Table of Contents
- Introduction and Overview
- Scope of Application
- Legal Basis
- Contact Information for the Data Controller
- Retention period
- Rights Under the General Data Protection Regulation
- Data Transfer to Third Countries
- Data Processing Security
- Communication
- Data Processing Agreement (DPA)
- Cookies
- Web Hosting Introduction
- Web Design Introduction
- Explanation of Terms Used
- Closing Remarks
Introduction and Overview
We have prepared this Privacy Policy (Version 04/14/2023-111824141) to explain to you, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (hereinafter “data”) we, as the data controller—and the data processors we engage (e.g., service providers)—process, will process in the future, and what legal rights you have. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, is designed to explain the most important points to you as simply and transparently as possible. Where it promotes transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and graphics are used. We use clear and simple language to explain that, in the course of our business activities, we process personal data only when there is a corresponding legal basis for doing so. This certainly isn’t possible if we provide explanations that are as brief, unclear, and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps you’ll discover a piece of information or two that you weren’t aware of before.
If you still have questions, please contact the responsible party listed below or in the legal notice, follow the provided links, and review additional information on third-party websites. You can, of course, also find our contact information in the legal notice.
Scope of Application
This Privacy Policy applies to all personal data processed by us within the company and to all personal data processed by companies we have engaged (data processors). By “personal data,” we mean information as defined in Article 4(1) of the GDPR, such as a person’s name, email address, and mailing address. The processing of personal data enables us to offer and bill for our services and products, whether online or offline. The scope of this Privacy Policy includes:
- All online platforms (websites, online stores) that we operate
- Social Media Presence and Email Communication
- Mobile apps for smartphones and other devices
In short: This Privacy Policy applies to all areas in which personal data is processed in a structured manner within the company through the channels mentioned. Should we enter into a legal relationship with you outside of these channels, we will inform you separately if necessary.
Legal Basis
In the following Privacy Policy, we provide you with transparent information regarding the legal principles and regulations—that is, the legal basis under the General Data Protection Regulation—that enable us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the portal for EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.
We process your data only if at least one of the following conditions applies:
- Consent (Article 6(1)(a) of the GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
- Contract (Article 6(1)(b) of the GDPR): We process your data to fulfill a contract or pre-contractual obligations with you. For example, when we enter into a purchase agreement with you, we need certain personal information in advance.
- Legal Obligation (Article 6(1)(c) of the GDPR): We process your data when we are subject to a legal obligation to do so. For example, we are legally required to retain invoices for accounting purposes. These invoices generally contain personal data.
- Legitimate Interests (Article 6(1)(f) of the GDPR): In cases where legitimate interests do not infringe upon your fundamental rights, we reserve the right to process personal data. For example, we must process certain data in order to operate our website securely and cost-effectively. This processing therefore constitutes a legitimate interest.
Other conditions, such as the collection of data in the public interest, the exercise of official authority, and the protection of vital interests, generally do not apply to us. Should such a legal basis nevertheless be relevant, it will be indicated in the appropriate section.
In addition to the EU regulation, national laws also apply:
- In Austria, this is the Federal Act on the Protection of Natural Persons with Regard to the Processing of Personal Data (Data Protection Act), or DSG for short.
- In Germany, the Federal Data Protection Act( BDSG) applies.
If any additional regional or national laws apply, we will provide you with information about them in the following sections.
Contact Information for the Data Controller
If you have any questions regarding data protection or the processing of personal data, please find the contact information for the responsible person or department below:
AdSimple GmbH
Fabriksgasse 20, 2230 Gänserndorf, Austria
Email: [email protected]
Phone: +43 2282 / 60 715
Legal Notice: https://www.adsimple.at/impressum/
Retention period
It is a general principle for us that we store personal data only for as long as is strictly necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing it no longer exists. In some cases, we are legally required to retain certain data even after the original purpose has ceased to exist, for example, for accounting purposes.
If you wish to have your data deleted or wish to revoke your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.
We will provide you with information below regarding the specific duration of each data processing activity, provided we have further details on the matter.
Rights Under the General Data Protection Regulation
In accordance with Articles 13 and 14 of the GDPR, we are informing you of the following rights to which you are entitled to ensure that your data is processed in a fair and transparent manner:
- Under Article 15 of the GDPR, you have the right to know whether we process any of your personal data. If we do, you have the right to receive a copy of that data and to be provided with the following information:
- the purpose for which we process the data;
- the categories, that is, the types of data that are processed;
- who receives this data, and if the data is transferred to third countries, how security can be ensured;
- how long the data is stored;
- the existence of the right to rectification, erasure, or restriction of processing, and the right to object to processing;
- that you can file a complaint with a supervisory authority (links to these authorities are provided below);
- the source of the data, if we did not collect it from you;
- whether profiling is carried out—that is, whether data is automatically analyzed to create a personal profile of you.
- Under Article 16 of the GDPR, you have the right to have your data corrected, which means that we must correct any data if you find errors.
- Under Article 17 of the GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you may request the erasure of your data.
- Under Article 18 of the GDPR, you have the right to restrict processing, which means that we may only store the data but may not use it further.
- Under Article 20 of the GDPR, you have the right to data portability, which means that, upon request, we will provide you with your data in a commonly used format.
- Under Article 21 of the GDPR, you have the right to object, which, once exercised, will result in a change to how your data is processed.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then review as soon as possible whether we can legally comply with this objection.
- If your data is used for direct marketing, you may object to this type of data processing at any time. After that, we may no longer use your data for direct marketing.
- If your data is used for profiling, you may object to this type of data processing at any time. After that, we may no longer use your data for profiling.
- Under certain circumstances, pursuant to Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing (such as profiling).
- Under Article 77 of the GDPR, you have the right to lodge a complaint. This means that you may file a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.
In short: You have rights—don’t hesitate to contact the responsible party listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you may file a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
Austrian Data Protection Authority
Director: Mag . Dr. Andrea Jelinek
Address: Barichgasse 40-42, 1030 Vienna
Phone: +43 1 52 152-0
Email address:
[email protected]
Website:
https://www.dsb.gv.at/
Data Transfer to Third Countries
We transfer or process data to countries outside the EU (third countries) only if you consent to such processing, if it is required by law, or if it is contractually necessary—and in any case, only to the extent generally permitted. In most cases, your consent is the primary reason we have data processed in third countries. The processing of personal data in third countries such as the United States—where many software providers offer services and have their server locations—may mean that personal data is processed and stored in unexpected ways.
We expressly point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. Data processing by U.S. services (such as Google Analytics) may result in data being processed and stored without being anonymized. Furthermore, U.S. government authorities may, in some cases, gain access to specific data. In addition, collected data may be linked to data from other services provided by the same provider, provided you have a corresponding user account. Whenever possible, we strive to use server locations within the EU, if such options are available.
We provide more detailed information about data transfers to third countries, where applicable, in the relevant sections of this Privacy Policy.
Data Processing Security
To protect personal data, we have implemented both technical and organizational measures. Whenever possible, we encrypt or pseudonymize personal data. By doing so, we make it as difficult as possible—within the limits of our capabilities—for third parties to infer personal information from our data.
Article 25 of the GDPR refers to “data protection through technology design and privacy-friendly default settings,” meaning that security must always be a priority—whether in software (e.g., forms) or hardware (e.g., access to the server room)—and appropriate measures must be implemented. Below, we will discuss specific measures as needed.
TLS Encryption with HTTPS
TLS, encryption, and HTTPS sound very technical—and they are. We use HTTPS (which stands for “Hypertext Transfer Protocol Secure”) to transmit data over the Internet in a way that’s secure against eavesdropping.
This means that the entire transmission of all data from your browser to our web server is secure—no one can “eavesdrop.”
This allows us to introduce an additional layer of security and comply with data protection through design (Article 25(1) of the GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the Internet, we can ensure the protection of confidential data.
You can tell that this data transmission security measure is in use by the small padlock icon in the upper-left corner of the browser, to the left of the web address (e.g., examplepage.de) and the use of the https scheme (instead of http) as part of our web address.
If you'd like to learn more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find useful links to additional information.
Communication
| Communication Summary: Data Subjects: Anyone who communicates with us by phone, email, or online form Data Processed: e.g., phone number, name, email address, form data entered. You can find more details under the respective contact method Purpose: Handling communication with customers, business partners, etc. Retention period: Duration of the business transaction and as required by law ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests) |
If you contact us and communicate with us by phone, email, or through our online form, we may process your personal data.
The data will be processed for the purpose of handling and addressing your inquiry and the related business transaction. The data will be stored for as long as necessary or as required by law.
Affected Individuals
The events mentioned above affect everyone who contacts us through the communication channels we provide.
Phone
When you call us, the call data is stored in pseudonymized form on the respective device and with the telecommunications provider used. In addition, data such as your name and phone number may subsequently be sent via email and stored for the purpose of responding to your inquiry. The data will be deleted as soon as the business transaction has been completed and legal requirements permit it.
When you communicate with us via email, data may be stored on your device (computer, laptop, smartphone, etc.) and on the email server. The data will be deleted as soon as the business matter has been resolved and legal requirements permit.
Online Forms
When you contact us via the online form, your data is stored on our web server and, if necessary, forwarded to one of our email addresses. The data will be deleted as soon as the business matter has been resolved and legal requirements permit.
Legal Basis
The processing of data is based on the following legal grounds:
- Art. 6(1)(a) of the GDPR (Consent): You give us your consent to store your data and to use it for purposes related to the business transaction;
- Art. 6(1)(b) of the GDPR (Contract): It is necessary for the performance of a contract with you or a processor, such as a telephone service provider, or we need to process the data for pre-contractual activities, such as preparing a quote;
- Art. 6(1)(f) of the GDPR (Legitimate Interests): We aim to handle customer inquiries and business communications in a professional manner. To do so, certain technical systems—such as email programs, Exchange servers, and mobile network providers—are necessary to ensure efficient communication.
Data Processing Agreement (DPA)
In this section, we’d like to explain what a data processing agreement is and why it’s necessary. Since the term “data processing agreement” is quite a mouthful, we’ll often use the acronym DPA throughout this text. Like most companies, we don’t operate alone; we also use services provided by other companies or individuals. By involving various companies or service providers, we may need to transfer personal data to them for processing. These partners then act as data processors, with whom we enter into a contract known as a Data Processing Agreement (DPA). The most important thing for you to know is that the processing of your personal data takes place exclusively in accordance with our instructions and must be governed by the DPA.
Who are data processors?
As a company and website owner, we are responsible for all data we process from you. In addition to the data controllers, there may also be so-called data processors. This includes any company or individual that processes personal data on our behalf. More specifically, and according to the GDPR definition: any natural or legal person, public authority, agency, or other body that processes personal data on our behalf is considered a data processor. Processors can therefore include service providers such as hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
To help clarify the terminology, here is an overview of the three roles under the GDPR:
Data subject(you as a customer or prospective customer) → Data controller (we as a company and data controller) → Data processor (service providers such as web hosting providers or cloud service providers)
Contents of a Data Processing Agreement
As mentioned above, we have entered into a Data Processing Agreement (DPA) with our partners who act as data processors. Above all, this agreement stipulates that the data processor shall process the data exclusively in accordance with the GDPR. The agreement must be concluded in writing; however, in this context, an electronic agreement is also considered “in writing.” The processing of personal data takes place only on the basis of this agreement. The agreement must include the following:
- Commitment to Us as the Data Controller
- Obligations and Rights of the Data Controller
- Categories of Data Subjects
- Type of Personal Data
- Nature and Purpose of Data Processing
- Purpose and Duration of Data Processing
- Location of Data Processing
Furthermore, the contract sets forth all of the data processor’s obligations. The most important obligations are:
- Measures to ensure data security
- to take all necessary technical and organizational measures to protect the rights of the data subject
- to maintain a data processing register
- to cooperate with the data protection supervisory authority at its request
- to conduct a risk analysis with respect to the personal data received
- Sub-processors may only be engaged with the written authorization of the controller.
You can see what an AVV actually looks like, for example, at https://www.wko.at/service/wirtschaftsrecht-gewerberecht/eu-dsgvo-mustervertrag-auftragsverarbeitung.html. A sample contract is provided there.
Cookies
| Cookies Summary: Data Subjects: Visitors to the website Purpose: Depends on the specific cookie. For more details, see below or contact the software provider that sets the cookie. Data Processed: Depends on the specific cookie used. For more details, see below or contact the software provider that sets the cookie. Retention period: Depends on the specific cookie; may vary from hours to years ⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests) |
What are cookies?
Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used, so that you can better understand the following privacy policy.
Whenever you browse the Internet, you use a browser. Some well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.
One thing is undeniable: Cookies are really useful little helpers. Almost all websites use cookies. More specifically, they are HTTP cookies, since there are other types of cookies for different applications. HTTP cookies are small files that our website stores on your computer. These cookie files are automatically placed in the cookie folder—essentially the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.
Cookies store certain user data about you, such as your language or personal page settings. When you visit our site again, your browser sends this “user-specific” information back to our site. Thanks to cookies, our website knows who you are and provides you with the settings you’re used to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.
The following diagram illustrates a possible interaction between a web browser—such as Chrome—and a web server. In this scenario, the web browser requests a website and receives a cookie from the server, which the browser then uses again the next time a different page is requested.
There are both first-party cookies and third-party cookies. First-party cookies are created directly by our site, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans, or other “malware.” Cookies also cannot access information on your computer.
Here's an example of what cookie data might look like:
Name: _ga
Value:GA1.2.1326744211.152111824141-9
Purpose: To distinguish between website visitors
Expiration date:After 2 years
A browser should be able to support these minimum sizes:
- At least 4,096 bytes per cookie
- At least 50 cookies per domain
- At least 3,000 cookies in total
What types of cookies are there?
The specific cookies we use depend on the services we employ and are explained in the following sections of this Privacy Policy. At this point, we would like to briefly discuss the different types of HTTP cookies.
There are four types of cookies:
Essential Cookies
These cookiesare necessary to ensure the website’s basic functionality. For example, these cookies are needed when a user adds a product to the shopping cart, then continues browsing other pages, and only proceeds to checkout later. These cookies ensure that the shopping cart is not cleared, even if the user closes their browser window.
Functional Cookies
These cookies collect information about user behavior and whether the user receives any error messages. They are also used to measure the website's loading time and performance across different browsers.
Functional Cookies
These cookies improve the user experience. For example, they store locations, font sizes, or form data that you have entered.
Advertising Cookies
These cookies are also called targeting cookies. They are used to deliver personalized ads to users. This can be very convenient, but it can also be very annoying.
Usually, when you visit a website for the first time, you'll be asked which of these types of cookies you want to allow. And, of course, this decision is also stored in a cookie.
If you'd like to learn more about cookies and don't mind reading technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments titled “HTTP State Management Mechanism.”
Purpose of Processing via Cookies
The purpose ultimately depends on the specific cookie. You can find more details below or by contacting the manufacturer of the software that sets the cookie.
What data is processed?
Cookies are small tools that help with a wide variety of tasks. Unfortunately, it is not possible to generalize about what data is stored in cookies, but we will inform you about the data that is processed or stored in the following privacy policy.
Cookie Retention Period
The storage period depends on the specific cookie and is explained in more detail below. Some cookies are deleted after less than an hour, while others may remain stored on a computer for several years.
You also have control over how long cookies are stored. You can manually delete all cookies at any time through your browser (see also “Right to Object” below). Furthermore, cookies that are based on your consent will be deleted no later than when you revoke your consent, although the lawfulness of their storage up to that point remains unaffected.
Right to Object – How Can I Delete Cookies?
You decide for yourself whether and how you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable, or allow only some cookies. For example, you can block third-party cookies but allow all other cookies.
If you want to see which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find these options in your browser settings:
Chrome: Delete, Enable, and Manage Cookies in Chrome
Safari: Managing Cookies and Website Data with Safari
Firefox: Clear cookies to remove data that websites have stored on your computer
Internet Explorer: Deleting and Managing Cookies
Microsoft Edge: Deleting and Managing Cookies
If you do not want to accept cookies at all, you can configure your browser to notify you whenever a cookie is about to be set. This allows you to decide for each individual cookie whether to allow it or not. The procedure varies depending on the browser. The best approach is to search for instructions on Google using the search terms “delete cookies Chrome” or “disable cookies Chrome” if you are using the Chrome browser.
Legal Basis
The so-called “Cookie Directives” have been in effect since 2009. They stipulate that the storage of cookies requires your consent (Article 6(1)(a) of the GDPR). However, reactions to these directives still vary widely among EU countries. In Austria, however, this directive was implemented in Section 96(3) of the Telecommunications Act (TKG). In Germany, the Cookie Directive was not transposed into national law. Instead, it was largely implemented in Section 15(3) of the Telemedia Act (TMG).
For strictly necessary cookies, even in the absence of consent, there are legitimate interests (Article 6(1)(f) of the GDPR), which are, in most cases, of an economic nature. We want to provide website visitors with a pleasant user experience, and certain cookies are often absolutely necessary to achieve this.
Unless strictly necessary cookies are used, this will only occur with your consent. The legal basis for this is Article 6(1)(a) of the GDPR.
The following sections provide more detailed information about the use of cookies, to the extent that the software used employs cookies.
Web Hosting Introduction
| Web Hosting Summary: Data Subjects: Visitors to the website Purpose: Professional hosting of the website and ensuring its operation Data Processed: IP address, time of website visit, browser used, and other data. More details can be found below or with the respective web hosting provider. Retention period: Depends on the respective provider, but generally 2 weeks ⚖️ Legal basis: Art. 6(1)(f) GDPR (Legitimate Interests) |
What is web hosting?
When you visit websites these days, certain information—including personal data—is automatically generated and stored, and this is also the case on this website. This data should be processed as sparingly as possible and only for valid reasons. By “website,” we mean the entirety of all web pages on a domain, i.e., everything from the home page to the very last subpage (like this one). By “domain,” we mean, for example, example.de or sampleexample.com.
If you want to view a website on a computer, tablet, or smartphone, you use a program called a web browser. You’re probably familiar with the names of some web browsers: Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari. We refer to them simply as browsers or web browsers.
To display a website, the browser must connect to another computer where the website’s code is stored: the web server. Operating a web server is a complex and resource-intensive task, which is why it’s usually handled by professional providers. These providers offer web hosting and ensure that website data is stored reliably and without errors. That’s a lot of technical terms, but please stick with it—it gets even better!
Personal data may be processed when the browser on your computer (desktop, laptop, tablet, or smartphone) establishes a connection and during the transfer of data to and from the web server. On the one hand, your computer stores data; on the other hand, the web server must also store data for a certain period of time to ensure proper operation.
A picture is worth a thousand words, so the following diagram illustrates the interaction between the browser, the Internet, and the hosting provider.
Why do we process personal data?
The purposes of data processing are:
- Professional website hosting and ensuring smooth operation
- to maintain operational and IT security
- Anonymous analysis of user behavior to improve our services and, if necessary, for law enforcement or the pursuit of legal claims
What data is processed?
Even as you are visiting our website right now, our web server—the computer on which this website is hosted—typically automatically stores data such as
- the complete web address (URL) of the webpage that was accessed
- Browser and browser version (e.g., Chrome 87)
- the operating system used (e.g., Windows 10)
- the address (URL) of the previously visited page (referrer URL) (e.g., https://www.beispielquellsite.de/vondabinichgekommen/)
- the hostname and IP address of the device from which the request is being made (e.g., COMPUTERNAME and 194.23.43.121)
- Date and Time
- in files known as web server log files
How long is data stored?
As a rule, the data listed above is stored for two weeks and then automatically deleted. We do not share this data with third parties; however, we cannot rule out the possibility that government authorities may access this data in the event of unlawful conduct.
In short: Your visit is logged by our provider (the company that hosts our website on special computers (servers)), but we will not share your data without your consent!
Legal Basis
The lawfulness of processing personal data in the context of web hosting is based on Article 6(1)(f) of the GDPR (protection of legitimate interests), as the use of professional hosting services from a provider is necessary to present the company on the Internet in a secure and user-friendly manner and, if necessary, to investigate any attacks or claims arising therefrom.
We generally have a contract with the hosting provider regarding data processing in accordance with Article 28 et seq. of the GDPR, which ensures compliance with data protection regulations and guarantees data security.
World4You Privacy Policy
For our World4You website, we use, among other things, a web hosting provider. The service provider is the Austrian company World4You Internet Services GmbH, Hafenstraße 35, 4020 Linz, Austria.
For more information about the data processed when using World4You, please see the Privacy Policy at https://www.world4you.com/de/unternehmen/datenschutzerklaerung.html.
Data Processing Agreement (DPA) World4You
In accordance with Article 28 of the General Data Protection Regulation (GDPR), we have entered into a Data Processing Agreement (DPA) with World4You (World4You Internet Services GmbH, Hafenstraße 35, 4020 Linz, Austria). You can read more about what a DPA is exactly—and, most importantly, what it must contain—in our general section titled “Data Processing Agreement (DPA).”
This agreement is required by law because World4You processes personal data on our behalf. It specifies that World4You may only process data it receives from us in accordance with our instructions and must comply with the GDPR. You can find the link to the Data Processing Agreement (DPA) at https://www.world4you.com/faq/de/dsgvo/faq.stellt-world4you-eine-vereinbarung-zur-auftragsverarbeitung-zur-verfuegung.html.
Web Design Introduction
| Web Design Privacy Policy SummaryData Subjects: Visitors to the website Purpose: To improve the user experience Data Processed: The specific data processed depends heavily on the services used. In most cases, this includes IP addresses, technical data, language settings, browser version, screen resolution, and browser name. You can find more details in the documentation for the respective web design tools used. Retention period: Depends on the tools used ⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests) |
What is web design?
We use various tools on our website to support our web design. Web design is not, as is often assumed, just about making our website look nice; it’s also about functionality and performance. But of course, achieving the right visual look for a website is also one of the main goals of professional web design. Web design is a subfield of media design and deals with the visual, structural, and functional design of a website. The goal of web design is to enhance your experience on our website. In web design jargon, this is referred to as user experience (UX) and usability. User experience encompasses all the impressions and experiences a website visitor has while on a website. Usability is a component of user experience. It refers to how user-friendly a website is. The primary focus here is on ensuring that content, subpages, or products are clearly structured so that you can find what you’re looking for quickly and easily. To provide you with the best possible experience on our website, we also use third-party web design tools. In this Privacy Policy, the “Web Design” category therefore includes all services that enhance the design of our website. These may include, for example, fonts, various plugins, or other integrated web design features.
Why do we use web design tools?
How you take in information on a website depends heavily on the site’s structure, functionality, and visual appeal. That’s why high-quality, professional web design has become increasingly important to us as well. We’re constantly working to improve our website and view this as an added service for you, our website visitors. Furthermore, an attractive and functional website also offers economic benefits for us. After all, you’ll only visit us and take advantage of our offerings if you feel completely at ease.
What data is stored by web design tools?
When you visit our website, web design elements may be embedded in our pages that can also process data. Exactly what data is involved depends, of course, largely on the tools used. Below, you can see exactly which tools we use for our website. For more detailed information about data processing, we also recommend that you read the respective privacy policies of the tools used. In most cases, these policies will explain what data is processed, whether cookies are used, and how long the data is retained. For example, when using fonts such as Google Fonts, information such as language settings, IP address, browser version, browser screen resolution, and browser name is automatically transmitted to Google’s servers.
Duration of Data Processing
How long data is processed varies greatly from case to case and depends on the web design elements used. For example, when cookies are used, the retention period can range from just one minute to a few years. Please educate yourself on this matter. To that end, we recommend reviewing our general section on cookies as well as the privacy policies of the tools used. There, you’ll typically find out exactly which cookies are used and what information is stored in them. Google Font files, for example, are stored for one year. This is intended to improve a website’s loading time. As a general rule, data is only retained for as long as necessary to provide the service. Data may also be stored for longer periods if required by law.
Right to Object
You also have the right and the option to revoke your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or via other opt-out features. You can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser. However, some data associated with web design elements (most commonly fonts) cannot be deleted quite so easily. This is the case when data is automatically collected the moment a page is loaded and transmitted to a third-party provider (such as Google). In such cases, please contact the support team of the respective provider. For Google, you can reach support at https://support.google.com/?hl=de.
Legal Basis
If you have consented to the use of web design tools, the legal basis for the corresponding data processing is this consent. Pursuant to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur when data is collected by web design tools. We also have a legitimate interest in improving the web design of our website. After all, this is the only way we can provide you with an attractive and professional website. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use web design tools to the extent that you have given your consent. We would like to emphasize this point once again here.
Information on specific web design tools—if available—can be found in the following sections.
Google Fonts Privacy Policy
| Google Fonts Privacy Policy SummaryData Subjects: Visitors to the website Purpose: To optimize our services Data Processed: Data such as IP addresses and CSS and font requests You can find more details below in this privacy policy. Retention period: Font files are stored by Google for one year ⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests) |
What are Google Fonts?
We use Google Fonts on our website. These are the “Google fonts” provided by Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.
You do not need to sign in or provide a password to use Google Fonts. Furthermore, no cookies are stored in your browser. The files (CSS, fonts) are retrieved via the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, requests for CSS and fonts are completely separate from all other Google services. If you have a Google account, you don’t need to worry that your Google account information will be transmitted to Google while you’re using Google Fonts. Google tracks the use of CSS (Cascading Style Sheets) and the fonts used and stores this data securely. We’ll take a closer look at exactly how this data is stored later on.
Google Fonts (formerly Google Web Fonts) is a collection of over 800 fonts that Googlemakes available to its users for free.
Many of these fonts are released under the SIL Open Font License, while others have been released under the Apache License. Both are free software licenses.
Why do we use Google Fonts on our website?
Google Fonts allows us to use fonts on our website without having to upload them to our own server. Google Fonts is a key component in maintaining the high quality of our website. All Google fonts are automatically optimized for the web, which saves data and is a major advantage, especially for use on mobile devices. When you visit our site, the small file size ensures fast loading times. Furthermore, Google Fonts are secure web fonts. Differences in rendering systems across various browsers, operating systems, and mobile devices can lead to errors. Such errors can sometimes cause text or entire web pages to appear distorted. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform issues with Google Fonts. Google Fonts supports all major browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). We use Google Fonts so that we can present our entire online service as attractively and consistently as possible.
What data does Google store?
When you visit our website, the fonts are loaded via a Google server. This external request results in data being transmitted to Google’s servers. This also allows Google to recognize that you—or rather, your IP address—are visiting our website. The Google Fonts API was developed to limit the use, storage, and collection of end-user data to what is necessary for the proper delivery of fonts. By the way, API stands for “Application Programming Interface” and serves, among other things, as a data transmitter in the software sector.
Google Fonts securely stores CSS and font requests on Google, ensuring they are protected. By analyzing the collected usage data, Google can determine how well individual fonts are being received. Google publishes the results on internal analytics pages, such as Google Analytics. In addition, Google uses data from its own web crawler to identify which websites use Google Fonts. This data is published in the Google Fonts BigQuery database. Business owners and developers use Google’s BigQuery web service to analyze and process large volumes of data.
However, it is important to note that every Google Font request automatically transmits information such as language settings, IP address, browser version, browser screen resolution, and browser name to Google’s servers. It is not clear whether this data is also stored, nor does Google provide clear information on this matter.
How long and where is the data stored?
Google stores requests for CSS assets on its servers—which are primarily located outside the EU—for one day. This allows us to use the fonts with the help of a Google stylesheet. A stylesheet is a formatting template that lets you quickly and easily change, for example, the design or font of a website.
Google stores font files for one year. Google’s goal is to improve the loading time of websites in general. When millions of websites link to the same fonts, they are cached after the first visit and appear immediately on all other websites visited later. Sometimes Google updates font files to reduce file size, increase language coverage, and improve design.
How can I delete my data or prevent it from being stored?
The data that Google stores for one day or one year cannot be easily deleted. The data is automatically transmitted to Google when you visit the page. To have this data deleted early, you must contact Google Support at https://support.google.com/?hl=de&tid=111824141. In this case, the only way to prevent data storage is to not visit our site.
Unlike other web fonts, Google gives us unrestricted access to all fonts. This means we have unlimited access to a vast selection of fonts, allowing us to get the most out of our website. For more information about Google Fonts and to find answers to other questions, visit https://developers.google.com/fonts/faq?tid=111824141. Although Google addresses data protection issues on that site, it does not provide truly detailed information about data storage. It is relatively difficult to obtain truly precise information from Google about the data it stores.
Legal Basis
If you have consented to the use of Google Fonts, the legal basis for the corresponding data processing is this consent. Pursuant to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, as may occur when such data is collected by Google Fonts.
We also have a legitimate interest in using Google Fonts to optimize our online service. The legal basis for this is Article 6(1)(f) of the GDPR (legitimate interests). However, we only use Google Fonts if you have given your consent.
Google processes your data in the United States, among other places. Please note that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the United States. This may entail various risks regarding the lawfulness and security of data processing.
Google uses so-called Standard Contractual Clauses (Art. 46, paras. 2 and 3 of the GDPR) as the basis for data processing by recipients located in third countries (outside the European Union, Iceland, Liechtenstein, and Norway—specifically, the United States) or for data transfers to those countries. Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through these clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the United States. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The Google Ads Data Processing Terms, which also correspond to the Standard Contractual Clauses for Google Fonts, can be found at https://business.safety.google/adsprocessorterms/.
You can also read about what data Google generally collects and how it is used at https://www.google.com/intl/de/policies/privacy/.
Explanation of Terms Used
We always strive to make our Privacy Policy as clear and understandable as possible. However, this isn’t always easy, especially when it comes to technical and legal topics. It often makes sense to use legal terms (such as “personal data”) or certain technical terms (such as “cookies” or “IP address”). However, we do not want to use these terms without providing an explanation. Below, you will find an alphabetical list of important terms we use that we may not have addressed sufficiently in the previous privacy policy. If these terms are taken from the GDPR and are definitions, we will also cite the relevant GDPR text here and, where appropriate, add our own explanations.
Regulatory Authority
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Supervisory Authority” means an independent public body established by a Member State in accordance with Article 51;
Explanation: “Supervisory authorities” are always independent government agencies that, in certain cases, also have the authority to issue directives. They are responsible for carrying out what is known as “state supervision” and are housed within ministries, specialized departments, or other government agencies. In Austria, there is an Austrian Data Protection Authority; in Germany, each federal state has its own data protection authority.
Data Processor
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Processor” means a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller;
Explanation: As a company and website owner, we are responsible for all data we process from you. In addition to the data controllers, there may also be so-called data processors. This includes any company or individual that processes personal data on our behalf. Data processors may therefore include, in addition to service providers such as tax advisors, hosting or cloud providers, payment or newsletter providers, or large companies such as Google or Microsoft.
Competent Supervisory Authority
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“affected supervisory authority” means a supervisory authority that is affected by the processing of personal data becausea)
the controller or the processor is established within the territory of the Member State of that supervisory authority,
b)
this processing has or may have a significant impact on data subjects residing in the Member State of this supervisory authority, or
c)
a complaint was filed with this supervisory authority;
Explanation: In Germany, each federal state has its own data protection supervisory authority. Therefore, if your company’s headquarters (main office) is located in Germany, the relevant supervisory authority for that federal state is generally your point of contact. In Austria, there is only one data protection supervisory authority for the entire country.
Consent
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Consent” of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, expressed in the form of a statement or other unambiguous affirmative action, by which the data subject indicates that he or she consents to the processing of personal data relating to him or her;
Explanation: On websites, this type of consent is typically obtained through a cookie consent tool. You’re probably familiar with it. Whenever you visit a website for the first time, you’re usually asked via a banner whether you agree to or consent to data processing. In most cases, you can also configure individual settings and thus decide for yourself which types of data processing you allow and which you do not. If you do not give your consent, no personal data about you may be processed. In principle, consent can of course also be given in writing—that is, not via a tool.
Personal Data
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“personal data”
any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
Explanation: Personal data is any data that can be used to identify you as an individual. This typically includes data such as:
- Name
- Address
- Email address
- Mailing Address
- Phone number
- Date of Birth
- Identification numbers such as Social Security number, tax identification number, ID card number, or student ID number
- Banking information such as account numbers, credit information, account balances, and much more.
According to the European Court of Justice (ECJ), your IP address is also considered personal data. IT experts can use your IP address to determine at least the approximate location of your device and, subsequently, identify you as the account holder. Therefore, storing an IP address also requires a legal basis under the GDPR. There are also so-called “special categories” of personal data that require special protection. These include:
- Racial and Ethnic Origin
- political views
- religious or ideological beliefs
- union membership
- genetic data, such as data obtained from blood or saliva samples
- Biometric data (information about psychological, physical, or behavioral characteristics that can identify a person).
Health data - Information about sexual orientation or sex life
Profiling
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Profiling” means any form of automated processing of personal data that consists of using such personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements;
Explanation: Profiling involves gathering various pieces of information about a person in order to learn more about that person. On the web, profiling is often used for advertising purposes or for credit checks. For example, web analytics and advertising analytics programs collect data about your behavior and interests on a website. This results in a specific user profile that can be used to deliver targeted advertising to a specific audience.
Person in Charge
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Controller” means the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union law or the law of the Member States, the controller or the specific criteria for its designation may be provided for by Union law or the law of the Member States;
Explanation: In our case, we are responsible for processing your personal data and are therefore the “data controller.” If we transfer collected data to other service providers for processing, those providers are “data processors.” A “Data Processing Agreement (DPA)” must be signed for this purpose.
Processing
Definition pursuant to Article 4 of the GDPR
For the purposes of this regulation, the term means:
“Processing”
any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, distribution, or any other form of disclosure; the matching or linking; the restriction, erasure, or destruction;
Note: When we refer to “processing” in our Privacy Policy, we mean any type of data processing. As mentioned above in the original GDPR statement, this includes not only the collection but also the storage and processing of data.
Closing Remarks
Congratulations! If you’re reading this, you’ve either really “battled your way through” our entire Privacy Policy or at least scrolled down to this point. As you can see from the length of our Privacy Policy, we take the protection of your personal data very seriously.
It’s important to us to inform you, to the best of our knowledge and belief, about the processing of personal data. In doing so, we don’t just want to tell you what data is processed, but also explain the reasons behind our use of various software programs. Privacy policies usually sound very technical and legal. However, since most of you aren’t web developers or lawyers, we wanted to take a different approach linguistically and explain the facts in simple and clear language. Of course, this isn’t always possible given the nature of the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions regarding data protection on our website, please do not hesitate to contact us or the data controller. We hope you continue to enjoy your visit and look forward to welcoming you back to our website soon.
All texts are protected by copyright.
Source: Created using AdSimple's Privacy Policy Generator





