top of page

PRIVACY POLICY

1. Introduction

This website is operated by: Natursteinwerk Böswald GmbH.

It is very important to us to handle our website visitors' data confidentially and to protect it in the best possible way. For this reason, we make every effort to comply with the requirements of the GDPR.

Below we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you really understand what happens to your data.

2. General information

2.1 Processing of personal data and other terms

Data protection applies to the processing of personal data. Personal data means all data with which you can be personally identified. This is, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently sitting in front of. Such data is processed when 'something happens to it'. Here, for example, the IP is transmitted from the browser to our provider and automatically stored there. This is then a processing (according to Art. 4 No. 2 GDPR) of personal data (according to Art. 4 No. 1 GDPR).

These and other legal definitions can be found in Art. 4 GDPR.

2.2 Applicable regulations/laws - GDPR, BDSG and TDDDG

The scope of data protection is regulated by law. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national law.

In addition, the TDDDG supplements the provisions of the GDPR as far as the use of cookies is concerned.

2.3 The person responsible

The controller within the meaning of the GDPR is responsible for data processing on this website. This is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

You can reach the person responsible at:

Natural stone works Böswald GmbH

Buchenaustraße 21 86653 Monheim-Weilheim

+49 9091 50909-0 info@natursteinwerk-boeswald.de

2.4 How data is generally processed on this website

As we have already established, there is data (e.g. IP address) that is collected automatically. This data is mainly required for the technical provision of the website. If we also use personal data or collect other data, we will inform you of this or ask for your consent.

You consciously provide us with other personal data.

You will find detailed information on this below.

2.5 Your rights

The GDPR provides you with comprehensive rights. These include, for example, free information about the origin, recipient and purpose of your stored personal data. You can also request the rectification, blocking or erasure of this data or lodge a complaint with the competent data protection supervisory authority. You can revoke your consent at any time.

You can find out what these rights look like in detail and how to exercise them in the last section of this Privacy Policy.

2.6 Data protection - Our view

Data protection is more than just a chore for us! Personal data has great value and careful handling of this data should be a matter of course in our digitalized world. As a website visitor, you should also be able to decide for yourself what "happens" to your data, when and by whom. That is why we are committed to complying with all legal regulations, only collect the data we need and, of course, treat it confidentially.

2.7 Forwarding and deletion

The transfer and deletion of data are also important and sensitive issues. We would therefore like to briefly inform you in advance about our general approach to this.

Data will only be passed on on the basis of a legal basis and only if this is unavoidable. This may be the case in particular if it is a so-called Data Processor and a Data Processing Agreement has been concluded in accordance with Art. 28 GDPR.

We delete your data when the purpose and legal basis for processing no longer apply and the deletion does not conflict with any other legal obligations. Art. 17 GDPR also provides a 'good' overview of this.

For further information, please refer to this Privacy Policy and contact the person responsible if you have any specific questions.

2.8 Hosting

This website is hosted externally. The personal data collected on this website is stored on the host's servers. This includes the automatically collected and stored log files (see below for more details), as well as all other data provided by website visitors.

External hosting is used for the purpose of secure, fast and reliable provision of our website and in this context serves to fulfill the contract with our potential and existing customers.

The legal basis for the processing is Art. 6 para. 1 lit. a, b and f GDPR, as well as § 25 para. 1 TDDDG, insofar as consent includes the storage of cookies or access to information in the terminal device of the website visitor or user within the meaning of the TDDDG.

Our hoster only processes data that is required to fulfill its performance obligation and acts as our Data Processor, i.e. it is subject to our instructions. We have concluded a corresponding Data Processing Agreement with our hoster.

We use the following hoster:

WiX

Wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel.

support@wix.com

https://de.wix.com/about/privacy.

 

2.9 Legal basis

The processing of personal data always requires a legal basis. The GDPR provides the following possibilities in Art. 6 para. 1 sentence 1:

a) The data subject has given their consent to the processing of their personal data for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) the processing is necessary for compliance with a legal obligation to which the controller is subject;

d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;

e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

In the following sections, we will provide you with the specific legal basis for the respective processing.

3. What happens on our website

When you visit our website, we process your personal data.

We use SSL or TLS encryption to protect this data in the best possible way against unauthorized access by third parties. You can recognize this encrypted connection by the https:// or lock symbol in the address bar of your browser.

Below you can find out what data is collected when you visit our website, for what purpose this is done and on what legal basis.

3.1 Data collection when accessing the website

When you visit the website, information is automatically stored in so-called server log files. This is the following information:

•Browser type and browser version

•Operating system used

•Referrer URL

•Host name of the accessing computer

•Time of the server request

•IP address

This data is temporarily required in order to be able to display our website to you permanently and without any problems. In particular, this data is used for the following purposes:

•System security of the website

•System stability of the website

•Troubleshooting on the website

•Establishing a connection to the website

•Presentation of the website

Data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR and is based on our legitimate interest in the processing of this data, in particular our interest in the functionality of the website and its security.

Where possible, this data is stored in pseudonymized form and deleted once the respective purpose has been achieved.

If the server log files make it possible to identify the data subject, the data is stored for a maximum period of 14 days. An exception is made if a security-relevant event occurs. In this case, the server log files are stored until the security-relevant event has been resolved and finally clarified.

Otherwise, no merging with other data takes place.

3.2 Cookies

3.2.1 General information

This website uses so-called cookies. This is a data record, information that is stored in the browser of your end device and is related to our website.

The use of cookies can make it easier for visitors to navigate the website.

3.2.2 Rejecting cookies

 

You can prevent cookies from being set by adjusting your browser settings.

Here you will find the corresponding links to frequently used browsers:

Mozilla Firefox: https://support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen?redirectslug=Cookies+l%C3%B6schen&redirectlocale=de

Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=de

Microsoft Edge: https://support.microsoft.com/de-de/windows/l%C3%B6schen-und-verwalten-von-cookies-168dab11-0753-043d-7c16-ede5947fc64d

Safari: https://support.apple.com/de-de/guide/mdm/mdmf7d5714d4/web and https://support.apple.com/de-de/guide/safari/sfri11471/mac

If you are using a different browser, we recommend that you enter the name of your browser and 'delete and manage cookies' in a search engine and follow the official link to your browser.

Alternatively, you can also change your cookie settings under www.aboutads.info/choices/ or www.youronlinechoices.com manage.

However, we must point out that a comprehensive blocking/deletion of cookies can lead to impairments in the use of the website.

3.2.3 Technically necessary cookies

We use technically necessary cookies on this website to ensure that our website functions correctly and in accordance with the applicable laws. They help to make the website user-friendly. Some functions of our website cannot be displayed without the use of cookies.

The legal basis for this is Art. 6 para. 1 lit. b, c and/or f GDPR, depending on the individual case.

3.2.4 Technically not necessary cookies

We also use cookies on our website that are not technically necessary. These cookies are used, among other things, to analyze the surfing behavior of the website visitor or to offer functions of the website that are not technically necessary.

The legal basis for this is your consent in accordance with Art. 6 para. 1 lit. a GDPR.

Technically unnecessary cookies are only set with your consent, which you can revoke at any time in the cookie consent tool.

3.3 Data processing through user input

 

3.3.1 Contact us

a) e-mail

When you contact us by email, we process your email address and any other data contained in the email. This data is stored on the mail server and in some cases on the respective end devices. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

b) Telephone

If you contact us by telephone, the call data may be stored in pseudonymized form on the respective end device and with the telecommunications provider used. Personal data collected during the telephone call will only be processed in order to process your request. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

3.4 Website construction kit system

3.4.1 Wix

We use the Wix service to create our website. This is a service of Wix.com Ltd, Namal 40, 6350671 Tel Aviv, Israel.

Wix is a website builder system that can be used to create HTML5 websites and mobile websites. It is an online platform that is based on the cloud principle. This makes it very easy to integrate the functions into your own website. With this service, we can design our website according to our wishes and meet our goal of user-friendliness.

Wix uses cookies. These cookies are only set with the consent of the website visitor and can be revoked at any time. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR.

Furthermore, the use of the service is technically necessary for us to display our website. The legal basis for the processing is Art. 6 para. 1 lit. f GDPR.

The data will be deleted as soon as it is no longer required for the processing purposes.

Further information:

https://de.wix.com/about/privacy.

3.5 Analysis and tracking tools

3.5.1 Google Maps

We use Google Maps on this website. Google Maps is a web mapping service. This service is provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

When using Google Maps, the IP address is stored. This data is usually transferred to a Google server in the USA and stored there. We have no influence on this. Google may use Google Fonts for a uniform presentation. These fonts are loaded in the browser cache of the website visitor.

Google Maps uses cookies. These cookies are only set with your consent. Consent can be revoked at any time.

The legal basis is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as this consent includes access to information in the user's terminal device or the storage of cookies within the meaning of the TDDDG.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

Further details:

https://privacy.google.com/businesses/gdprcontrollerterms/ and

https://privacy.google.com/businesses/gdprcontrollerterms/sccs/

https://policies.google.com/privacy?hl=de.

3.5.2 Meta pixel

We use meta pixels on this website. Meta Pixel is a conversion tracking tool. This service is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Habour, Dublin 2, Ireland.

Meta pixel enables us to track the behavior of the website visitor after they have been redirected to the website via a Facebook ad.

Meta-Pixel uses cookies for its own advertising purposes. The data is stored and processed by Facebook so that a connection to the respective user profile can be established.

The data collected is also transferred to the USA and other third countries.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

If personal data is collected on this website using meta pixels and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Habour, Dublin 2, Ireland are jointly responsible for data processing in accordance with Art. 26 GDPR. This joint responsibility is limited exclusively to the collection and transfer of data to Facebook.

There is an agreement on joint processing for this purpose:

https://www.facebook.com/legal/controller_addendum.

We are responsible for providing data protection information when using the Facebook tool and for the secure integration of the tool on the corresponding website in accordance with data protection law. Facebook, on the other hand, is responsible for the data security of its products. This means that data subjects' rights with regard to the data processed by Facebook must be asserted directly with Facebook.

Further details:

https://de-de.facebook.com/about/privacy/

https://www.facebook.com/ads/preferences/?entry_product=ad_settings_scrnen

http://www.youronlinechoices.com/de/praferenzmanagement/

https://www.facebook.com/legal/EU_data_transfer_addendum

https://de-de.facebook.com/help/566994660333381.

3.5.3 WIX Analytics

We integrate the analytics functions of Wix on our website. This service is offered by wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel.

Wix Analytics collects and stores various types of user data for optimization and marketing purposes. This data is anonymized and summarized in statistical reports. The information collected includes login data, time zone settings, operating system and platform used, details of website visits such as the URL, duration of use, number of pages visited per session, search terms entered, information about interactions on the website, such as content searched for or viewed, page response speed and conversion rate.

Wix Analytics uses cookies for this purpose. The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as this consent includes access to information in the user's terminal device or the storage of cookies within the meaning of the TDDDG.

Otherwise, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the analysis to ensure the technical stability of our website.

Further information:

https://de.wix.com/about/privacy.

3.5.4 Tik Tok Analytics

We integrate the functions of TikTok Analytics on our website. This service is offered by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.

The statistical analysis by TikTok Analytics for operators of TikTok company profiles provides aggregated data and anonymized statistics on the use of the company profile by TikTok users. These analyses include demographic information such as age, gender, city/country, device type, interactions with the "Like" button, region and language settings, as well as the proportion of men and women. In addition, key figures on reach, clicks on posts, reactions, comments, shared content, total video views and details on playback behavior are recorded. TikTok measures the reach of our posts, mentions and events based on the various sources of access, including external access via websites and apps, as well as impressions (e.g. by followers) and their resulting interactions. All interactions with our posts are also recorded, including the total number of user interactions such as clicks, comments, likes, messages and "follow" information. TikTok Analytics can set cookies. The legal basis for the processing is then Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as this consent includes access to information in the user's terminal device or the storage of cookies within the meaning of the TDDDG. Otherwise, the legal basis for the processing is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in analyzing our website. Further information:

https://www.tiktok.com/legal/page/eea/privacy-policy/de.

3.5.5 TikTok Pixel

We use TikTok Pixel on our website. TikTok Pixel is operated by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.

TikTok Pixel enables us to analyze user behavior on our website and to place targeted advertising measures. Personal data such as IP address, user ID, pages visited, length of stay and interactions with the website are processed. The purpose of data processing is to analyze user behavior and optimize our marketing strategies.

The legal basis for data processing is consent in accordance with Art. 6 para. 1 lit. a GDPR. TikTok Pixel uses cookies to analyze and track user behavior. These cookies are only set with consent, which can be revoked at any time. The legal basis for this is Art. 6 para. 1 lit. a GDPR.

Data is transferred to third countries, in particular to the USA. The EU Commission's Standard Contractual Clauses (SCC) are used to ensure an adequate level of data protection. Data is stored until the data subject withdraws consent to storage or the purpose for storage no longer applies.

Further information on data processing can be found here: https://www.tiktok.com/legal/page/eea/privacy-policy/de.

3.5.6 Google Search Console

We integrate the Google Search Console service on our website, which is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Search Console is a service that enables us to monitor the indexing status of our website and optimize its visibility in Google search results.

Various data is processed, including information on website performance, clicks, accesses and technical errors that occur on the website. The purpose of data processing is to improve search engine optimization (SEO), analyze the technical performance of the website and correct errors.

The legal basis for data processing is Art. 6 para. 1 lit. f GDPR, as we have a legitimate interest in optimizing our website in the search results and ensuring its functionality.

Google Search Console does not set cookies on our website. However, data may be transferred to third countries, in particular to the USA, as Google operates servers worldwide. The standard contractual clauses (SCCs) of the EU Commission are used to ensure an adequate level of data protection.

The data is stored for as long as it is necessary for the respective processing purpose or until the user requests deletion.

Further information on data processing can be found at: https://policies.google.com/privacy.

3.6 Social media plugins

3.6.1 Facebook

Elements of the social network Facebook are integrated on this website. This service is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

If the social media element is activated, a direct connection is established between the website visitor and the Facebook servers and their IP address is transmitted to Facebook. If the website visitor has a user account, the visit to this website can be assigned to the corresponding user account.

The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

If personal data is collected on this website with the help of Facebook and forwarded to Meta, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Habour, Dublin 2, Ireland are jointly responsible for data processing in accordance with Art. 26 GDPR. This joint responsibility is limited exclusively to the collection and transfer of data to Facebook.

 

There is an agreement on joint processing for this purpose:

https://www.facebook.com/legal/controller_addendum. We are responsible for providing data protection information when using the Facebook tool and for the secure integration of the tool on the corresponding website in accordance with data protection law. Facebook, on the other hand, is responsible for the data security of its products. This means that data subjects' rights with regard to the data processed by Facebook must be asserted directly with Facebook.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

Further information:

https://www.facebook.com/legal/EU_data_transfer_addendum

https://de-de.facebook.com/help/566994660333381

https://www.facebook.com/policy.php

https://de-de.facebook.com/privacy/explanation.

3.6.2 Instagram

Elements of the social network Instagram are integrated on this website. This service is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

If the social media element is activated, a direct connection is established between the website visitor and the Instagram servers and their IP address is transmitted to Instagram. If the website visitor has a user account, the visit to this website can be assigned to the corresponding user account. As the website operator, we have no knowledge of the content of the transmitted data.

The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

If personal data is collected on this website with the help of Facebook or Instagram and forwarded to Meta, the website operator and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Habour, Dublin 2, Ireland are jointly responsible for data processing in accordance with Art. 26 GDPR. This joint responsibility is limited exclusively to the collection and transfer of data to Facebook and Instagram. There is an agreement on joint processing for this purpose:

https://www.facebook.com/legal/controller_addendum.

The website operator is responsible for providing data protection information when using the Instagram tool and for the secure integration of the tool on the corresponding website in accordance with data protection law. Facebook and Instagram, on the other hand, are responsible for the data security of their products. This means that data subjects' rights with regard to data processed by Facebook or Instagram must be asserted directly with Facebook or Instagram.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

https://www.facebook.com/legal/EU_data_transfer_addendum

https://de-de.facebook.com/help/566994660333381

https://www.facebook.com/policy.php

https://instagram.com/about/legal/privacy/.

3.6.3 TikTok

Elements of the TikTok social network are integrated on this website. This service is offered by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.

If the social media element is activated, a direct connection is established between the website visitor and the TikTok servers and their IP address is transmitted to TikTok. If the website visitor has a user account, the visit to this website can be assigned to the corresponding user account. The website operator has no knowledge of the content of the transmitted data.

The legal basis for the processing is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

The EU Commission's Standard Contractual Clauses (SCC) apply to data transfers to the USA.

Further information:

https://www.tiktok.com/legal/page/eea/privacy-policy/de-DE?tid=331689749201

https://ads.tiktok.com/i18n/official/policy/controller-to-controller.

3.7 Social media profiles

In addition to our website, our company is also present on social networks. Here we want to present our company and create the opportunity to get in touch with us.

We also use the opportunity to place advertisements and job advertisements on social media.

In the following, we provide information about which data we and the respective social network process when you visit and interaction with our profile.

3.7.1 Facebook

We operate a Facebook fan page at https://www.facebook.com/. This social network is operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

a) Interaction with our company profile

When you visit our Facebook profile and interact with us via it, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information.

The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our Facebook profile.

Insofar as an inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.

b) Page Insights

As explained in the Meta Privacy Policy under "How do we use your information?" (Meta also collects and uses information to provide analytics services, known as Page Insights, for site operators. This also applies to our Facebook page.

Page insights are summarized statistics that are created based on certain interactions of visitors with pages and the content associated with them (e.g. viewing a page or a video, subscribing to a page, marking a page with "Like" or "No longer like", etc.) and are logged by the meta servers.

In connection with the Page Insights, Meta provides us with summarized statistics and insights that give us information about how people interact with our company website. We do not have access to any personal data, only to the summarized Page Insights. With the help of the page insights, we can view anonymous statistics, e.g. the reach of our account, page views, likes, etc.. These also contain evaluations according to the age, gender and location of the users (as specified by them in their respective Facebook profiles). To evaluate the reach, we can make settings or set appropriate filters with regard to the selection of a time period, the viewing of a specific post and demographic groupings. This data is anonymized. It is not possible for us to draw conclusions about specific individuals.

The purpose of processing this data is to analyze our reach and adapt our content and advertisements to user interests so that visitors can derive the greatest possible benefit from them. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target group-specific content and place advertisements to better market our company and our services.

The processing is based on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.

When processing personal data in the course of the so-called Page Insights, we are jointly responsible with Facebook in accordance with Art. 26 para. 1 GDPR.

We have concluded a corresponding agreement with Facebook for this purpose, which can be viewed here (https://www.facebook.com/legal/terms/page_controller_addendum).

The contact details for Facebook are:

Online contact: https://www.facebook.com/help/contact/1650115808681298

Postal: Meta Platforms Ireland Limited, ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland.

For Facebook, you can contact the data protection officer at the following link:

https://www.facebook.com/help/contact/540977946302970.

Further information about the Page Insights:

https://de-de.facebook.com/legal/terms/page_cntroller_addendum

c) Processing of personal data and cookies by Meta

When you access a Facebook page, the IP address assigned to your end device is transmitted to Facebook. According to Facebook, this IP address is anonymized (for "German" IP addresses). Facebook also stores information about the end devices of its users (e.g. as part of the "login notification" function); Facebook may thus be able to assign IP addresses to individual users. If you are currently logged in to Facebook as a user, a cookie with your Facebook ID is stored on your device. This enables Facebook to track that you have visited this page and how you have used it. Facebook buttons integrated into websites enable Facebook to record your visits to these websites and assign them to your Facebook profile. This data can be used to tailor content or advertising to you.

Information on how personal data can be managed or deleted can be found in Facebook's Privacy Center:

https://www.facebook.com/privacy/center/.

Further information on the handling of data by Facebook can be found here:

http://de-de.facebook.com/about/privacy.

3.7.2 Instagram

We operate an Instagram profile. This social media platform is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

a) Interaction with our company profile

When you visit our Instagram profile and interact with us, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information.

The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our Instagram profile.

Insofar as an inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.

b) Insights

As explained in the Meta Privacy Policy under "How do we use your information?" (https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect), Meta also collects and uses information to provide analytics services, known as insights, for site operators. This also applies to our Instagram profile.

The insights are summarized statistics that are created based on certain interactions of visitors with pages and the content associated with them and are logged by the meta servers. This includes the following information, among others

•How many people see and interact with our products, services or content, such as posts, videos, Instagram pages, listings, stores and advertisements (if the advertisement is shown on meta-products);

•How people interact with our content, websites, apps and services;

•Which group of people interact with our content and which group of people use our services.

Meta provides us with summarized reports and insights that tell us how well our content, features, products and services are performing.

We do not receive access to personal data, but only to the summarized reports.

To evaluate the reach, we can make settings or set appropriate filters with regard to the selection of a time period, the viewing of a specific post and demographic groupings. This data is anonymized. It is not possible for us to draw conclusions about specific individuals.

The purpose of processing this data is to analyze our reach and adapt our content and advertisements to user interests so that visitors can derive the greatest possible benefit from them. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target group-specific content and place advertisements to better market our company and our services.

The processing is based on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.

When processing personal data in the course of the so-called Insights, the processing is carried out under joint responsibility with Meta in accordance with Art. 26 para. 1 GDPR.

We have concluded a corresponding agreement with Meta, which can be viewed here (https://www.facebook.com/legal/terms/page_controller_addendum.).

Meta's contact details are as follows:

Online contact: https://www.facebook.com/help/contact/1650115808681298

Postal: Meta Platforms Ireland Limited, ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland.

For Instagram, you can contact the data protection officer at the following link:

https://www.facebook.com/help/contact/540977946302970.

Further information about the Insights:

https://de-de.facebook.com/help/pages/insights.

You can find Instagram's full privacy policy here:

https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect

Processing of personal data and cookies by Meta

When you access an Instagram page, the IP address assigned to your device is transmitted to Meta. According to Meta, this IP address is anonymized (for "German" IP addresses). Meta also stores information about the end devices of its users (e.g. as part of the "login notification" function); Meta may thus be able to assign IP addresses to individual users. If you are currently logged in to Instagram as a user, a cookie with your Instagram ID is stored on your device. This enables Meta to track that you have visited this page and how you have used it. Meta buttons integrated into websites enable Meta to record your visits to these websites and assign them to your Instagram profile. This data can be used to tailor content or advertising to you.

Further information:

https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect.

3.7.3 TikTok

We operate a TikTok channel. TikTok is provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (hereinafter "TikTok Ireland"). Our TikTok channel gives us the opportunity to present ourselves to TikTok users and to get in touch with them.

a) Interactions with our TikTok channel

Users can interact with our TikTok channel via their TikTok account, for example by liking or commenting on our posts. In doing so, we process the associated data such as the user name and profile picture.

We use this data to optimize our content and its presentation and to adapt it to the respective user interests.

It is also possible to send us direct messages on our TikTok channel. The user name and profile picture are also displayed here.

The legal basis for data processing is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in optimizing our TikTok channel and the content published there. We also have a legitimate interest in communicating with users in order to answer questions, respond to criticism, build a relationship and exchange information. This enables us to improve our services and respond to the needs of potential customers. By communicating via TikTok, we reach younger customers in particular.

Comments are saved on the channel for an unlimited period of time and can be viewed by other users. The same applies to the use of the Like function and direct messages.

b) TikTok analysis

When our TikTok channel is accessed and used, additional data is processed for TikTok analysis. These are summarized statistics that are created and logged by TikTok based on certain interactions of visitors with our TikTok channel and provide information about how our channel is interacted with.

This data includes, but is not limited to:

•- Follower growth

•- Video views

•- Profile views

•- Likes, comments and shares

•- Average playback time

•- Percentage of viewers who watch the entire video

•- Sources of traffic (e.g. profile, For You feed)

•- Geographical distribution of the audience

•- Activity times of the followers.

The data is provided to us in aggregated form as statistics. We do not have access to personal data, but only to the summarized statistics.

Further information on the TikTok analyses can be found here:

https://www.tiktok.com/creators/creator-portal/en-us/tiktok-content-strategy/understanding-your-analytics/.

This data is processed solely for the purpose of analyzing and improving the content on our TikTok channel. By evaluating this data, we can recognize how our content and our TikTok channel are consumed. This enables us to create target group-oriented content and, if necessary, to place advertising in order to better market our company and our services.

The processing is based on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.

When processing personal data in the course of TikTok analyses, the processing is carried out under joint responsibility with TikTok in accordance with Art. 26 para. 1 GDPR.

To this end, we have concluded a corresponding agreement with TikTok, which is available here

can be viewed.

The contact details of TikTok are:

Online contact: https://privacytiktok.zendesk.com/hc/en-us/requests/new.

Postal: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland.

You can use this form to contact TikTok's data protection officer:

https://www.tiktok.com/legal/report/DPO.

c) Processing of personal data by TikTok

When using TikTok's services, TikTok processes the personal data of users. This includes data such as your IP address, location data, time zone settings, advertising IDs, app and browser versions and device data (system, network type, device ID, screen resolution, operating system, audio settings and connected audio devices). The TikTok profiles and channels accessed, likes, messages and other usage data are also processed. If you are logged in with your own TikTok account, this data will be assigned to your account.

Further information on the processing of data by TikTok can be found here: https://www.tiktok.com/legal/page/eea/privacy-policy/de.

3.8 Third-party content

3.8.1 Google Fonts

We have integrated Google Fonts locally on our server. This means that no data is transferred to Google, despite its use.

 

3.8.2 WIX CDN

We use the CDN from WIX. This service is offered by wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel. A Content Delivery Network (CDN) is a distributed network of servers used to deliver web content such as web pages, images and videos to users faster by providing the data from a server geographically closer to the user. This reduces loading times and improves the user experience while protecting websites from high traffic loads and security threats. Personal data is forwarded to WIX for this purpose. The legal basis is Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in increasing the security and delivery speed of our website and using a CDN. This data is stored until the data subject requests deletion, the consent to storage is revoked or the purpose for storage no longer applies. Further information: https://de.wix.com/manage/privacy-security-hub.

https://de.wix.com/about/privacy.

3.8.3 Dieter Live API 

We use the Live API from Dieter macht den Datenschutz to display our Privacy Policy. This is a service of simply Legal GmbH, Burkarderstraße 36, 97082 Würzburg.

The API is a technical interface. When you access our Privacy Policy, a connection to the servers of simply Legal GmbH is established. Your IP address will be transmitted to simply Legal GmbH.

Further information on the handling of data by simply Legal GmbH:

https://www.dieter-datenschutz.de/datenschutz/.

3.8.4 Wix Multilingual

We use Wix Multilingual on our website, a service for creating multilingual websites, provided by Wix.com Ltd, 40 Namal Tel Aviv St., Tel Aviv, Israel. Wix Multilingual enables us to offer our website in several languages and thus reach an international audience. When using Wix Multilingual, data such as language preferences and technical information such as IP address and browser type are processed. The data is processed for the purpose of providing a multilingual website and improving the user experience. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR due to our legitimate interest in the international orientation of our website. Wix Multilingual can set cookies to save language settings. These cookies are only set with consent and can be revoked at any time in our cookie consent tool. The legal basis for this is Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Data is transferred to a third country, namely Israel. Israel has an adequacy decision from the European Commission, so that an adequate level of data protection is guaranteed. The data is stored until deletion is requested, consent is revoked or the purpose for storage no longer applies. Statutory retention periods remain unaffected. Further information on data processing can be found at https://de.wix.com/about/privacy.

3.9 Cloud backups

We use cloud backup functions on our website to protect the data and content of the website from data loss, corruption or security incidents. This ensures that the website can be restored quickly and completely in the event of a server failure, a hacker attack or other unforeseen events.

If personal data is stored on our website, it is transferred to the servers of the respective provider during backups. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR, as we have a legitimate interest in backing up our data.

We use the following cloud backup service:

WIX CMS Backup

Wix.com, Inc, 500 Terry A. Francois Boulevard, 6th Floor, San Francisco, CA 94158, USA. https://support.wix.com/en/article/wix-privacy-policy.

4. What else is important

Finally, we would like to inform you in detail about your rights and how you will be informed about changes to data protection requirements.

4.1 Your rights in detail

4.1.1 Right to information in accordance with Art. 15 GDPR

You can request information about whether your personal data is being processed. If this is the case, you can request further information on the type and manner of processing. A detailed list can be found in Art. 15 para. 1 lit. a to h GDPR.

4.1.2 Right to rectification in accordance with Art. 16 GDPR

This right includes the correction of incorrect data and the completion of incomplete personal data.

4.1.3 Right to erasure in accordance with Art. 17 GDPR

This so-called 'right to be forgotten' gives you the right, under certain conditions, to request the deletion of personal data by the controller. This is generally the case if the purpose of the data processing no longer applies, if consent has been withdrawn or the initial processing took place without a legal basis. A detailed list of reasons can be found in Art. 17 para. 1 lit. a to f GDPR. This "right to be forgotten" also corresponds to the controller's obligation under Art. 17 para. 2 GDPR to take reasonable steps to ensure that the data is generally erased.

4.1.4 Right to restriction of processing in accordance with Art. 18 GDPR

This right is subject to the conditions set out in Art. 18 para. 1 lit. a to d.

4.1.5 Right to data portability in accordance with Art. 20 GDPR

This regulates the basic right to receive your own data in a commonly used form and to transfer it to another controller. However, this only applies to data processed on the basis of consent or a contract in accordance with Art. 20 (1) (a) and (b) and insofar as this is technically feasible.

4.1.6 Right to object pursuant to Art. 21 GDPR

In principle, you can object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the legitimate interest of the controller in the processing and if the processing relates to direct marketing and/or profiling.

4.1.7 Right to "individual decision-making" pursuant to Art. 22 GDPR

In principle, you have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. However, this right is also restricted and supplemented by Art. 22 (2) and (4) GDPR.

4.1.8 Further rights

The GDPR contains comprehensive rights to inform third parties about whether or how you have asserted rights under Art. 16, 17, 18 GDPR. However, this only applies insofar as this is possible or feasible with reasonable effort.

We would like to take this opportunity to draw your attention once again to your right to withdraw your consent in accordance with Art. 7 (3) GDPR. However, this does not affect the lawfulness of the processing carried out up to that point.

We would also like to draw your attention to your rights under §§ 32 ff. BDSG, which, however, are largely congruent with the rights just described.

4.1.9 Right to lodge a complaint pursuant to Art. 77 GDPR

You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes this Regulation.

5. What if the GDPR is abolished tomorrow or other changes take place?

The current status of this Privacy Policy is 25.09.2025. From time to time it is necessary to adapt the content of the Privacy Policy in order to react to actual and legal changes. We therefore reserve the right to amend this Privacy Policy at any time. We will publish the amended version in the same place and recommend that you read the Privacy Policy regularly.

Created with the kind support of Dieter macht den Datenschutz

bottom of page