messaging service WhatsApp. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

If you communicate with us via WhatsApp, your personal data stored by WhatsApp, in particular telephone number, profile name, profile picture if applicable, and chat content, will be processed by us insofar as this is necessary to handle your request. The legal basis depends on the content and context of the communication and is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.

Please note that WhatsApp also processes personal data on servers of Meta Platforms Inc. in the USA. WhatsApp relies on EU standard contractual clauses to safeguard an adequate level of data protection. The use of WhatsApp is voluntary. If you do not wish to use WhatsApp, alternative contact options such as email or telephone are available.

Use of chatbots

We use chatbots to communicate with you. Chatbots are able to respond to your questions and other input without human assistance. For this purpose, chatbots analyse your input and other data in order to provide suitable responses, such as names, email addresses, customer numbers, orders and chat histories. Your IP address, log files, location information and other metadata may also be collected via the chatbot and stored on the servers of the chatbot provider.

The collected data may be used to create user profiles, to display interest-based advertising where the legal requirements are met, and to improve our chatbots and their response behaviour. The data you enter during communication remains with us or the chatbot operator until you request deletion, revoke your consent or the purpose for storage no longer applies. Mandatory statutory provisions remain unaffected.

The legal basis for the use of chatbots is Art. 6(1)(b) GDPR if the chatbot is used for contract initiation or within the framework of contract performance. Where consent has been requested, processing is carried out on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG. In all other cases, the use is based on our legitimate interest in the most effective possible customer communication pursuant to Art. 6(1)(f) GDPR.

Intercom

This website uses Intercom for chat, messenger and communication functions. The provider is Intercom R&D Unlimited Company, 2nd Floor, Stephen Court, 18–21 St. Stephen’s Green, Dublin 2, Ireland.

Intercom enables us to contact visitors to our website, process enquiries and manage communication histories. In particular, name, email address, message content, chat histories, IP address, device and browser information, usage data, timestamps and technical metadata may be processed.

The processing of content entered in the chat or messenger is carried out on the basis of Art. 6(1)(b) GDPR insofar as this is necessary for contract initiation or contract performance. In all other cases, processing is based on our legitimate interest in effective and user-friendly communication pursuant to Art. 6(1)(f) GDPR. Where Intercom uses cookies or comparable technologies for analysis or marketing purposes, processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Intercom also processes data in the USA. According to Intercom, it participates in the EU-US Data Privacy Framework.

Registration on this website

You can register on this website in order to use additional functions. We use the data entered for this purpose only for the use of the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full; otherwise, we will reject the registration.

For important changes, for example to the scope of the offer or technically necessary changes, we use the email address provided during registration to inform you. The processing of the data entered during registration is carried out for the purpose of implementing the user relationship established by the registration and, where applicable, for initiating further contracts pursuant to Art. 6(1)(b) GDPR.

12. HOSTING AND CONTENT DELIVERY NETWORKS (CDN)

In order to provide our online offering securely and efficiently, we use the services of one or more web hosting providers. For these purposes, infrastructure and platform services, computing capacity, storage space, database services, security services and technical maintenance services may be used.

Raidboxes

We host our website with Raidboxes. The provider is Raidboxes GmbH, Hafenstraße 32, 48153 Münster, Germany. Raidboxes collects technical access data in the course of providing our website, including IP addresses, log files, browser information and access times. Processing is carried out for the secure and reliable provision of our website.

The use of Raidboxes is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, high-performance and reliable provision of our online offering. We have concluded a data processing agreement with Raidboxes.

dogado

We also use hosting and infrastructure services provided by dogado GmbH, Antonio-Segni-Straße 11, 44263 Dortmund, Germany. When you visit our website, dogado may process technical data, in particular IP addresses, log files, browser information, server requests and access times. Processing serves the provision, security and stability of our online offering.

The use is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable provision of our website. We have concluded a data processing agreement with dogado.

13. SOCIAL MEDIA

Social media elements with Shariff

This website uses elements of social media, for example Facebook, Twitter, Instagram, Pinterest, XING, LinkedIn and Tumblr. The social media elements can usually be recognised by the respective social media logos. To ensure data protection on this website, we use these elements only together with the so-called Shariff solution. This application prevents the social media elements integrated on this website from transferring your personal data to the respective provider as soon as you first enter the website.

Only when you activate the respective social media element by clicking the associated button is a direct connection to the provider’s server established. As soon as you activate the social media element, the respective provider receives the information that you have visited this website with your IP address. Activating the plugin constitutes consent within the meaning of Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Facebook

Elements of the Facebook social network are integrated on this website. The provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, collected data is also transferred to the USA and other third countries. If the social media element is active, a direct connection is established between your end device and Facebook’s server.

Where consent has been obtained, the service is used on the basis of Art. 6(1)(a) GDPR and Section 25 TDDDG. Where no consent has been obtained, use is based on our legitimate interest in achieving the broadest possible visibility in social media. In certain cases, we and Meta Platforms Ireland Limited are jointly responsible for the collection and forwarding of data to Facebook pursuant to Art. 26 GDPR.

Instagram

Functions of the Instagram service are integrated on this website. These functions are offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. If the social media element is active, a direct connection is established between your end device and Instagram’s server. Instagram thereby receives information about your visit to this website.

Where consent has been obtained, the service is used on the basis of Art. 6(1)(a) GDPR and Section 25 TDDDG. Where no consent has been obtained, use is based on our legitimate interest in achieving the broadest possible visibility in social media. In certain cases, we and Meta Platforms Ireland Limited are jointly responsible for the collection and forwarding of data to Facebook or Instagram pursuant to Art. 26 GDPR.

LinkedIn

This website uses elements of the LinkedIn network. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. Whenever a page of this website containing LinkedIn elements is accessed, a connection to LinkedIn servers is established. LinkedIn is informed that you have visited this website using your IP address.

Where consent has been obtained, the service is used on the basis of Art. 6(1)(a) GDPR and Section 25 TDDDG. Where no consent has been obtained, use is based on our legitimate interest in achieving the broadest possible visibility in social media.

WhatsApp

This website uses elements of the WhatsApp messenger service. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Whenever a page of this website containing WhatsApp elements is accessed, a connection to WhatsApp servers may be established. WhatsApp is thereby informed that you have visited this website with your IP address.

Where consent has been obtained, the service is used on the basis of Art. 6(1)(a) GDPR and Section 25 TDDDG. Where no consent has been obtained, use is based on our legitimate interest in simple communication and broad visibility in social media.

14. ANALYSIS TOOLS AND ADVERTISING

Google Analytics

This website uses functions of the Google Analytics web analytics service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables the website operator to analyse the behaviour of website visitors. The website operator receives various usage data, such as page views, length of stay, operating systems used and the origin of the user.

Google Analytics uses technologies that enable recognition of the user for the purpose of analysing user behaviour, such as cookies or device fingerprinting. The information collected by Google about the use of this website is usually transferred to a Google server in the USA and stored there. The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be revoked at any time.

Browser plugin

You can prevent the collection and processing of your data by Google by downloading and installing the browser plugin provided by Google.

Google Ads

The website operator uses Google Ads. Google Ads is an online advertising program provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads enables us to display advertisements in the Google search engine or on third-party websites when users enter certain search terms on Google. Targeted advertisements can also be displayed based on user data available to Google.

The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be revoked at any time.

Google Conversion Tracking

This website uses Google Conversion Tracking. The provider is Google Ireland Limited. Google Conversion Tracking enables Google and us to recognise whether a user has performed certain actions. We can, for example, evaluate which buttons on our website are clicked and how often, and which products are viewed or purchased particularly frequently. We do not receive information that personally identifies users.

Google Call Conversion Tracking

We use Google Call Conversion Tracking on our website. If you access our website via a Google advertisement, the telephone number displayed on the website may be replaced by a forwarding number provided by Google. This enables us to record whether a visit generated via Google Ads resulted in a phone call. Call contents are not recorded.

Google Tag Manager

We use Google Tag Manager from Google. This tag manager allows us to centrally integrate and manage code sections from various tracking tools that we use on our website. We have a legitimate interest in analysing the behaviour of website visitors and improving our offering technically and economically. The legal basis is Art. 6(1)(f) GDPR.

Google Ads Remarketing

This website uses the functions of Google Ads Remarketing. The provider is Google Ireland Limited. Google Ads Remarketing allows us to assign people who interact with our online offering to certain target groups in order to subsequently display interest-based advertising to them in the Google advertising network.

The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be revoked at any time.

Meta Pixel (formerly Facebook Pixel)

This website uses Meta’s visitor action pixel for conversion measurement. The provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. This allows the behaviour of site visitors to be tracked after they have been redirected to the provider’s website by clicking on a Facebook advertisement. The collected data is anonymous for us as the operator of this website, but Facebook may store and process the data so that a connection to the respective user profile is possible.

The use of this service is based on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. We use the advanced matching function within the Meta Pixel, which enables us to transmit certain customer and prospect data collected via our website to Meta in hashed or otherwise protected form where applicable.

Sentry

To provide you with a reliable and secure service, we use the error management tool Sentry. The service provider is Functional Software, Inc., 132 Hawthorne Street, San Francisco, CA 94107, USA. This tool helps us efficiently detect and resolve errors on our website in order to improve the stability and user-friendliness of our services. Processing is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR.

Microsoft Clarity

This website uses Microsoft Clarity. The provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Microsoft Clarity enables us to evaluate user behaviour on our website. In particular, page views, clicks, scrolling behaviour, technical browser and device information, referrer URL, IP address and interactions with the website may be processed.

The use of Microsoft Clarity is based exclusively on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent may be revoked at any time.

LinkedIn Insight Tag

This website uses the LinkedIn Insight Tag. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. The LinkedIn Insight Tag enables us to determine whether users perform certain actions on our website after clicking on a LinkedIn advertisement. IP address, device and browser information, timestamps, page views, referrer URL and campaign information may be processed.

The use of the LinkedIn Insight Tag is based exclusively on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Leadinfo

This website uses Leadinfo. The provider is Leadinfo B.V., Rotterdam, Netherlands. Leadinfo enables us to identify companies that visit our website by comparing the visitor’s IP address with publicly accessible company databases. This allows us to determine whether a specific company has visited our website and which pages were accessed. Direct identification of individual natural persons by us is not intended.

The use of Leadinfo is based on our legitimate interest pursuant to Art. 6(1)(f) GDPR in analysing business website visits, optimising our offering and addressing business prospects in a targeted manner. Where Leadinfo uses cookies or comparable technologies, processing is carried out on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Kissmetrics

This website uses Kissmetrics. The provider is Kissmetrics or Sandstorm Analytics, Inc., USA. Kissmetrics is an analysis and tracking service that allows us to evaluate the use of our website, user interactions, campaigns and conversion events. In particular, IP address, browser and device information, timestamps, page views, referrer URL, campaign information, interactions and cookie or user identifiers may be processed.

Kissmetrics uses cookies, pixels, web beacons and comparable technologies to record user interactions and recognise returning visits. The use of Kissmetrics is based exclusively on your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

15. NEWSLETTER

Newsletter data

If you would like to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and agree to receive the newsletter. Further data is not collected, or is collected only on a voluntary basis. We use newsletter service providers for the processing of newsletters, as described below.

Brevo

This website uses Brevo to send newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. Brevo is a service that can be used to organise and analyse newsletter distribution. If you enter data for the purpose of receiving the newsletter, in particular your email address, this data is processed on Brevo’s servers.

With the help of Brevo, we can analyse our newsletter campaigns. In particular, it can be evaluated whether a newsletter message was opened and which links were clicked. Processing is based on your consent pursuant to Art. 6(1)(a) GDPR. Where Brevo uses cookies, tracking pixels or comparable technologies, processing is additionally based on Section 25(1) TDDDG. You may revoke your consent at any time by unsubscribing from the newsletter.

16. PLUGINS AND TOOLS

Google APIs

Various Google APIs are used on our website to provide interactive functions and content. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The APIs used may include, among others, the Google Maps API, Google Fonts API or ajax.googleapis.com.

When our website is accessed, data, including your IP address and information about your end device, is transmitted to Google servers in order to technically provide the requested functions. Use is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the technically reliable and user-friendly provision of interactive functions and content. Where consent has been requested, processing is additionally based on Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

Adobe Fonts

This website uses web fonts from Adobe for the uniform display of certain fonts. The provider is Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA. When you access this website, your browser loads the required fonts directly from Adobe so that they can be displayed correctly on your end device. This establishes a connection to Adobe servers in the USA.

The storage and analysis of data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the uniform presentation of the typeface on the website. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Google reCAPTCHA

We use Google reCAPTCHA on this website. The provider is Google Ireland Limited. reCAPTCHA is used to check whether data entered on this website, for example in a contact form, is entered by a human or by an automated program. For this purpose, reCAPTCHA analyses the behaviour of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters the website.

The reCAPTCHA analyses may run completely in the background. Website visitors are not advised separately that an analysis is taking place. The use of reCAPTCHA is intended to protect our online offerings from abusive automated spying and spam. Processing is based on Art. 6(1)(f) GDPR; where consent has been requested, processing is based exclusively on Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Wistia

This website may use Wistia to embed and display video content. The provider is Wistia, Inc., 120 Brookline Street, Cambridge, MA 02139, USA. When you access a page with embedded Wistia videos, a connection to Wistia servers may be established. In this context, IP addresses, device and browser information, usage data and interactions with the video content may be processed.

The use of Wistia is based on our legitimate interest in an appealing presentation of our online offering pursuant to Art. 6(1)(f) GDPR. Where consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Trustindex

This website may use Trustindex to display customer reviews and ratings. The provider is Trustindex Ltd. When review widgets are integrated, technical data such as IP address, browser information, device information and access times may be transmitted to Trustindex. If you interact with the widget, further data may be processed.

The use of Trustindex is based on our legitimate interest in the transparent presentation of customer reviews and the promotion of trust in our services pursuant to Art. 6(1)(f) GDPR. Where consent has been requested, processing is carried out on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Wordfence Security

We use Wordfence Security to protect our website. Wordfence is a security plugin for WordPress websites. The provider is Defiant Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA. Wordfence is used to protect our website from unwanted access, malware, brute-force attacks and other security threats. For this purpose, IP addresses, access data, browser information and other technical data may be processed.

The use of Wordfence is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure operation of our website and protection against cyberattacks. Where consent has been requested, processing is carried out on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

17. ECOMMERCE AND PAYMENT PROVIDERS

Processing of customer and contract data

We collect, process and use personal customer and contract data for the establishment, content arrangement and modification of our contractual relationships. We collect, process and use personal data concerning the use of this website only insofar as this is necessary to enable the user to use the service or to bill for it.

The legal basis is Art. 6(1)(b) GDPR. The customer data collected will be deleted after completion of the order or termination of the business relationship and expiry of any statutory retention periods.

Data transmission upon conclusion of contracts for services and digital content

We transmit personal data to third parties only if this is necessary in the context of contract processing, for example to the payment service provider commissioned with payment processing. Further transmission of data does not take place unless you have expressly consented to the transmission. Your data will not be passed on to third parties without express consent, for example for advertising purposes.

The legal basis for data processing is Art. 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures.

Payment services

We integrate payment services from third-party companies on our website. When you make a purchase from us, your payment data, such as name, payment amount, account details, credit card number or similar payment information, is processed by the payment service provider for the purpose of payment processing.

The respective contractual and data protection provisions of the respective providers apply to these transactions. The use of payment service providers is based on Art. 6(1)(b) GDPR and on our legitimate interest in a smooth, convenient and secure payment process pursuant to Art. 6(1)(f) GDPR. Where your consent is requested for certain actions, Art. 6(1)(a) GDPR is the legal basis; consent may be revoked at any time with effect for the future.

Google Pay

We offer payment via Google Pay. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. If you select payment via Google Pay, the payment data you enter will be transmitted to Google for payment processing. The use of Google Pay is based on Art. 6(1)(b) GDPR and our legitimate interest in offering a convenient payment method.

PayPal

We offer payment via PayPal. The provider of this payment service is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. If you select payment via PayPal, the payment data you enter will be transmitted to PayPal. Data may also be transferred to the USA. The use of PayPal is based on Art. 6(1)(b) GDPR and our legitimate interest in offering a convenient and secure payment method.

Shopify Payment

We use Shopify Payment for payment processing. Shopify Payment enables us to accept various payment methods. Depending on the payment method selected, the data required for payment processing is transmitted to Shopify or the respective payment providers. Processing is carried out on the basis of Art. 6(1)(b) GDPR and our legitimate interest in secure and efficient payment processing.

Mastercard

We offer payment by Mastercard. The provider is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium. If you pay by Mastercard, the payment data required for payment processing is transmitted to Mastercard. Processing is based on Art. 6(1)(b) GDPR.

VISA

We offer payment by VISA. The provider is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom. If you pay by VISA, the payment data required for payment processing is transmitted to VISA. Processing is based on Art. 6(1)(b) GDPR.

American Express

We offer payment by American Express. The provider is American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany. If you pay by American Express, the payment data required for payment processing is transmitted to American Express. Processing is based on Art. 6(1)(b) GDPR.

Klarna

We offer payment via Klarna. The provider is Klarna Bank AB, Sveavägen 46, 111 34 Stockholm, Sweden. Klarna may process personal data such as contact details, order data, payment data and, where applicable, creditworthiness data in order to process payment. Processing is carried out on the basis of Art. 6(1)(b) GDPR and our legitimate interest in offering flexible payment options.

Stripe

We offer payment via Stripe. The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe processes payment data for the purpose of payment processing. Processing is carried out on the basis of Art. 6(1)(b) GDPR and our legitimate interest in secure and efficient payment processing.

Handling of applicant data

We offer you the opportunity to apply to us, for example by email, post or via an online application form. Below we inform you about the scope, purpose and use of your personal data collected as part of the application process. We assure you that your data will be collected, processed and used in accordance with applicable data protection law and all other statutory provisions and will be treated as strictly confidential.

Scope and purpose of data collection

If you send us an application, we process your associated personal data, for example contact and communication data, application documents, notes from interviews and similar data, insofar as this is necessary to decide on the establishment of an employment relationship. The legal basis is Section 26 BDSG under German law, Art. 6(1)(b) GDPR and, where applicable, Art. 6(1)(f) GDPR. If you give consent, processing may also be based on Art. 6(1)(a) GDPR.

Data retention period

If we cannot offer you a position, if you reject a job offer, if you withdraw your application, revoke your consent to data processing or request deletion, the data you have submitted, including any remaining physical application documents, will be stored or retained for a limited period after completion of the application process in order to be able to trace the details of the application process in the event of disputes. Statutory retention obligations remain unaffected.

Admission to the applicant pool

If we do not offer you a position, there may be an option to include you in our applicant pool. If you are included, all documents and information from the application will be transferred to the applicant pool so that we can contact you in the event of suitable vacancies. Inclusion in the applicant pool takes place exclusively on the basis of your express consent pursuant to Art. 6(1)(a) GDPR. Consent is voluntary and has no relation to the current application process. You may revoke your consent at any time.

Currency and amendment of this privacy policy

This privacy policy is currently valid and may be amended from time to time. Due to the further development of our website and offers or due to changed legal or official requirements, it may become necessary to amend this privacy policy. The current privacy policy can be accessed on our website at any time.