Skip to main content

Privacy Policy

Here you will find information on how FunnelCAD handles your data in accordance with the GDPR.

Preamble​

With this Privacy Policy, we want to inform you about the types of personal data we process, for what purposes, and to what extent. This statement applies to all data processing carried out by us – whether within the scope of our services, on our websites, in mobile applications, or on external online presences such as our social media profiles.

Date: September 30, 2026

Controller​

Overview of Processing​

The following overview summarizes the types of data processed, the purposes of their processing, and refers to the data subjects.

Types of Processed Data​

  • Inventory data (stock data)
  • Payment data
  • Contact data
  • Content data
  • Contract data
  • Usage data
  • Meta, communication, and procedural data
  • Protocol data (log data)

Categories of Data Subjects​

  • Service recipients and clients
  • Prospects
  • Communication partners
  • Users
  • Business and contractual partners

Purposes of Processing​

  • Provision of contractual services and fulfillment of contractual obligations
  • Communication
  • Security measures
  • Direct marketing
  • Reach measurement
  • Tracking
  • Office and organizational procedures
  • Conversion measurement
  • Target group formation
  • Organizational and administrative procedures
  • Feedback
  • Marketing
  • Creation of profiles with user-related information
  • Provision of our online offering and ensuring user-friendliness
  • Operation of the information technology infrastructure
  • Public relations
  • Sales promotion
  • Support for business processes and commercial procedures

Relevant Legal Bases according to the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the GDPR regulations, national data protection requirements in your or our country of residence or establishment may also apply. Should more specific legal bases be relevant in individual cases, we will inform you of these in this privacy policy.

  • Consent (Art. 6 para. 1 sentence 1 lit. a GDPR): You have given your consent to the processing of your personal data for one or more specific purposes.
  • Performance of Contract and Pre-Contractual Inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR): Processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract.
  • Legal Obligation (Art. 6 para. 1 sentence 1 lit. c GDPR): Processing is necessary for compliance with a legal obligation.
  • Legitimate Interests (Art. 6 para. 1 sentence 1 lit. f GDPR): Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your rights.

National Data Protection Regulations in Germany: In addition, specific regulations apply in Germany, namely the Federal Data Protection Act (BDSG) – particularly regarding access, deletion, objection, processing of special categories of personal data, as well as transmission and automated decision-making.

Note on the Applicability of the GDPR and Swiss DPA: This privacy notice serves both to inform in accordance with the Swiss DPA (Data Protection Act) and the GDPR. For reasons of better comprehensibility, we use the terms of the GDPR. However, the legal definitions are based on the respective law.

Security Measures​

In accordance with legal requirements – taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing – we take appropriate technical and organizational measures to ensure a level of security commensurate with the risk.

Important measures include:

  1. Ensuring the confidentiality, integrity, and availability of your data by controlling access and processing.
  2. Establishing procedures for exercising your data subject rights and for erasing or restricting processing.
  3. Considering data protection already when selecting hardware, software, and procedures through data-protection-friendly default settings.

Securing Online Connections: We use TLS/SSL encryption (HTTPS). A website protected by an SSL/TLS certificate displays "HTTPS" in the URL, signaling to you that your data is transmitted securely and encrypted.

Transfer of Personal Data​

We may transmit or disclose your personal data to other bodies, companies, legally independent organizational units, or persons – for example, to IT service providers or providers of services and content that are integrated into our website. In doing so, we always comply with legal requirements and conclude corresponding contracts or agreements.

International Data Transfers​

If we process or transfer your data in a third country (outside the EU/EEA), this will only take place in compliance with legal requirements. If the data protection level of a third country is recognized by an Adequacy Decision (Art. 45 GDPR), this serves as the basis. Otherwise, the data transfer only takes place if the data protection level is otherwise secured, for example, through Standard Contractual Clauses (Art. 46 para. 2 lit. c GDPR), explicit consent, or contractual/statutory requirements.

Further information can be found at https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de and at https://www.dataprivacyframework.gov/.

General Information on Data Storage and Deletion​

We delete your personal data in accordance with statutory provisions as soon as the underlying consents are revoked or no further legal bases exist – this applies if the original processing purpose ceases to apply or the data is no longer required. Exceptions exist if legal obligations or special interests require longer retention.

Data that must be retained for commercial or tax reasons or for legal prosecution will be archived accordingly.

Further information on specific retention and deletion periods can be found in the following points:

  1. 10 years: Retention period for books, records, annual financial statements, inventories, management reports, opening balance sheets, and related working instructions (§ 147 para. 1 no. 1 in conjunction with para. 3 AO, § 14b para. 1 UStG, § 257 para. 1 no. 1 in conjunction with para. 4 HGB).
  2. 8 years: Retention period for booking documents (e.g., invoices, cost receipts) (§ 147 para. 1 no. 4 and 4a in conjunction with para. 3 AO, § 257 para. 1 no. 4 in conjunction with para. 4 HGB).
  3. 6 years: Retention period for other business documents, insofar as they are relevant for taxation (§ 147 para. 1 no. 2, 3, 5 in conjunction with para. 3 AO, § 257 para. 1 no. 2 and 3 in conjunction with para. 4 HGB).
  4. 3 years: Storage of data to consider potential warranty and damage claims (§§ 195, 199 BGB).

Rights of Data Subjects​

According to the GDPR, you have the following rights as a data subject:

  • Right to Object: You can object at any time to the processing of your personal data based on Art. 6 para. 1 lit. e or f GDPR – even if this relates to profiling. In particular, you have the right to object to processing for direct marketing purposes.
  • Right to Withdraw Consent: You can withdraw your given consent at any time.
  • Right of Access (Information): You have the right to know whether and what data of yours is being processed, as well as to receive a copy of this data and further information in accordance with statutory provisions.
  • Right to Rectification: You can request the completion or correction of inaccurate data.
  • Right to Erasure and Restriction of Processing: You can request the erasure of your data or a restriction of processing in accordance with statutory provisions.
  • Right to Data Portability: You have the right to receive your data in a structured, common, and machine-readable format or to request transmission to another controller.
  • Complaint to Supervisory Authority: You can lodge a complaint with a supervisory authority if you believe that the processing of your data violates the GDPR.

Business Services​

We process data of our contractual partners – i.e., customers and prospects – within the framework of contractual and similar legal relationships and in communication (also pre-contractual), such as for answering inquiries.

This data serves to fulfill our contractual obligations, such as providing the agreed services, update obligations, and support in case of warranty or service disruptions. It is also processed to safeguard our rights, for administrative tasks, and the organization of our company – based on our legitimate interests in ensuring proper business management and security measures.

Processing on your behalf: If you store personal data of other people in FunnelCAD (for example, a client's name in a note) or share it through FunnelCAD (for example, through a link or a connected app), you are the controller for this data and we process it on your behalf. Our data processing agreement (AVV) under Art. 28 GDPR, with the technical and organisational measures and the list of sub-processors, sets out how we do this.

Data is only passed on to third parties if this is necessary for the fulfillment of the mentioned purposes or for compliance with legal obligations. We will inform you about further processing, for example for marketing purposes, in this privacy policy.

You will usually find out which data is necessary for this purpose before or during data collection (e.g., in online forms or through specific markings).

We generally delete this data after four years, unless longer statutory periods apply (e.g., ten years for tax purposes). Data transmitted within the scope of an order is deleted after the end of the order.

  • Types of Data Processed: Inventory data, payment data, contact data, contract data, usage data, and meta, communication, and procedural data.
  • Data Subjects: Service recipients, clients, prospects, communication partners, and business and contractual partners.
  • Purposes of Processing: Contract fulfillment, security measures, communication, organizational procedures, business processes.
  • Legal Bases: Performance of contract and pre-contractual inquiries, legal obligations, legitimate interests (see Section 4).

Business Processes and Procedures​

We process personal data within the framework of our business processes to efficiently manage customer management, sales, payment transactions, accounting, and project management. This data supports us in transaction processing, building customer relationships, and internal administrative tasks.

Data may be passed on to third parties (e.g., tax or legal advisors, banks, shipping service providers, IT services) if this is legally required or necessary for the fulfillment of our obligations. We conclude corresponding contracts for this purpose.

  • Types of Data Processed: Inventory data (name, address, contact info, customer number, date of birth, nationality); Payment data (bank details, invoices, payment history, credit card data, IBAN, BIC); Contact data (postal/email addresses, phone numbers, messenger IDs, social media profiles); Content data (messages, contributions, authorship, publication times); Contract data (contract subject, term, customer category, payment modalities); Usage data (page views, dwell time, click paths, interactions); Meta, communication, and procedural data (IP addresses, time details, IDs, log files).

  • Data Subjects: All groups mentioned above.

  • Purposes of Processing: Contract fulfillment, administration, organization, and commercial procedures.

  • Legal Bases: See Section 4.

  • Economic Analyses and Market Research: We analyze data on business transactions and contracts to identify market trends and make business decisions. These analyses are carried out internally and based on pseudonymized or anonymized data. Legal Bases: Legitimate Interests.

Payment Processing​

If you buy the Pro plan, you pay on the checkout page of our payment service provider Stripe. You enter your payment details there, directly at Stripe – we never see them. Stripe processes the payment, calculates the value added tax, issues the invoices, and manages the subscription (renewal, cancellation). In the app, "Account settings ▸ Plan ▸ Manage billing" takes you to Stripe's customer portal, where you can see your invoices and change your payment details, billing address, and VAT ID, or cancel your subscription.

So that the payment belongs to your account, the app passes your account ID and your email address to Stripe when you go to the checkout; you can change the email address there. From Stripe, we store only what we need to switch Pro on and off in your account: Stripe's customer and subscription identifiers, the status of the subscription, the billing period (yearly or monthly), the current paid period and whether and when the subscription has been cancelled, as well as the identifiers of the notifications from Stripe that we have processed. We do not store your name, billing address, VAT ID, payment details, or invoice amounts in the app.

We are the controller for this processing. Stripe processes the data partly on our behalf and partly as an independent controller, in particular to meet its own legal obligations as a payment service provider (e.g., fraud and money laundering prevention).

We delete the subscription data stored in the app together with your account. We keep invoices and accounting records for as long as commercial and tax law requires (8 years for invoices, 10 years for books and records; see "General Information on Data Storage and Deletion"). Stripe stores data in accordance with its own privacy policy and statutory obligations.

  • Types of Data Processed: Inventory data (name, billing address, VAT ID), contact data (email address), payment data (payment method, invoices, payment history), and contract data (plan, billing period, status and term of the subscription).

  • Data Subjects: Service recipients and clients.

  • Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations, office and organizational procedures (accounting and tax).

  • Legal Bases: Performance of contract (Art. 6 para. 1 sentence 1 lit. b GDPR); legal obligation to retain invoices and accounting records (Art. 6 para. 1 sentence 1 lit. c GDPR).

  • Stripe: Payment processing, invoicing, and subscription management for the Pro plan. Service Provider: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland; Legal Bases: Performance of contract (Art. 6 para. 1 sentence 1 lit. b GDPR), legal obligation (Art. 6 para. 1 sentence 1 lit. c GDPR); Website: https://stripe.com; Privacy Policy: https://stripe.com/privacy; Basis for Third Country Transfers: For transfers to Stripe, Inc., USA: Data Privacy Framework (DPF) and Standard Contractual Clauses (Art. 46 para. 2 lit. c GDPR).

Version History of Cloud Boards​

For each board in your account, FunnelCAD keeps earlier versions of it so that you can go back to one: the whole board as it was, when, and whether you or an app you connected (such as Claude) changed it. To show "this browser" on a version, we keep a one-way code made from your sign-in session's identifier. The version itself holds no IP address or device name, but while that sign-in session exists we also keep the session's IP address and browser type (for sign-in security), so the code can be linked to them until the session ends or expires; after that it cannot.

On Free, we keep the versions of the last 7 days; on Pro (and during the trial), every version of the last 7 days, then one a day up to 30 days, then one a week up to 6 months; the newest version always. Versions made while you had Pro keep these periods after Pro ends. Until paid plans start, every account keeps versions as on Pro, and those versions keep the Pro periods afterwards. Older versions are deleted every night. Deleting a board for good, or your account, deletes all its versions at once; you can also delete a board's earlier versions yourself ("Version history ▸ Delete earlier versions"). Versions are never shown on share links. They are included in "Download everything". A value or note you delete on a board stays in its earlier versions until they are deleted as described above, and in our backups for up to 6 months (see "Provision of the Online Offering and Web Hosting").

  • Types of Data Processed: Content data (earlier versions of your boards), meta, communication, and procedural data (time of a version, who changed it, the one-way session code).
  • Data Subjects: Users; persons whose data you enter in your boards.
  • Purposes of Processing: Provision of contractual services (going back to an earlier version).
  • Legal Bases: Performance of contract (Art. 6 para. 1 sentence 1 lit. b GDPR).

Connected Apps (e.g., Claude)​

With the Pro plan (including the free 14-day Pro trial), you can connect an AI app to your FunnelCAD account – currently Claude by Anthropic (on claude.ai, in the Claude desktop and mobile apps, and in Claude Code). You start the connection yourself in that app, sign in to FunnelCAD, and confirm it with "Allow" on FunnelCAD's own page. Without this confirmation, nothing is connected and nothing is sent. The Free plan cannot connect apps.

What the connected app receives: Only when the app asks for it, and only from your own account, we send it: the names of your funnels; their blocks with your inputs and the figures FunnelCAD computes from them; the links between the blocks; settings, scenarios and warnings; the text of the scorecard; and the addresses of share links that the app itself has created. Notes and tasks are sent only when the app asks for them explicitly. On your own funnels that have a live link, the app can also read the comments and suggested values that you and the people you gave the link to wrote there, with their display names – never their email addresses. We never send the app other people's funnels, your email address, your password, or your plan and billing details. Changes the app makes (for example, a new funnel, a changed value, a note or task added or ticked, a comment or a reply) are saved in your account as if you had made them yourself; comments and replies appear under your name, and the people taking part in the discussion are notified by email, as when you reply in the app.

What the app can also do on your instruction: Apart from your account settings, your plan and billing and the connection of apps, a connected app can do what you can do with your funnels by hand. In particular, it can delete your data (move funnels to the Trash, delete them for good, empty the Trash, delete share links together with their statistics, and delete comments, including other people's); change who can see a funnel (switch links on and off, give a link a new address, set or remove a link password – which you tell the app for this purpose); decide on reviewers' suggestions and block reviewers (the reviewers receive the usual emails); read the view counts of your links; export or import whole funnels as files; and read a board's earlier versions, restore one (the state before is kept as a version) or copy one as a new board. Your account password is never sent to the app.

What we store about a connection: In your account – shown in the app under "Account settings ▸ Connections" and included in "Download everything" – we store:

  • the connection: the app's name and the address it returns to (e.g., claude.ai, or "this computer" for Claude Code), the permissions, when it was connected, last used and ended, and why it ended;
  • an activity log: for each request, which function was used, for which funnel, when, with what outcome and how many changes – never the content of your funnel or what the app wrote;
  • the app's registration (name and return address) and its sign-in tokens, which we store only as one-way hashes (SHA-256), never in readable form. An access token is valid for 1 hour, a renewal token for 30 days.

Our server logs contain no tokens, no funnel names and no funnel content.

Storage period: We delete entries of the activity log after 90 days, ended connections together with their log 90 days after they ended, and a registered app without a connection after 7 days at the latest. When you delete your account, we delete all of this with it.

Disconnecting: You can disconnect an app at any time under "Account settings ▸ Connections"; from its next request on, it is refused. Changing or resetting your password and "Sign out everywhere else" disconnect all apps as well. When your Pro plan ends, the connection stays listed, but the app can no longer read or change anything.

The app's provider: The provider of the connected app processes the data it receives under its own terms and privacy policy, which you have accepted with that provider. It is a recipient that you have chosen and to which we transfer data on your instruction; it is not our processor, and we have no influence on what it does with the data. For Claude, the provider is Anthropic: according to Anthropic's privacy policy, Anthropic Ireland, Limited is the controller for users in the EEA, the UK and Switzerland, and Anthropic PBC (USA) for users elsewhere; for business offerings (e.g., Claude for Work or the API), Anthropic processes the data under the customer's own agreement with Anthropic.

Personal data of third parties in your funnels: If your funnels contain personal data of other people (for example, a client's name in a note, or the comments and display names of the people who comment on your live links), you decide as the controller whether this data goes to the app; for this data, we act as your processor and transfer it on your instruction (Terms of Service, Section 10, and the data processing agreement).

Third-country transfer: The app's requests reach us from Anthropic's servers, which may be located outside the EU/EEA, in particular in the USA; our answers go there. This transfer takes place because you instruct it, to a provider that you have chosen and contracted with yourself. For its own processing, Anthropic names adequacy decisions and standard contractual clauses (Art. 46 para. 2 lit. c GDPR) as the safeguards in its privacy policy.

  • Types of Data Processed: Content data (funnels, their inputs and figures; notes and tasks only on request; comments on your live links with the commenters' display names), meta, communication, and procedural data (connection, activity log, hashed tokens), and protocol data.

  • Data Subjects: Users; persons whose data you enter in your funnels; people who comment on your live links.

  • Purposes of Processing: Provision of contractual services and fulfillment of contractual obligations; security measures.

  • Legal Bases: Performance of contract (Art. 6 para. 1 sentence 1 lit. b GDPR) – the connection is a function that you switch on and use; legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR) in the secure operation of the connection, the limits and the protection against misuse.

  • Claude: AI assistant that the user connects to their FunnelCAD account. Service Provider: Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland; Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA; Role: Recipient chosen by the user; processes the data under its own terms, not on our behalf; Legal Bases: Performance of contract (Art. 6 para. 1 sentence 1 lit. b GDPR); Website: https://www.anthropic.com; Privacy Policy: https://www.anthropic.com/legal/privacy.

Provision of the Online Offering and Web Hosting​

We process user data to provide our online services. This includes, in particular, the IP address, which is required to send content and functions to your browser or device.

  • Types of Data Processed: Usage data, meta, communication, and procedural data, protocol data, and content data.

  • Data Subjects: Users of our websites and online services.

  • Purposes of Processing: Provision of the online offering, ensuring user-friendliness, operation of the IT infrastructure, and security measures.

  • Legal Bases: Legitimate Interests.

  • Collection of Access Data and Log Files: All accesses to our online offering are logged in server log files, which include, among others, IP addresses, access times, and browser information. This serves to protect against overload and misuse. Legal Bases: Legitimate Interests. Deletion: Log files are deleted or anonymized after a maximum of 30 days.

  • Sending email via Scaleway: The app sends its emails from no-reply@funnelcad.com through Scaleway's "Transactional Email" service in the EU (region Paris): sign-in and confirmation codes, password reset links, notices about your account, your trial and your plan, and notifications about comments and replies on live links (with the board's name, the display name of the person who commented and a short excerpt of the comment). Scaleway processes the recipients' email addresses and names and the content of these emails on our behalf. Service Provider: Scaleway SAS, 8 rue de la Ville l'Evêque, 75008 Paris, France; Legal Bases: Performance of contract (Art. 6 para. 1 sentence 1 lit. b GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR) for security notices; Website: https://www.scaleway.com; Privacy Policy: https://www.scaleway.com/en/privacy-policy/; Third Country Transfers: none; processing in the EU (France).

  • Hosting of funnelcad.com via Cloudflare: Our website funnelcad.com is provided via Cloudflare, which offers a Content Delivery Network (CDN) and other security and optimization services. Service Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Legal Bases: Legitimate Interests. Website: https://www.cloudflare.com/de-de Privacy Policy: https://www.cloudflare.com/de-de/privacypolicy/ Third Country Transfers: Cloudflare also processes data outside the EEA within its global network and describes appropriate safeguards pursuant to Art. 45 and 46 GDPR for this.

  • Hosting of the app (app.funnelcad.com) at Hetzner: The FunnelCAD app and its database run on a cloud server of Hetzner Online GmbH in a data centre in Nuremberg, Germany. Requests reach the server through Cloudflare's network (see above) via an encrypted tunnel; the server accepts no other connections from the internet. Hetzner processes the data stored and processed in the app (in particular account data and the content of your cloud funnels) on our behalf. Backups: Every night we back up the whole database – accounts, boards and their versions, links and comments – and the server's configuration. Each backup is encrypted on the server before it leaves it and stored in a Hetzner Storage Box in Falkenstein, Germany; the key to decrypt it is not on the server. We keep 14 daily, 8 weekly and 6 monthly backups, never longer than 6 months, and encrypted local copies on the server for 3 days. Data you delete therefore disappears from the backups after 6 months at the latest. If we ever have to restore a backup, accounts deleted since that backup are deleted again before the service is reachable; for other deletions since the backup (for example a board, a link or a comment), we switch the links off and tell you what to delete again. Service Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Legal Bases: Performance of contract (Art. 6 para. 1 sentence 1 lit. b GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR); Website: https://www.hetzner.com; Privacy Policy: https://www.hetzner.com/legal/privacy-policy/; Third Country Transfers: none; processing in Germany.

Use of Cookies​

Cookies are functions that store and read information on your devices. They serve, among other things, the functionality, security, and user-friendliness of our offerings, as well as the creation of visitor statistics. We use cookies in accordance with legal regulations. Where necessary, we obtain your consent. Otherwise, we rely on our legitimate interests, especially when storing and reading information is essential to provide content and functions requested by you.

Notes on Data Protection Legal Bases: The processing of personal data using cookies is based on your consent or our legitimate interests.

Storage Duration: We distinguish between:

  • Temporary Cookies (Session Cookies): These are deleted as soon as you leave our offer or close your browser.
  • Permanent Cookies: These remain stored even after the browser is closed (up to two years, unless otherwise specified).

General Notes on Withdrawal and Objection: You can withdraw your consent and object to the processing at any time – for example, via your browser settings.

  • Types of Data Processed: Meta, communication, and procedural data (e.g., IP addresses, time details, IDs).
  • Data Subjects: Users of our websites and online services.
  • Legal Bases: Consent or legitimate interests (see above).

Further Notes:

  • Processing of Cookie Data based on Consent: We use a consent management solution that obtains, logs, and manages your consent to the use of cookies. Your choice is stored in the local storage of your browser, together with the time of the choice and a random consent ID, until you change it or delete the data stored by your browser. You can change or withdraw your choice at any time via "Cookie settings" at the bottom of every page. Legal Bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR).

Blogs and Publication Media​

We use blogs or similar media to provide content and communicate with you. The data of readers is only processed to the extent necessary for the presentation of the content, communication between authors and readers, or for security reasons.

  • Types of Data Processed: Inventory data, contact data, content data, usage data, and meta, communication, and procedural data.
  • Data Subjects: Users of our websites and online services.
  • Purposes of Processing: Feedback and provision of our online offering.
  • Legal Bases: Legitimate Interests.

Contact and Inquiry Management​

If you contact us – whether by post, contact form, email, phone, or via social media – or are already in a business relationship, we process your information to the extent necessary to process your inquiry.

  • Types of Data Processed: Inventory data, contact data, content data, usage data, meta, communication, and procedural data.

  • Data Subjects: Communication partners.

  • Purposes of Processing: Communication, administrative and organizational procedures, feedback.

  • Legal Bases: Performance of contract, pre-contractual inquiries, and legitimate interests.

  • Google Workspace: Emails to our addresses (for example legal@, support@ and hello@funnelcad.com) are received and stored in mailboxes hosted by Google Workspace. Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Bases: Performance of contract, pre-contractual inquiries, and legitimate interests (Art. 6 para. 1 sentence 1 lit. b and f GDPR); Website: https://workspace.google.com; Privacy Policy: https://policies.google.com/privacy; Basis for Third Country Transfers: Data Privacy Framework (DPF) and Standard Contractual Clauses (Art. 46 para. 2 lit. c GDPR), as provided in Google's data processing terms (https://workspace.google.com/terms/dpa_terms.html).

Promotional Communication via Email, Post, Fax, or Phone​

We also process personal data for advertising purposes – for example, via email, phone, post, or fax – provided this complies with legal requirements.

You can withdraw your consent or object to promotional communication at any time. After a withdrawal or objection, we store the necessary data (e.g., email address, phone number) for up to three years to secure proof of previous authorization. This storage is solely for the defense against possible claims. If withdrawal or objection is permanently respected, the data will be stored in a blocking list.

  • Types of Data Processed: Inventory data, contact data, and content data.
  • Data Subjects: Communication partners.
  • Purposes of Processing: Direct marketing, sales promotion.
  • Legal Bases: Consent; for email advertising to existing customers, § 7 para. 3 UWG in conjunction with Art. 13 para. 2 of Directive 2002/58/EC; legitimate interests only for forms of advertising that do not require prior consent or a special statutory permission.

Web Analysis, Monitoring, and Optimization​

Our web analysis (also called "reach measurement") serves to evaluate the visitor flows of our online offering. It collects pseudonymized data about the behavior, interests, and demographic information (e.g., age, gender) of users, so we can understand when and how our offer is used and where improvements are needed.

We also use testing procedures (e.g., A/B tests) to compare and optimize different versions of our offer. Profiles may be created in your browser or device. If you have consented, location data will also be processed.

We store the IP addresses of users, but pseudonymize them using IP masking to prevent personal identification.

  • Types of Data Processed: Usage data, meta, communication, and procedural data.
  • Data Subjects: Users of our websites.
  • Purposes of Processing: Reach measurement, creation of user profiles, optimization of our offering.
  • Legal Bases: Consent or legitimate interests.

Further Notes:

  • PostHog: If you enable the "Analytics" category in the cookie banner, we use PostHog (PostHog, Inc.) via its EU cloud for reach measurement and to improve our website. In doing so, we record pseudonymous browser identifiers, page views, and predefined interactions, for example clicks on buttons and links. We do not transmit email addresses or free-text entries to PostHog. Session recordings are disabled. You can withdraw your consent at any time via the cookie settings. Legal Bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR). Service Provider: PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA; processing for this project in the EU cloud. Website: https://posthog.com Privacy Policy: https://posthog.com/privacy

Online Marketing​

We process personal data for online marketing purposes – this includes, in particular, placing advertising spaces or displaying content that is based on your potential interests, as well as measuring the effectiveness of these measures.

For this purpose, we may create user profiles and store data in cookies or similar procedures. Information on viewed content, visited websites, technical data (e.g., browser, device), usage times, and communication partners, and – if you have consented – also location data, are stored.

We store IP addresses and pseudonymize them using IP masking. No directly personal data such as name or email address is stored.

Notes on Legal Bases: Processing takes place either on the basis of your consent or based on our legitimate interests in showing you personalized advertising and measuring the effectiveness of our marketing measures.

Notes on Withdrawal and Objection: You can object to personalized advertising via the privacy notices of the respective providers. Alternatively, you can disable cookies in your browser – however, this may limit the functionality of our website.

  • Types of Data Processed: Usage data, meta, communication, and procedural data.

  • Data Subjects: Users of our websites and online services.

  • Purposes of Processing: Reach measurement, tracking, target group formation, personalized marketing, and conversion measurement.

  • Legal Bases: Consent or legitimate interests.

  • Google Ads and Conversion Measurement: We use Google Ads to place ads in Google's advertising network and measure their success. Service Provider: Google Ireland Limited, Dublin 4, Ireland; Legal Bases: Consent and legitimate interests; Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy; Basis for Third Country Transfers: Data Privacy Framework (DPF).

  • Meta Pixel and Conversion Measurement: If you enable the "Marketing" category in the cookie banner, we use the Meta Pixel to measure the success of our ads on Facebook and Instagram and to show our ads to people who have visited our website (Custom Audiences). The Meta Pixel sets a cookie with a pseudonymous ID and transmits usage data (e.g., visited pages, time, browser and device information, IP address) to Meta. Service Provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal Bases: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR); Joint Controllership: For the collection of the data on our website and its transmission to Meta, we and Meta are jointly responsible (Art. 26 GDPR); the agreement is available at https://www.facebook.com/legal/controller_addendum; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/; Basis for Third Country Transfers: Data Privacy Framework (DPF).

Presences in Social Networks (Social Media)​

We maintain online presences in social networks to communicate with active users and offer information about us. Please note that your data may be processed outside the EU, which may limit your rights.

Processing usually takes place for market research and advertising purposes using cookies that record your usage behavior.

Amendment and Update​

Please regularly inform yourself about the content of this privacy policy. We will adapt it as soon as changes in our data processing make this necessary. As soon as a change requires your cooperation (e.g., renewed consent) or an individual notification is necessary, we will inform you.

Please note that addresses and contact data of companies mentioned in this privacy policy may change over time. Please check this information before contacting them.

Definitions of Terms​

Below you will find an overview of the terms used in this privacy policy. Where legal definitions exist, they apply. The following explanations serve for better comprehensibility:

  • Inventory Data (Stock Data): Essential information necessary for the identification and management of contractual partners, user accounts, profiles, etc. (e.g., name, contact information, date of birth, user IDs).
  • Content Data: Information generated during the creation, editing, and publication of content (e.g., texts, images, videos, audio files, and associated metadata such as author, date, tags).
  • Contact Data: Information that enables communication (e.g., phone numbers, email addresses, postal addresses).
  • Conversion Measurement: Procedure for recording the reaction to marketing measures (e.g., clicks on ads, purchases), often with the help of cookies.
  • Meta, Communication, and Procedural Data: Data about the handling of information (e.g., file size, creation date, communication histories, audit logs).
  • Usage Data: Information about how and when users interact with digital offerings (e.g., page views, click paths, device information, location data).
  • Personal Data: All information relating to an identified or identifiable natural person (e.g., name, ID, location data, online identifier).
  • Profiles with User-Related Information: Automated processing in which personal data is analyzed or evaluated to determine personal aspects (e.g., interests, behavior).
  • Protocol Data (Log Data): Records of events or activities in a system (e.g., timestamps, IP addresses, error messages).
  • Reach Measurement: Also known as Web Analytics, used to evaluate visitor flows to optimize the offering.
  • Tracking: The monitoring of user behavior across various offers, often using cookies and profiling.
  • Controller: The person or organization that decides on the purposes and means of the processing of your personal data.
  • Processing: Any operation related to personal data, be it collection, evaluation, storage, transmission, or deletion.
  • Contract Data: All details of an agreement between parties (e.g., services, term, payment modalities).
  • Payment Data: Information required for processing transactions (e.g., credit card number, bank details, invoice information).
  • Target Group Formation: Procedure for identifying specific user groups for advertising purposes (e.g., Custom Audiences), often using cookies.