Search
Close this search box.

Privacy policy

Privacy at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data are all data with which you can be personally identified. Detailed information on data protection can be found in our privacy policy listed below this text.

Data Collection on this Website

Who is responsible for data collection on this website?

The data processing on this website is carried out by the website operator. You can find their contact details in the “Controller Information” section of this privacy policy.

How do we collect your data?

Your data is collected when you provide it to us. This may, for example, be data that you enter into a contact form.

Other data is automatically collected or obtained upon your consent when visiting the website through our IT systems. These are mainly technical data (e.g., internet browser, operating system, or time of page access). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Some of the data is collected to ensure the proper functioning of the website. Other data may be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right to obtain free information about the origin, recipient, and purpose of your stored personal data at any time. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. Additionally, under certain circumstances, you have the right to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

For this purpose and for any further questions regarding data protection, you can contact us at any time.

Analysis tools and third-party tools

Your surfing behavior may be statistically analyzed when visiting this website. This is mainly done with so-called analysis programs.

Detailed information about these analysis programs can be found in the following privacy policy.

2. Hosting

We host the content of our website with the following provider:

RAIDBOXES

The provider is RAIDBOXES GmbH, Hafenstr. 32, 48151 Münster (hereinafter RAIDBOXES). When you visit our website, RAIDBOXES collects various log files, including your IP addresses.

Please refer to RAIDBOXES’ privacy policy for details: https://raidboxes.io/legal/privacy/.

The use of RAIDBOXES is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in a reliable presentation of our website. If consent has been requested, the processing is based exclusively on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information on the user’s terminal device (e.g., for device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.

Data Processing Agreement

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a data protection required contract that ensures that the personal data of our website visitors are processed only according to our instructions and in compliance with the GDPR.

  1. General Notes and Mandatory Information

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

When you use this website, various personal data are collected. Personal data are data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.

We would like to point out that data transmission over the internet (e.g., communication by e-mail) may have security vulnerabilities. A complete protection of the data against access by third parties is not possible.

Controller Information

The controller for data processing on this website is:

Water Is Right Foundation c/o Design Offices Barckhausstr. 1 60325 Frankfurt am Main Germany

Phone: [Phone number of the controller] Email: wir@waterisright.org

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).

Storage Duration

Unless a specific storage period is specified within this privacy policy, your personal data will remain with us until the purpose for data processing ceases. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, provided we have no other legally permissible grounds for storing your personal data (e.g., tax or commercial retention periods); in the latter case, the deletion will take place after these grounds cease to apply.

General Notes on the Legal Bases for Data Processing on this Website

If you have given your consent to data processing, we will process your personal data based on Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR if special categories of data according to Art. 9 para. 1 GDPR are processed. In the event of explicit consent to the transfer of personal data to third countries, data processing also takes place on the basis of Art. 49 para. 1 lit. a GDPR. If you have consented to the storage of cookies or access to information on your device (e.g., via device fingerprinting), data processing also takes place based on § 25 para. 1 TTDSG. The consent can be revoked at any time. If your data are necessary for the performance of a contract or for the implementation of pre-contractual measures, we will process your data based on Art. 6 para. 1 lit. b GDPR. Furthermore, we will process your data if it is necessary to fulfill a legal obligation based on Art. 6 para. 1 lit. c GDPR. Data processing may also be carried out based on our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR. The relevant legal bases will be provided in the following paragraphs of this privacy policy, as applicable in each individual case.

Notice Regarding Data Transfer to Privacy-Insecure Third Countries and Transfer to US Companies Not Certified under the EU-US Data Privacy Framework (DPF)

We use tools from companies located in privacy-insecure third countries, as well as US-based tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to these countries and processed there. We would like to point out that no level of data protection comparable to that of the EU can be guaranteed in privacy-insecure third countries.

We would like to inform you that the USA, as a safe third country, generally maintains a level of data protection comparable to that of the EU. Data transfer to the USA is permissible if the recipient holds certification under the “EU-US Data Privacy Framework” (DPF) or has appropriate additional safeguards. Information on transfers to third countries, including the recipients of the data, can be found in this privacy policy.

Recipients of Personal Data

In the course of our business activities, we collaborate with various external entities. Sometimes, the transmission of personal data to these external entities is necessary. We only disclose personal data to external entities if it is necessary for the performance of a contract, if we are legally obligated to do so (e.g., disclosure of data to tax authorities), if we have a legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR in the disclosure, or if another legal basis permits data disclosure. When using data processors, we only disclose personal data of our customers based on a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.

Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent that has already been given at any time. The legality of the data processing carried out prior to the revocation remains unaffected by the revocation.

Right to Object to Data Collection in Special Cases and to Direct Marketing (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6 PARA. 1 LIT. E OR F GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION AT ANY TIME; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS FOR THE PROCESSING CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL CEASE PROCESSING YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS OR FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 PARA. 1 GDPR).

IF YOUR PERSONAL DATA ARE PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING, INCLUDING PROFILING RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21 PARA. 2 GDPR).

Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.

Right to Data Portability

You have the right to receive the personal data concerning you, which we process based on your consent or for the performance of a contract, in a structured, commonly used, and machine-readable format, and to have those data transmitted to another controller, where technically feasible.

Information, Correction, and Deletion

You have the right, within the framework of the applicable legal provisions, to obtain free information about your stored personal data, their origin and recipients, the purpose of data processing, and, if applicable, a right to correction or deletion of these data. For this purpose and for any further questions regarding personal data, you can contact us at any time.

Right to Restriction of Processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:

  • If you contest the accuracy of your personal data stored by us, we usually need time to verify this. During the verification period, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
  • If we no longer need your personal data, but you need them for the exercise, defense, or assertion of legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
  • If you have objected pursuant to Art. 21 para. 1 GDPR, a balancing of interests must be carried out between your interests and ours. As long as it is not yet clear whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data – apart from their storage – may only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.

SSL or TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

  1. Data Collection on This Website

Cookies

Our website uses so-called “cookies.” Cookies are small data packets that do not harm your device. They are either temporarily stored for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted after your visit ends. Permanent cookies remain stored on your device until you delete them yourself or automatic deletion occurs through your web browser.

Cookies can originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).

Cookies serve various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies may be used for evaluating user behavior or for advertising purposes.

Cookies that are necessary for carrying out the electronic communication process, for providing certain functions requested by you (e.g., for the shopping cart function), or for optimizing the website (e.g., cookies for measuring web traffic) (necessary cookies) are stored based on Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent for the storage of cookies and similar recognition technologies has been requested, the processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG); the consent can be revoked at any time.

You can configure your browser to inform you about the setting of cookies and only allow cookies in individual cases, accept cookies for specific cases or generally exclude them, as well as activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.

You can find out which cookies and services are used on this website in this privacy policy.

Consent with Complianz

Our website uses the consent technology of Complianz to obtain your consent for storing certain cookies on your device or for the use of certain technologies and to document them in compliance with data protection regulations. The provider of this technology is Complianz B.V., Kalmarweg 14-5, 9723 JG Groningen, Netherlands (hereinafter “Complianz”).

Complianz is hosted on our servers, so no connection is made to the servers of the Complianz provider. Complianz stores a cookie in your browser to assign the granted consents or their revocation. The data collected in this way is stored until you request deletion from us, delete the Complianz cookie yourself, or the purpose for data storage no longer applies. Mandatory legal retention periods remain unaffected.

The use of Complianz is for obtaining the legally required consents for the use of cookies. The legal basis for this is Art. 6 para. 1 lit. c GDPR.

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

A merging of this data with other data sources is not carried out.

The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of his website – for this purpose, the server log files must be recorded.

Contact Form

If you send us inquiries via the contact form, your information from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We will not pass on this data without your consent.

The processing of this data is based on Art. 6 para. 1 lit. b GDPR, provided your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries sent to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; the consent can be revoked at any time.

The data entered by you in the contact form will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after the completed processing of your inquiry). Mandatory legal provisions – in particular, retention periods – remain unaffected.

Inquiry by Email, Phone, or Fax

If you contact us by email, phone, or fax, your inquiry including all resulting personal data (name, inquiry) will be stored and processed by us for the purpose of processing your request. We will not pass on this data without your consent.

The processing of this data is based on Art. 6 para. 1 lit. b GDPR, provided your request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of the inquiries sent to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested; the consent can be revoked at any time.

The data you send us via contact inquiries will remain with us until you request us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after the completed processing of your request). Mandatory legal provisions – in particular, legal retention periods – remain unaffected.

  1. Analysis Tools and Advertising

Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Tag Manager is a tool that enables us to integrate tracking or analytics tools and other technologies on our website. Google Tag Manager itself does not create user profiles, store cookies, or conduct independent analyses. It is solely used for the management and deployment of the tools integrated through it. However, Google Tag Manager does collect your IP address, which may also be transferred to Google’s parent company in the United States.

The use of Google Tag Manager is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the quick and uncomplicated integration and management of various tools on their website. If consent has been obtained, processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, to the extent that the consent includes the storage of cookies or access to information on the user’s terminal device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards for data processing in the US. Each company certified under the DPF is committed to adhering to these data protection standards. Further information can be obtained from the provider at the following link:

Google Analytics

This website uses features of the web analytics service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics enables the website operator to analyze the behavior of website visitors. In doing so, the website operator receives various usage data, such as page views, time spent on the site, operating systems used, and the user’s origin. This data is aggregated into a user ID and assigned to the respective device of the website visitor.

Furthermore, with Google Analytics, we can record your mouse movements, scrolling, and clicks, among other things. Google Analytics also employs various modeling approaches to complement the collected data and utilizes machine learning technologies for data analysis.

Google Analytics uses technologies that enable the recognition of the user for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). The information collected by Google about the use of this website is usually transmitted to a Google server in the United States and stored there.

The use of this service is based on your consent under Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.

The transfer of data to the USA is based on the standard contractual clauses of the European Commission. Details can be found here: Google Analytics Data Processing Terms.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards for data processing in the US. Each company certified under the DPF is committed to adhering to these data protection standards. Further information can be obtained from the provider at the following link: DPF Certification Details

Browser-Plugin

You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at the following link: Browser Plugin Link.

For more information on how Google Analytics handles user data, please refer to Google’s privacy policy: Google Analytics Privacy Policy.

Data Processing Agreement

We have entered into a data processing agreement with Google and fully comply with the strict requirements of the German data protection authorities when using Google Analytics.

Google Optimize

We have integrated Google Optimize on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as Google Optimize).

Google Optimize allows us to optimize our website by conducting tests (A/B testing) and personalizing the website. For this purpose, Google Optimize processes the IP address of website visitors. The collected personal data may then be further processed by additional analytics tools.

The use of Google Optimize is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in optimizing their online presence. If consent has been obtained, the processing is carried out exclusively based on Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, to the extent that the consent includes the storage of cookies or access to information on the user’s device (e.g., for device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.

For further details, please refer to the provider’s privacy policy at https://business.safety.google/adsprocessorterms/.

The data transfer to the USA is based on the Standard Contractual Clauses of the European Commission. Details can be found here: https://policies.google.com/privacy/frameworks and https://privacy.google.com/businesses/controllerterms/mccs/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA aimed at ensuring compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For further information, please visit the following link provided by the provider:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active.

Data Processing:

We have entered into a data processing agreement (DPA) for the use of the above-mentioned service. This is a legally required contract that ensures that this service processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

Google Ads:

The website operator uses Google Ads. Google Ads is an online advertising program provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Ads allows us to display advertisements in the Google search engine or on third-party websites when the user enters specific search terms on Google (keyword targeting). Furthermore, targeted advertisements can be displayed based on user data available to Google (e.g., location data and interests) (audience targeting). As website operators, we can quantitatively analyze this data by, for example, analyzing which search terms led to the display of our advertisements and how many ads resulted in corresponding clicks.

The use of this service is based on your consent under Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. The consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the European Commission. Details can be found here: https://policies.google.com/privacy/frameworks und https://privacy.google.com/businesses/controllerterms/mccs/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards for data processing in the USA. Every company certified under the DPF is committed to adhering to these data protection standards. For further information, you can contact the provider using the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google Ads Remarketing

This website utilizes the features of Google Ads Remarketing. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

With Google Ads Remarketing, we can assign specific target groups to individuals who interact with our online offerings, allowing us to subsequently display interest-based advertising to them within the Google advertising network (remarketing or retargeting).

Furthermore, the advertising target groups created with Google Ads Remarketing can be linked to Google’s cross-device capabilities. This enables interest-based, personalized advertising messages that have been tailored to your previous usage and browsing behavior on one device (e.g., mobile phone) to also be displayed on another of your devices (e.g., tablet or PC).

If you have a Google account, you can opt out of personalized advertising using the following link:

https://www.google.com/settings/ads/onweb/.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. This consent can be revoked at any time.

For further information and the privacy policy, please refer to Google’s privacy policy at:

https://policies.google.com/technologies/ads?hl=de.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA aimed at ensuring compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For further information, you can contact the provider at the following link:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Audience targeting with customer matching

For audience targeting, we use Google Ads Remarketing’s customer matching feature. In this process, we provide certain customer data (e.g., email addresses) from our customer lists to Google. If these customers are Google users and logged into their Google accounts, they will be shown relevant advertising messages within the Google network (e.g., on YouTube, Gmail, or in the search engine).

Google Conversion Tracking

This website uses Google Conversion Tracking. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

Google Conversion Tracking allows Google and us to recognize whether the user has taken certain actions. For example, we can evaluate which buttons on our website have been clicked frequently and which products have been viewed or purchased most often. This information is used to create conversion statistics. We learn the total number of users who clicked on our ads and what actions they took. We do not receive any information that allows us to personally identify the user. Google itself uses cookies or similar recognition technologies for identification purposes.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. The consent can be revoked at any time.

More information about Google Conversion Tracking can be found in Google’s privacy policy:

https://policies.google.com/privacy?hl=de.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For further information, you can contact the provider using the following link:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Meta-Pixel (formerly Facebook Pixel)

This website uses the visitor action pixel from Facebook/Meta for conversion tracking. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, the collected data is also transferred to the USA and other third countries.

This allows tracking of the actions of website visitors who have been redirected to the provider’s website after clicking on a Facebook ad. This enables the effectiveness of Facebook ads to be evaluated for statistical and market research purposes, and future advertising measures to be optimized.

The use of this service is based on your consent according to Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TTDSG. The consent can be revoked at any time.

We utilize the advanced matching feature within the Meta Pixel.

The advanced matching feature allows us to transmit various types of data (e.g., location, state, postal code, hashed email addresses, names, gender, date of birth, or phone number) of our customers and prospects that we collect through our website to Meta (Facebook). By activating this feature, we can further tailor our advertising campaigns on Facebook to individuals who are interested in our offerings. Additionally, the advanced matching enhances the attribution of website conversions and expands Custom Audiences.

To the extent that personal data is collected on our website using the tool described here and transmitted to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited solely to the collection of the data and its transmission to Facebook. The processing carried out by Facebook after transmission is not part of the joint responsibility. The obligations jointly incumbent upon us have been recorded in an agreement on joint processing.

The data transfer to the USA is based on the standard contractual clauses of the European Commission. Details can be found here:

https://www.facebook.com/legal/EU_data_transfer_addendum und https://de-de.facebook.com/help/566994660333381.

You can find further information on protecting your privacy in Facebook’s privacy policy:

https://de-de.facebook.com/about/privacy/.

You can also activate the remarketing function “Custom Audiences” in the ad settings section under https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen deactivate it. You must be logged in to Facebook to do this.

If you do not have a Facebook account, you can deactivate usage-based advertising from Facebook on the website of the European Interactive Digital Advertising Alliance. http://www.youronlinechoices.com/de/praferenzmanagement/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF commits to adhering to these data protection standards. For further information, you can visit the provider’s website at the following link:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

Facebook Conversion API

We have integrated the Facebook Conversion API on this website. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the collected data may also be transferred to the USA and other third countries.

The Facebook Conversion API allows us to track the interactions of website visitors with our website and transmit them to Facebook to improve advertising performance on Facebook.

For this purpose, the following data is collected, in particular: the time of access, the accessed webpage, your IP address and your user agent, as well as any other specific data (such as purchased products, value of the shopping cart, and currency). A complete overview of the data that can be collected can be found here:

https://developers.facebook.com/docs/marketing-api/conversions-api/parameters.

The use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. This consent can be revoked at any time.

Insofar as personal data is collected on our website and forwarded to Facebook using the tool described here, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, share responsibility for this data processing (Art. 26 GDPR). This joint responsibility is limited exclusively to the collection of data and its transmission to Facebook. The processing carried out by Facebook after the data has been forwarded is not part of the joint responsibility. Our joint obligations have been documented in a joint processing agreement. You can find the wording of the agreement here:

https://www.facebook.com/legal/controller_addendum.

According to this agreement, we are responsible for providing data protection information when using the Facebook tool and for the data protection-compliant implementation of the tool on our website. Facebook is responsible for the data security of its products. You can exercise your data subject rights (e.g., requests for information) regarding the data processed by Facebook directly with Facebook. If you exercise your data subject rights with us, we are obliged to forward them to Facebook.

Details regarding the data transfer to the USA are based on the standard contractual clauses of the European Commission. Details can be found here:

https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

In the privacy notices of Facebook, you can find further information on protecting your privacy:

https://de-de.facebook.com/about/privacy/.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For further information, you can visit the following link:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

Auftragsverarbeitung

We have entered into a contract for order processing (AVV) for the use of the service mentioned above. This is a legally required contract that ensures that this service processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR.

Facebook Custom Audiences

We utilize Facebook Custom Audiences. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

When you visit or use our websites and apps, avail yourself of our free or paid offerings, transmit data to us, or interact with the Facebook content of our company, we collect your personal data. If you grant us consent to use Facebook Custom Audiences, we will transmit this data to Facebook, enabling Facebook to display tailored advertising to you. Additionally, your data may be used to define target audiences (Lookalike Audiences).

Facebook processes this data as our processor. Details can be found in the Facebook user agreement:

https://www.facebook.com/legal/terms/customaudience.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here:

https://www.facebook.com/legal/terms/customaudience und https://www.facebook.com/legal/terms/dataprocessing.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA, which is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

  1. Plugins and Tools

Font Awesome

This site uses Font Awesome to ensure consistent display of fonts and icons. The provider is Fonticons, Inc., 6 Porter Road Apartment 3R, Cambridge, Massachusetts, USA.

When a page is accessed, your browser loads the required fonts into its cache to display text, fonts, and symbols correctly. For this purpose, the browser you are using must establish a connection to the servers of Font Awesome. As a result, Font Awesome becomes aware that this website has been accessed via your IP address. The use of Font Awesome is based on Art. 6 Para. 1 lit. f GDPR. We have a legitimate interest in presenting the typeface uniformly on our website. If consent has been requested, processing will be carried out exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TTDSG, provided that consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) in accordance with TTDSG. Consent can be revoked at any time.

If your browser does not support Font Awesome, a standard font from your computer will be used.

For more information about Font Awesome, please visit [link to Font Awesome] and review the Font Awesome Privacy Policy.

https://fontawesome.com/privacy.

Google Maps

This site uses the Google Maps mapping service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

To use the features of Google Maps, it is necessary to store your IP address. This information is typically transmitted to a Google server in the United States and stored there. The provider of this site has no influence on this data transmission. When Google Maps is activated, Google may use Google Fonts for the purpose of uniform font representation. When Google Maps is accessed, your browser loads the necessary web fonts into its browser cache to display texts and fonts correctly.

The use of Google Maps is in the interest of an attractive presentation of our online offerings and easy location of the places we specify on the website. This represents a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR. If consent has been requested, processing will be carried out exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TTDSG, provided that consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) in accordance with TTDSG. Consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the European Commission. Details can be found here:

https://privacy.google.com/businesses/gdprcontrollerterms/ und https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.

More information about how user data is handled can be found in Google’s privacy policy:

https://policies.google.com/privacy?hl=de.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For further information, you can contact the provider via the following link:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Google reCAPTCHA

We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

reCAPTCHA is used to check whether the data input on this website (e.g., in a contact form) is done by a human or by an automated program. For this purpose, reCAPTCHA analyzes the behavior of the website visitor based on various characteristics. This analysis starts automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various information (e.g., IP address, duration of the website visit, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.

The reCAPTCHA analyses run entirely in the background. Website visitors are not informed that an analysis is taking place.

The storage and analysis of the data are based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its web offerings against abusive automated spying and spam. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) in accordance with the TTDSG. The consent can be revoked at any time.

For more information on Google reCAPTCHA, please refer to Google’s Privacy Policy and Terms of Use at the following links:

https://policies.google.com/privacy?hl=de and https://policies.google.com/terms?hl=de.

The company is certified under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the United States aimed at ensuring compliance with European data protection standards for data processing in the USA. Every company certified under the DPF commits to adhering to these data protection standards. For further information, you can contact the provider via the following link:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active

Wordfence

We have integrated Wordfence on this website. The provider is Defiant Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA (hereinafter “Wordfence”).

Wordfence is used to protect our website from unauthorized access or malicious cyber attacks. For this purpose, our website establishes a permanent connection to the servers of Wordfence so that Wordfence can synchronize its databases with the accesses made on our website and, if necessary, block them.

The use of Wordfence is based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in effectively protecting his website from cyber attacks. If consent has been requested, processing is carried out exclusively on the basis of Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information on the user’s device (e.g., device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.

The data transfer to the USA is based on the standard contractual clauses of the European Commission. Details can be found here:

https://www.wordfence.com/help/general-data-protection-regulation/.

Data Processing Agreement

We have entered into a Data Processing Agreement (DPA) for the use of the service mentioned above. This is a legally required agreement ensuring that the provider processes the personal data of our website visitors only according to our instructions and in compliance with the GDPR (General Data Protection Regulation).