Privacy Policy
We are delighted that you are visiting our website. The protection and security of your personal information whilst using our website is very important to us. We would therefore like to take this opportunity to inform you about which of your personal data we collect when you visit our website and for what purposes this data is used. Personal data refers to specific details relating to the personal or factual circumstances of an identified or identifiable natural person (data subject), e.g. name, address, email addresses, user behaviour. This is therefore data that enables us to identify you. In addition, you will also find some information here regarding data processing activities outside this website (e.g. video conferences or newsletters).
Responsible for data processing
Data controller
For the processing of personal data within the meaning of the EU General Data Protection Regulation (GDPR)
Finance for Expats GmbH
Aronstabweg 2
30559 Hanover
Telephone: +49 (511) 5151 2950
Email: info@financeforexpats.de
Data Protection Officer
exkulpa gmbh
Waldfeuchterstr. 266
52525 Heinsberg
Telephone: 02452 / 99 33 11
General information
In addition to the data you actively provide to us on this site (e.g. via our contact form), we collect certain technical data. This so-called metadata is automatically transmitted from your computer to our servers as soon as you access our website (including browser, operating system and timestamps). We use this data to ensure our website is displayed correctly. In addition, we may collect data via integrated third-party providers (e.g. for external media such as map services or analytics tools). We explain the specific purposes and legal bases for this in the course of this privacy policy.
Retention period
Unless a specific retention period is stated within this privacy policy, we will retain your personal data for as long as the purpose of the data processing remains valid. If you submit a valid request for erasure or withdraw your consent, we will erase your data. Statutory retention obligations remain unaffected.
Legal bases for data processing
If you have consented to data processing, the processing of your personal data is carried out on the basis of Article 6(1)(a) of the GDPR or Article 9(2)(a) of the GDPR, where special categories of data are processed in accordance with Article 9(1) of the GDPR. Where you have given your explicit consent to the transfer of personal data to third countries, the data is also processed in accordance with Article 49(1)(a) of the GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g. through device fingerprinting), data processing also takes place on the basis of Section 25(1) of the TDDDG. You may withdraw your consent at any time. Where your data is necessary for the performance of a contract or for the implementation of pre-contractual measures, we process your data in accordance with Article 6(1)(b) of the GDPR. Furthermore, we process your data where this is necessary to comply with a legal obligation, on the basis of Article 6(1)(c) of the GDPR. Data processing may also take place on the basis of our legitimate interest in accordance with Article 6(1)(f) of the GDPR. The following sections of this privacy policy provide information on the respective legal bases in individual cases.
Note on data transfers to third countries and US companies without DPF certification
Please note that we use tools provided by companies based in third countries where data protection standards are not adequate or in the USA, and which are not covered by the EU-US Data Protection Framework (DPF). When using these tools, your personal data may be transferred to and processed in these countries. Please note that in these third countries, a level of data protection comparable to that of the EU cannot be guaranteed. We would like to clarify that the US generally offers a level of data protection comparable to that of the EU. The transfer of data to the US is permitted if the recipient holds DPF certification or provides appropriate additional safeguards. Information on data transfers to third countries, including data recipients, can be found in our Privacy Policy.
Automated decision-making
Your personal data is not processed for the purposes of automated decision-making.
Your rights
As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: You have the right to request confirmation from us as to whether your personal data is being processed and, if so, to receive further information about the processing and copies of the data being processed (Art. 15 GDPR).
- Right to rectification: You have the right to request the immediate rectification of any inaccurate personal data concerning you and, where applicable, the completion of any incomplete personal data (Article 16 of the GDPR).
- Right to erasure: You have the right to request the erasure without undue delay of personal data concerning you where the legal conditions are met, in particular where the data is no longer necessary for the purposes for which it was collected and the processing is unlawful (Art. 17 GDPR).
- Right to restriction of processing: You have the right to request that we restrict the processing of your personal data where the legal conditions are met, in particular where you contest the accuracy of the data, the processing is unlawful and you object to erasure (Article 18 of the GDPR).
- Right to data portability: You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided this is technically feasible (Article 20 of the GDPR).
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you, where the processing is carried out on the basis of Article 6(1)(e) or (f) of the GDPR (Article 21 of the GDPR).
- Right to withdraw consent: You have the right to withdraw your consent to the processing of personal data at any time with effect for the future. Withdrawing your consent does not affect the lawfulness of processing carried out on the basis of your consent prior to its withdrawal (Article 7(3) of the GDPR).
- Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR (Article 77 of the GDPR).
Further data processing operations
General information obligations
This information is intended for customers, prospective customers, suppliers and employees. We process your personal data for the following purposes:
- To fulfil our contractual obligations towards you (Article 6(1)(b) of the GDPR).
- To carry out pre-contractual obligations (Article 6(1)(b) of the GDPR).
- To respond to enquiries (Article 6(1)(b) of the GDPR).
- Where you have given us your consent to process your personal data for specific purposes (such as to receive our newsletter), data processing takes place on the basis of your consent (Article 6(1)(a) of the GDPR).
- To comply with legal obligations to which our company is subject (Article 6(1)(c) of the GDPR).
- Where necessary, we also process your data to safeguard our legitimate interests, in particular to assert legal claims and defend ourselves in legal disputes, or to ensure IT security; to consult with and exchange data with credit reference agencies to assess creditworthiness and default risks; for direct marketing and market research, provided you have not objected to the use of your data for this purpose; in connection with measures for business management and the further development of services and products, in connection with measures for product and sales optimisation, in connection with risk management measures, and for the prevention or investigation of criminal offences (Article 6(1)(f) of the GDPR).
Categories of recipients of personal data
Within our company, only those employees who absolutely need the data to carry out their duties have access to it (the ‘need-to-know’ principle). Individual processes and services are carried out by carefully selected service providers, commissioned in accordance with data protection regulations, who are based within the EEA. Where service providers commissioned by us gain access to personal data whilst performing their services, data processing agreements have been concluded with them in accordance with Article 28(3) of the GDPR.
Duration of data retention
The data we process is stored for the duration of the contractual relationship and its fulfilment, whilst complying with statutory retention periods. These include, in particular, retention obligations under commercial and tax law as set out in the German Commercial Code (HGB) and the German Fiscal Code (AO). The standard retention and documentation periods amount to up to ten years. If no contractual relationship is established, we process the data only for as long as is necessary for the specific purpose.
Cookies
Cookies are small text files stored by your browser on your device to retain certain information whilst you are using the website. Cookies enable us to improve various aspects of our website and make your visit more convenient. There are various types of cookies, each serving different purposes. Temporary cookies, also known as session cookies, are stored only for the duration of your use of the website and are automatically deleted when you close your browser. Persistent cookies, on the other hand, remain stored on your device for a longer period and enable us to recognise you and your preferences when you visit the website again. Cookies can also be categorised as first-party cookies and third-party cookies. First-party cookies are set by our website, whilst third-party cookies are set by other websites or service providers whose content is integrated into our website, such as plugins or analytics tools. Cookies are used for various purposes, such as ensuring the website functions properly, storing user settings, compiling anonymous statistics on user behaviour, or displaying personalised content and advertising. The legal basis for the use of cookies varies depending on the purpose of the cookies. In some cases, the setting of cookies is based on your legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to make our website functional and user-friendly. As the website operator, we have a legitimate interest in storing necessary cookies to ensure the technically flawless and optimised provision of our services. Where we seek your consent to the use of cookies, processing is carried out on the basis of Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. You may withdraw your consent at any time.
CookieConsent (orestbida)
We use the open-source solution ‘CookieConsent’ (version 3, developed by orestbida) to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies, and to document your choices in accordance with data protection regulations. The library is loaded onto our website via the JSDelivr CDN; it runs locally in your browser and does not transmit any personal data to the software developer. When you visit our website, a cookie banner is displayed. You can accept all cookies, reject non-essential cookies, or manage your settings by category (e.g. essential cookies and analytics cookies). Your consent choices are stored locally in your browser (e.g. via cookies or local storage) so that your settings can be taken into account on subsequent visits. CookieConsent is used to obtain the legally required consents for the use of certain technologies. The legal basis for this is Article 6(1)(c) of the GDPR. Further information on CookieConsent can be found in the project documentation: https://cookieconsent.orestbida.com/.
Data processing in detail
Below, we provide information on the individual processing operations, the scope and purpose of data processing, the legal basis, the obligation to provide your data and the respective retention period. No automated decision-making, including profiling, takes place in individual cases.
Provision of the website
When you access and use our website, we collect the personal data that your browser automatically transmits to our server. The following information is temporarily stored in a so-called log file:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the file accessed
- Website from which the access originated (referrer URL)
- Browser used and, where applicable, your computer’s operating system, as well as the name of your internet service provider
Our website is not hosted by us directly, but by a service provider who processes the aforementioned data on our behalf in accordance with Article 28 of the GDPR for the purpose of providing the website.
The use of the hosting provider is for the purpose of fulfilling our contractual obligations towards our potential and existing customers (Article 6(1)(b) of the GDPR) and in the interest of ensuring the secure, fast and efficient provision of our online services by a professional provider (Article 6(1)(f) of the GDPR).
We use the following hosting provider:
Firebase Google Inc.
Google Ireland Limited
Gordon House
Barrow Street, Dublin 4
Ireland
Hetzner (content management system / CMS)
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
Our website content is managed via a CMS hosted by Hetzner (cms.webstra.de). Hetzner processes personal data on our behalf in accordance with Article 28 of the GDPR. For details, please view Hetzner’s privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz.
We use Hetzner on the basis of Article 6(1)(f) of the GDPR. We have a legitimate interest in the reliable operation of our content management infrastructure. We have concluded a data processing agreement (DPA) with Hetzner for the use of this service.
Contact form
Nature and scope of processing
When you send us enquiries (e.g. via the contact form, by email or by telephone), we store all the data resulting from this (e.g. name, email address, subject of the enquiry, etc.). We require this data to process your enquiry and to be able to answer any follow-up questions . We will not pass on this data without your consent.
Purpose and legal basis
The processing of this data is carried out on the basis of Article 6(1)(b) of the GDPR, provided that your enquiry relates to the performance of a contract or is necessary for the implementation of pre-contractual measures. Otherwise, the processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Article 6(1)(f) of the GDPR) or on your consent (Article 6(1)(a) of the GDPR) if you have previously given it.
Retention period
The data you enter in the contact form will remain with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your enquiry has been fully processed). Mandatory legal provisions – in particular retention periods – remain unaffected.
Contact form for job applicants
Nature and scope of processing
We collect and process the personal data of job applicants. Such data processing may also take place electronically, for example, when applicants submit their application documents to us by email or via a web form on our website. On our website, we offer you the option of submitting applications for advertised vacancies to us by email.
Purpose and legal basis
We process applicants’ personal data in accordance with legal requirements for the purpose of establishing an employment relationship (Article 6(1)(b) of the GDPR). You are not obliged to provide us with this data. However, without this data, we cannot carry out an application process with you. If your application is successful, the data you have submitted will be stored in our data processing systems on the basis of Article 6(1)(b) of the GDPR and, insofar as you provide us with special categories of personal data, such as health information, on the basis of Article 9(2)(b) for the purpose of carrying out the employment relationship. We also use the professional networking services LinkedIn and XING to approach potential candidates. In this regard, the operators of these networks act on our behalf as data processors in accordance with our instructions. The legal basis for data processing when approaching potential candidates on our behalf is Article 6(1)(f) of the GDPR (our legitimate interests). If, as a result of such an approach, you send us your application, we will process your data for the purpose of establishing an employment relationship as described above, on the basis of Article 6(1)(b) of the GDPR.
Retention period
In the event of a rejection, your data will be stored for a period of 6 months following the conclusion of the application process. This is done to safeguard our legitimate interests, in order to assess whether we require the data to defend against any potential claims arising in connection with the application process. We are then obliged to delete or anonymise your data. In this case, the data will only be available to us as so-called metadata without any direct personal reference for statistical analysis (for example, the proportion of female and male applicants, the number of applications per period, etc.). If it becomes apparent that further storage of the data is necessary after the expiry of the six-month period to safeguard our legitimate interests (e.g. due to an impending or pending legal dispute), the data will only be deleted once the purpose for its continued retention no longer applies. The legal basis for this further data retention is our legitimate interests in the assertion, exercise or defence of civil law claims (Article 6(1)(f) of the GDPR in conjunction with Section 24(1)(2) of the BDSG or, where special categories of personal data are stored, Article 9(2)(f) of the GDPR in conjunction with Section 24(2) of the BDSG).
Inclusion in the candidate pool
As part of the application process, we offer applicants the opportunity to be included in our ‘talent pool’ for a period of 24 months on the basis of consent within the meaning of Article 6(1)(a) and Article 9(2)(a) of the GDPR. If you have provided special categories of personal data in your application, such as health information, your consent also extends to this data. You are not obliged to provide us with your application data for our talent pool. However, without this data, we cannot consider you for future vacancies unless you submit a new application. Consent to the inclusion of application data in the Talent Pool is voluntary and may be withdrawn at any time with future effect. Withdrawal of consent does not affect the lawfulness of any data processing carried out on the basis of that consent prior to its withdrawal. Your application documents will be deleted from the talent pool at the latest upon expiry of the retention period, or in the event of a withdrawal of consent or the acceptance of a job offer from one of the companies responsible for the talent pool. If, as part of the application process, you receive and accept an offer of employment with us, we or the relevant company will store the personal data collected during the application process for the purpose of managing the employment relationship. The legal basis for this data processing is Article 6(1)(b) of the GDPR or, insofar as you provide us with special categories of personal data, such as health information, Article 9(2)(b).
Newsletter
We offer our newsletter on this website. If you wish to subscribe to it, we require your email address and further information to verify that the email address belongs to you and that you consent to receiving the newsletter. No other personal data is collected unless you provide it voluntarily (e.g. name, telephone number, place of residence, etc.). When processing the data you provide when signing up for the newsletter, we rely exclusively on your consent under Article 6(1)(a) of the GDPR as the legal basis. You may withdraw your consent to the processing and storage of your personal data at any time (e.g. via the ‘Unsubscribe’ link in the newsletter) with effect for the future. We store the personal data you have provided for the purpose of receiving the newsletter until you unsubscribe from the newsletter via us or the mailing service provider. This does not apply to data we have stored about you for other purposes. If you unsubscribe from the newsletter mailing list, your email address will be stored by us or the mailing service provider on a blacklist for an indefinite period. This is done to prevent future mailings from being sent to you. The data on the blacklist is used exclusively for this purpose and is not combined with any other data. This is not only in your interest but also in our legitimate interest under Article 6(1)(f) of the GDPR to fulfil our legal obligations regarding the sending of newsletters. You may object to this storage provided that your personal interests override our legitimate interest.
Brevo
This website uses Brevo to send newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. Brevo is a service for organising and analysing newsletter distribution. The data you provide to subscribe to the newsletter is stored on Brevo’s servers in Germany. Brevo enables us to analyse our newsletter campaigns. For example, we can see whether a newsletter message has been opened and which links have been clicked. This allows us to identify which links have been clicked on most frequently. Brevo also allows us to group newsletter recipients into different categories (‘clustering’). For example, newsletter recipients can be grouped by age, gender or place of residence. This enables us to tailor the newsletters more effectively to the respective target groups. If you do not wish Brevo to analyse your data, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message. Further information on Brevo’s features can be found here: https://www.brevo.com/de/newsletter-software/. Data processing is carried out on the basis of your consent (Article 6(1)(a) of the GDPR). You may withdraw this consent at any time. The lawfulness of any data processing operations that have already taken place remains unaffected by the withdrawal. The data stored by us for the purpose of sending the newsletter will be retained by us or the newsletter service provider until you unsubscribe from the newsletter, and will be deleted from the distribution list once you have unsubscribed. Data stored by us for other reasons remains unaffected by this. After you unsubscribe from the newsletter list, your email address may be stored by us or the newsletter service provider on a block list to prevent future mailings. The data from the block list is used solely for this purpose and is not combined with any other data. This serves both your and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). Storage on the block list is not time-limited. You may object to this storage provided that your interests override our legitimate interest. Further information on data protection at Brevo can be found here: https://www.brevo.com/de/legal/privacypolicy/. To ensure that personal data is processed in accordance with our guidelines and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Presence on social media platforms
We maintain public profiles on various social media platforms via our website. You can find more detailed information on the social media platforms we use in the relevant sections of our privacy policy. Social networks such as Facebook, Twitter and others can analyse your user behaviour in detail when you visit their websites or a website featuring integrated social media content (e.g. ‘Like’ buttons or advertising banners). Visiting our social media pages triggers numerous data processing operations relevant to data protection: If you are logged into your social media account and visit our social media presence, the operator of the social media portal may link this visit to your user account. However, your personal data may also be collected even if you are not logged in or do not have an account with the relevant social media portal. In this case, data is collected, for example, via cookies stored on your device or by recording your IP address. Using the data collected in this way, the operators of the social media platforms can create user profiles that record your preferences and interests. This enables interest-based advertising to be displayed to you both on and off the respective social media platform. If you have an account with the relevant social network, interest-based advertising may be displayed to you at on all devices on which you are logged in or have previously been logged in. Please note that we are unable to track all data processing activities on social media platforms. Depending on the provider, further processing operations may therefore be carried out by the operators of the social media platforms. For further details, please refer to the terms of use and privacy policies of the respective social media platforms.
Legal basis for data processing
Our social media accounts serve to ensure the most comprehensive online presence possible. This constitutes a legitimate interest within the meaning of Article 6(1)(f) of the GDPR. The analysis processes initiated by the social networks may be based on different legal grounds, which must be specified by the operators of the social networks (e.g. consent within the meaning of Article 6(1)(a) of the GDPR).
Data controller and exercising rights
When you visit our social media pages (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You may, in principle, exercise your rights (right of access, rectification, erasure, restriction of processing, data portability and the right to lodge a complaint) both with us and with the operator of the relevant social media portal (e.g. with Facebook). Despite our joint responsibility with the social media platform operators, we do not have full control over the data processing operations carried out by the social media platforms. Our options depend largely on the corporate policy of the respective provider.
Duration of data storage
Data collected directly by us via our social media presence will be deleted from our systems as soon as you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory legal provisions – in particular retention periods – remain unaffected. We have no influence over the duration for which your data is stored by the operators of social networks for their own purposes. For further details, please contact the operators of the social networks directly (e.g. via their privacy policy, see below).
Facebook page
Our company has a profile on Facebook. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter ‘Meta’). According to Meta, the data collected is also transferred to the USA and other third countries. We have entered into a joint processing agreement (Controller Addendum) with Meta. This agreement sets out which data processing operations we and Meta are responsible for when you visit our Facebook page. You can view the agreement via the following link: https://www.facebook.com/legal/terms/page_controller_addendum. You can adjust your advertising settings yourself in your user account. To do so, click on the following link and log in: https://www.facebook.com/settings?tab=ads. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when data is processed in the USA. Certification under the DPF obliges companies to adhere to these data protection standards. Data transfers to the US are based on the European Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381. For further information, please refer to Facebook’s privacy policy: https://www.facebook.com/about/privacy/.
Instagram page
Our company has a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards. Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Further details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://help.instagram.com/519522125107875 and https://de-de.facebook.com/help/566994660333381. For further information on how your personal data is handled, please refer to Instagram’s privacy policy: https://help.instagram.com/519522125107875.
LinkedIn page
Our company has a profile on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. LinkedIn uses advertising cookies. If you wish to disable LinkedIn advertising cookies, please use the following link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to adhere to these data protection standards. Data transfers to the US are based on the European Commission’s Standard Contractual Clauses. Further details can be found here: https://www.linkedin.com/legal/l/dpa and https://www.linkedin.com/legal/l/eu-sccs. For further information on how your personal data is handled, please refer to LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.
Communication via WhatsApp
To communicate with our customers and other third parties, we use, amongst other things, the instant messaging service WhatsApp Business, provided by WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. When you communicate with us via WhatsApp, the chats are end-to-end encrypted. This is intended to prevent WhatsApp or third parties from gaining access to the content of the chat. However, WhatsApp does have access to metadata generated during the communication process (e.g. sender, recipient and time). WhatsApp shares the personal data it collects with its parent company, Meta, which is based in the USA. Further details on data processing can be found in WhatsApp’s Privacy Policy at: https://www.whatsapp.com/legal/#privacy-policy. The use of WhatsApp is based on our legitimate interest in communicating as quickly and effectively as possible with customers, prospective customers and other business and contractual partners (Article 6(1)(f) of the GDPR). If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; you may withdraw your consent at any time. The content of communications exchanged via WhatsApp remains with us until you request its deletion, withdraw your consent to its storage, or the purpose for storing the data no longer applies (e.g. once your enquiry has been fully processed). Mandatory legal provisions – in particular retention periods – remain unaffected. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. We have configured our WhatsApp accounts so that there is no automatic data synchronisation with the address book on the smartphones in use. To ensure that personal data is processed in accordance with our guidelines and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Video conferences
Data processing
We use online conferencing tools to communicate with our customers. The specific tools we use are listed below. When you communicate with us via video or audio conference, your personal data is collected and processed by us and by the provider of the relevant tool. The tools collect the data you provide, including your email address and telephone number. They also process the duration of the conference, when you joined the conference, the number of participants and other metadata. In addition, the tool provider processes all technical data required to facilitate the conference. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and the type of connection. When you share content on this service, it is stored on the providers’ servers. This includes cloud recordings, chat messages, voice messages, and photos and videos that you have shared whilst using this service. Please note that we do not have full control over the data processing operations carried out by the tools used. For further details on data processing by the conferencing tools, please refer to the privacy policies of the respective tools used.
Purpose and legal basis
The conferencing tools are used to communicate with prospective or existing contractual partners or to offer specific services to our customers (Article 6(1)(b) of the GDPR). Furthermore, the use of these tools serves to generally simplify and speed up communication with us or our company (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). If you have previously given your consent to data processing, the processing of your data takes place solely on the basis of Article 6(1)(a) of the GDPR; you may withdraw your consent at any time.
Retention period
Data collected directly by us via the video and conferencing tools will be deleted from our systems as soon as you request us to do so, withdraw your consent to storage, or the purpose for storing the data no longer applies. Stored cookies remain on your device until you delete them. Mandatory statutory retention periods remain unaffected. We have no influence over the retention period of your data stored by the operators of the conferencing tools for their own purposes. For further details, please contact the operators of the conferencing tools directly.
Services and tools used
Meta Pixel
We use the Meta Pixel on this website, which is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. The Meta Pixel enables us to analyse the behaviour of our website visitors when they are redirected to our website by clicking on a Facebook advert. We use the user data to measure the success of our Facebook adverts and to optimise them. As the website operator, we only receive anonymised data for this purpose, meaning we cannot identify you as a user. Meta, on the other hand, processes the data in such a way that it is attributed to a specific user and used for its own advertising purposes. This enables Meta to display personalised adverts on Meta and other websites. We, as the website operator, have no influence over this. Further information on data processing can be found in Meta’s privacy policy at https://www.facebook.com/about/privacy/.
Legal basis
When using Meta Pixel, we rely on your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. You may withdraw your consent at any time. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. The transfer of your personal data to the USA is based on the European Commission’s Standard Contractual Clauses. Further information on this can be found at https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381. If personal data is collected on this website via this service and passed on to Meta, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, share joint responsibility for the processing of your personal data (Article 26 of the GDPR). However, we are only responsible for the collection of your data and its transfer to Meta, whilst Meta is responsible for what happens to the data thereafter. The obligations we impose on each other within the framework of joint controllership are set out in a joint data processing agreement. You can find the exact text of the agreement at the following link: https://www.facebook.com/legal/controller_addendum. Accordingly, when using the Meta tool, we must provide you with information on data protection and ensure that the tool is implemented on our website in compliance with data protection regulations. Meta itself is responsible for the security of its own products. If you wish to exercise your rights as a data subject and, for example, request information about your data processed by Meta, you can contact Meta directly. If you exercise your rights as a data subject with us, we are obliged to forward your request to Meta.
YouTube Video
This website embeds videos from YouTube. The operator is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use YouTube in enhanced privacy mode. According to YouTube, this mode ensures that no information about website visitors is stored before the video is viewed. However, the enhanced privacy mode does not necessarily prevent data from being shared with YouTube partners. YouTube establishes a connection to the Google DoubleClick network, regardless of whether you watch a video. When you play a YouTube video on this website, a connection is established with YouTube’s servers. The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you also allow YouTube to associate your browsing behaviour with your personal profile. You can prevent this by logging out of your account. Once a video has started playing, YouTube may store various cookies on your device or use similar recognition technologies, such as device fingerprinting. This enables YouTube to obtain information about visitors to this website. This information is used, amongst other things, to collect video statistics, improve user experience and prevent fraud. It cannot be ruled out that further data processing operations may take place after a video has started, over which we have no control.
Legal basis
The use of YouTube is based on our legitimate interest in presenting our online services in an appealing manner (Article 6(1)(f) of the GDPR). Where consent has been sought, the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG. This consent may be withdrawn at any time. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information on data protection at YouTube can be found in the privacy policy: https://policies.google.com/privacy?hl=de.
Google Tag Manager
On this website, we use services and features provided by Google Tag Manager, which is offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is a tool that enables us to implement other tools on our website. It does not create user profiles, does not store cookies and does not carry out independent analyses. However, your IP address is recorded and may be transferred to the USA. Google Tag Manager itself is used solely for the management of these tools, which are integrated via it.
Purpose & Legal Basis
When using Google Tag Manager on this website, we rely on Article 6(1)(f) of the GDPR as the legal basis, as we have a legitimate interest in implementing and managing tracking tools on this website quickly and easily. If you have previously given your consent to data processing on this website via Google Tag Manager, the processing of your data takes place solely on the legal basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. You may withdraw your consent at any time. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Gstatic
On this website, we use features provided by Gstatic, a service operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Nature and scope of data processing
Gstatic is a service provided by Google to speed up the loading of web pages. Gstatic stores website resources such as images, CSS and JavaScript files on its servers in order to deliver them to the user more quickly when the page is visited again. During this data processing, technical information, such as your IP address and technical details of your browser, is transmitted to Gstatic. The user profiles created by Gstatic are pseudonymised and cannot be traced directly back to you as an individual. Further information on this can be found in Google’s Privacy Policy: https://policies.google.com/privacy.
Legal basis
The use of Gstatic on this website is based on your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TTDSG. You have the right to withdraw your consent at any time. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Google API
On our website, we use the services and functions of Google APIs, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Nature and scope of data processing
Google APIs allow us to access additional services and data from Google. When using these services, your IP address is transmitted to Google Ireland Limited. Please note that we provide specific information in our privacy policy for each additional Google service that we use. Further information on Google APIs and data protection can be found in Google’s privacy policy: https://policies.google.com/privacy.
Legal basis
We use Google APIs on the basis of our legitimate interests (i.e. the interest in optimising our online offering), in accordance with Article 6(1)(f) of the GDPR. Where we obtain consent (e.g. consent to the storage of cookies), data processing takes place exclusively on the basis of Article 6(1)(a) of the GDPR; you may withdraw this consent at any time.
Data processing on behalf of a third party
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Stripe, Inc.
Nature and scope of processing
We have integrated Stripe Payments components into our website. Stripe Payments is a service provided by Stripe, Inc. and offers online payment solutions worldwide. If you select Stripe Payments as your payment method, the data required for the payment transaction will be automatically transmitted to Stripe, Inc., San Francisco, California, USA. In this context, the following data is generally collected: name, address, company (if applicable), email address, telephone and mobile numbers, and IP address.
Purpose and legal basis
Use of the service is based on the performance of a contract, i.e. for the processing of payment transactions in accordance with Article 6(1)(b) of the GDPR.
Retention period
We have no influence over the specific retention period for the processed data; this is determined by Stripe, Inc. Further information can be found in the privacy policy for Stripe Payments: https://stripe.com/de/privacy.
Google Analytics
On this website, we use services and functions provided by Google Analytics, offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Nature and scope of data processing
As the website operator, Google Analytics enables us to determine how our website is used. As part of this analysis, we learn how often our website is visited, how long visitors stay on the site and which devices or systems they use to access the website. We can also track your mouse movements and clicks. To do this, Google Analytics uses machine learning and other technologies to analyse and supplement your data. The data collected is usually processed on Google’s servers in the USA.
Legal basis
When using Google Analytics, we rely on Article 6(1)(f) of the GDPR as the legal basis for the storage and analysis of personal data, as we have a legitimate interest in analysing the use of our website. This enables us to optimise our online offering for you. If you have previously given your consent to data processing by Google Analytics on this website, the processing of your data takes place solely on the legal basis of Article 6(1)(a) of the GDPR. You may withdraw your consent at any time. The transfer of your personal data to the USA is based on the EU Commission’s Standard Contractual Clauses. Further information on this can be found at https://privacy.google.com/businesses/controllerterms/mccs/.
Data processing on behalf of the controller
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Retention period
Google stores data linked to cookies, user IDs or advertising IDs for two months; after that, it is anonymised or deleted. Further information on the retention period and the deletion of your data can be found at https://support.google.com/analytics/answer/7667196?hl=de.
Ahrefs Analytics
This website uses Ahrefs Analytics, a web analytics service provided by Ahrefs Pte. Ltd. (16 Raffles Quay, #33-03 Hong Leong Building, Singapore 048581).
Ahrefs Analytics helps us understand how visitors use our website, for example which pages are accessed and from which sources visitors arrive. When you visit our website, data such as your IP address, browser information, pages visited and referrer URL may be processed by Ahrefs.
Ahrefs Analytics is integrated in a cookie-free manner. It does not set cookies in your browser and is therefore not included in our cookie banner.
We use Ahrefs Analytics on the basis of our legitimate interest in analysing and optimising our online offering pursuant to Article 6(1)(f) of the GDPR.
Further information on data processing by Ahrefs can be found in Ahrefs’ privacy policy: https://ahrefs.com/legal/privacy-policy.
Google Maps
Nature and scope of data processing
This website uses Google Maps. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. To use the features, it is necessary to store your IP address. As a rule, the information is transmitted to and stored on a Google server. The provider of this website has no influence over this data transmission. If Google Maps is enabled, Google may use web fonts to ensure a consistent display of fonts. When you access Google Maps, your browser loads the required fonts into your browser cache so that the fonts are displayed correctly.
Legal basis
The use of Google Maps is based on our legitimate interest in presenting our online services in an appealing manner and in ensuring that the locations we specify are easy to find (Article 6(1)(f) of the GDPR). Where consent has been sought, the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. This consent may be withdrawn at any time. Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses: https://business.safety.google/gdprcontrollerterms/sccs/ and https://business.safety.google/gdprcontrollerterms/. Google’s privacy policy can be found here: https://policies.google.com/privacy?hl=de. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the US which aims to ensure compliance with European data protection standards when processing data in the US. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Google Fonts
Nature and scope of data processing
This website uses web fonts to ensure consistent display of fonts provided by Google. When you visit the page, your browser loads the required web fonts into your browser cache so that text and fonts are displayed correctly. To do this, the browser you are using establishes a connection to Google’s servers. As a result, Google becomes aware of your IP address.
Legal basis
The use of Google Web Fonts is based on our legitimate interest in ensuring a consistent display of the typography on our website (Article 6(1)(f) of the GDPR). If consent has been requested (e.g. consent to the storage of cookies), the processing of data takes place exclusively on the basis of your consent in accordance with Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG. This consent may be withdrawn at any time. If your browser does not support web fonts, a standard font from your computer will be used. Further information on Google Web Fonts can be found here: https://developers.google.com/fonts/faq. Google’s privacy policy can be found here: https://policies.google.com/privacy?hl=de. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt000000001L5AAI&status=Active
Brevo
This website uses Brevo to send out newsletters. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. Brevo is a service for organising and analysing newsletter distribution. The data you provide to subscribe to the newsletter is stored on Brevo’s servers in Germany. Brevo enables us to analyse our newsletter campaigns. For example, we can see whether a newsletter message has been opened and which links have been clicked. This allows us to identify which links have been clicked on most frequently. Brevo also allows us to group newsletter recipients into different categories (‘clustering’). For example, newsletter recipients can be grouped by age, gender or place of residence. This enables us to tailor the newsletters more effectively to the respective target groups. If you do not wish Brevo to carry out this analysis, you must unsubscribe from the newsletter. We provide a link for this purpose in every newsletter message. Further information on Brevo’s features can be found here: https://www.brevo.com/de/newsletter-software/. Data processing is carried out on the basis of your consent (Article 6(1)(a) of the GDPR). You may withdraw this consent at any time. The lawfulness of any data processing operations that have already taken place remains unaffected by the withdrawal. The data stored by us for the purpose of sending the newsletter will be retained by us or the newsletter service provider until you unsubscribe from the newsletter, and will be deleted from the distribution list once you have unsubscribed. Data stored by us for other reasons remains unaffected by this. After you unsubscribe from the newsletter, your email address may be stored by us or the newsletter service provider on a block list to prevent future mailings. The data from the block list is used solely for this purpose and is not combined with any other data. This serves both your and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Article 6(1)(f) of the GDPR). Storage on the block list is not time-limited. You may object to this storage provided that your interests override our legitimate interest. Further information on data protection at Brevo can be found here: https://www.brevo.com/de/legal/privacypolicy/. To ensure that personal data is processed in accordance with our guidelines and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
JSDelivr CDN
Nature and scope of processing
We use JSDelivr CDN to ensure the proper delivery of our website’s content. JSDelivr CDN is a service provided by Prospect One, which acts as a Content Delivery Network (CDN) on our website. A CDN helps to deliver content from our online offering – in particular files such as graphics or scripts – more quickly with the aid of servers distributed regionally or internationally. When you access this content, you establish a connection to servers operated by Prospect One, Krolewska 65a, Krakow, Malopolskie 30-081, Poland, whereby your IP address and, where applicable, browser data such as your user agent are transmitted. This data is processed exclusively for the purposes stated above and to maintain the security and functionality of JSDelivr CDN.
Purpose and legal basis
The use of the Content Delivery Network is based on our legitimate interests, i.e. our interest in the secure and efficient provision and optimisation of our online services in accordance with Article 6(1)(f) of the GDPR. We intend to transfer personal data to third countries outside the European Economic Area, in particular the USA. Data transfers to the USA are carried out in accordance with Article 45(1) of the GDPR on the basis of the European Commission’s adequacy decision. The US companies involved and/or their US sub-processors are certified under the EU-US Data Privacy Framework (EU-US DPF). In cases where no adequacy decision by the European Commission exists (including US companies that are not certified under the EU-US DPF), we have agreed on other appropriate safeguards with the recipients of the data in accordance with Articles 44 et seq. of the GDPR. Unless otherwise stated, these are the European Commission’s standard contractual clauses in accordance with Implementing Decision (EU) 2021/914 of 4 June 2021. You can view a copy of these standard contractual clauses at https://eur-lex.europa.eu/legal-content/DE/TXT/HTML/?uri=CELEX:32021D0914&from=DE. Furthermore, prior to any such transfer to a third country, we will obtain your consent in accordance with Article 49(1), first sentence, point (a) of the GDPR, which you provide via the Consent Manager (or other forms, registrations, etc.). Please note that transfers to third countries may involve risks of which the details are unknown (e.g. data processing by the third country’s security authorities, the exact scope of which and the consequences for you we do not know, over which we have no influence and of which you may not become aware).
Retention period
We have no influence over the specific retention period of the processed data; this is determined by Prospect One. Further information can be found in the privacy policy for JSDelivr CDN: https://www.jsdelivr.com/privacy-policy-jsdelivr-net.
sentry.io
On this website, we use features provided by sentry.io, a service offered by Functional Software, Inc., 132 Hawthorne St, San Francisco, CA 94107, USA.
Nature and scope of data processing
sentry.io is a tool for error tracking and performance monitoring that helps us identify technical error messages and improve the stability of our website. In particular, information is collected about the browser used, the operating system, the time of the error and technical details regarding the error situation. This information is generally processed anonymously and is used exclusively for the analysis and resolution of malfunctions. Functional Software, Inc. does not use the data collected for advertising or analytical purposes. Further information on this can be found in the sentry.io privacy policy: https://sentry.io/privacy/.
Legal basis for processing
Front-end integration: The integration of sentry.io into the front-end is based solely on your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. You give this consent via our cookie banner. Without your consent, no data is transferred to sentry.io via the front-end. Back-end integration: The use of sentry.io in the back-end is based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR, in order to detect technical errors, maintain the stability of our systems and ensure the secure operation of our website.
Data processing on behalf of a controller
To ensure that data processing complies with data protection regulations, we have entered into a data processing agreement (DPA) with Functional Software, Inc. in accordance with Article 28 of the GDPR.
Cloudflare CDN
We use a so-called ‘Content Delivery Network’ (CDN) provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. A CDN enables us to deliver certain content quickly, particularly large media files. This is achieved via a network of regionally distributed servers connected via the internet. In this way, the provider can analyse the data transmission between your browser and our servers and filter out potentially malicious traffic. The processing of users’ data is carried out solely for the aforementioned purposes and serves to maintain the security and functionality of the CDN. The use of Cloudflare is based on our legitimate interest in providing our website as error-free and secure as possible (Article 6(1)(f) of the GDPR). Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses. Further details can be found here: https://www.cloudflare.com/privacypolicy/. Further information on security and data protection at Cloudflare can be found here: https://www.cloudflare.com/privacypolicy/. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the US which aims to ensure compliance with European data protection standards when processing data in the US. Certification under the DPF obliges companies to adhere to these data protection standards. Further information is available at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnZKAA0&status=Active
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Unpkg CDN
On this website, we use services and features provided by Unpkg CDN, a content delivery network (CDN) operated by Cloudflare, Inc.
Nature and scope of data processing
The CDN is used to deliver content from our online offering, such as graphics or scripts, quickly and efficiently. The content is stored on servers distributed regionally or globally so that it can be made available to users more quickly. Each time this content is accessed, a connection is established to Cloudflare’s servers, during which your IP address and, where applicable, other browser data such as your user agent are collected and processed. This data processing serves solely to optimise and ensure the functionality of the service. Further information on this can be found in the privacy policy for Unpkg CDN at: https://www.cloudflare.com/privacypolicy/.
Legal basis
The use of Unpkg CDN is based on our legitimate interest in the secure and efficient provision of our online services in accordance with Article 6(1)(f) of the GDPR.
Data processing on behalf of a controller
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Europace AG
Mortgage calculator (Europace)
Our website uses a mortgage calculator (“Baufi-Passt”) provided by Europace AG, Heidestraße 8, 10557 Berlin (“Europace”). This calculator enables users to calculate and compare mortgage terms and to carry out a feasibility check. The Europace calculator module is technically integrated as soon as you access this page. In doing so, your IP address, the page you have accessed, the time of access and your browser configuration are transmitted to Europace. If you use the calculator and submit the data you have entered (e.g. postcode, property requirements, financing needs) via the ‘Calculate’ or ‘Compare now with no obligation!’ button, this information is transmitted to Europace. Europace processes the data in order to calculate and display suitable financing options for you. The data is only transmitted once you actively click this button – without this action, your entries will not be passed on to Europace. Further information can be found in Europace’s privacy policy: https://europace.de/datenschutzerklaerung/ The legal basis for the processing of your data in relation to the “Europace” service is Article 6(1)(f) of the GDPR (legitimate interest in data processing). This legitimate interest arises from our need to offer you a user-friendly website with a wide range of functions and an appealing design.
ThinkImmo
On our real-estate search pages we embed a property search widget provided by ThinkImmo. When you access these pages, a connection is established with ThinkImmo’s servers and technical data such as your IP address, browser information and, where applicable, cookies (including Tealium/analytics cookies set by the widget) may be processed.
If you use the search and submit contact or search details, that information is processed in order to provide property results and related services.
The use of ThinkImmo is based on Article 6(1)(f) of the GDPR (legitimate interest in offering a property search). Where cookies or access to information on your device are involved and consent has been obtained, processing is also based on Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
CHECK24 / ProCheck24
On selected pages we embed comparison and application widgets provided by CHECK24 Vergleichsportal / ProCheck24 (CHECK24 Vergleichsportal GmbH, Elsenheimerstraße 43, 80687 Munich, Germany). These widgets allow you to compare energy, internet, banking and insurance products and, where applicable, to start an application.
When you access these pages, your IP address, the page accessed, the time of access, browser information and cookies required by CHECK24 (including session and, where applicable, marketing cookies) may be processed. If you submit data in the widget, CHECK24 processes that data in order to provide the comparison or application service.
Further information is available in CHECK24’s privacy policy: https://www.check24.de/unternehmen/datenschutz/.
The legal basis is Article 6(1)(b) of the GDPR where the processing is necessary to provide a comparison or application you request, otherwise Article 6(1)(f) of the GDPR. Where cookies or similar technologies are involved and consent has been obtained, processing is also based on Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
PriceHubble
On our property valuation page we embed a valuation widget provided by PriceHubble AG. When you access this page, a connection is established with PriceHubble’s servers. Technical data such as your IP address and browser information may be processed, and Google Analytics cookies may be set by the widget provider.
If you enter a property address or other details, this information is processed in order to generate a valuation estimate.
Further information can be found in PriceHubble’s privacy policy: https://www.pricehubble.com/privacy-policy/.
The use of PriceHubble is based on Article 6(1)(f) of the GDPR. Where cookies or device access are involved and consent has been obtained, processing is also based on Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG.
Usercentrics
We use Usercentrics’ consent technology to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies, and to document this in accordance with data protection regulations. The provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich (hereinafter “Usercentrics”). When you visit our website, the following personal data is transmitted to Usercentrics:
- Your consent(s) or the withdrawal of your consent(s)
- Your IP address
- Information about your browser
- Information about your device
- The time of your visit to the website
In order to be able to record and document your consent or withdrawal of consent, the provider sets a cookie in your browser. This data is stored until you delete the cookie, request that we delete the data, or the purpose for which the data is processed no longer applies. Statutory retention obligations remain unaffected. Usercentrics is used to obtain the legally required consents for the use of certain technologies. The legal basis for this is Article 6(1)(c) of the GDPR.
ProvenExpert
We display ProvenExpert seals on our website. This service is provided by Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin, https://www.provenexpert.com. We use the ProvenExpert badge on our website to show that customers have reviewed our company via the ProvenExpert service. When you visit our website, the website communicates with the service provider. ProvenExpert is aware that you have visited us and displays the badge in your language to make it easier for you to use our website. In integrating ProvenExpert into this website, we rely on Article 6(1)(f) of the GDPR as the legal basis, as we have a legitimate interest in presenting customer reviews in a way that is as easy as possible for customers to understand. If you have previously consented to the processing of your data, the processing is carried out on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TTDSG, insofar as the consent covers the storage of information or access to information on your device within the meaning of the TTDSG. Consent may be withdrawn at any time.
Calendly
You can book appointments with us via our website. To do this, we use the ‘Calendly’ tool provided by Calendly LLC, 271 17th St NW, 10th Floor, Atlanta, Georgia 30363, USA. When you use our appointment booking form, we process the data you enter for the purpose of planning, conducting and, where applicable, following up on the appointment. This data is stored on the provider’s servers. The data you enter will remain with us until you request its deletion, withdraw your consent to its storage or the purpose for storing the data no longer applies. Mandatory legal provisions remain unaffected.
Purpose & Legal Basis
Data processing is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in facilitating a straightforward appointment-booking process for prospective customers and existing customers. If you have previously consented to the processing of your data, the processing is carried out on the basis of Article 6(1)(a) of the GDPR and Section 25(1) of the TDDDG, insofar as the consent covers the storage of information or access to information on your device within the meaning of the TDDDG. Consent may be withdrawn at any time. The company is certified under the “EU-US Data Privacy Framework” (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards. Data transfers to the USA are based on the European Commission’s Standard Contractual Clauses. Further details can be found here: https://calendly.com/pages/dpa. Further information on data processing can be found here: https://calendly.com/de/pages/privacy
Data processing on behalf of a controller
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.
Sentry
On this page, we use features provided by Sentry, a service offered by Functional Software, Inc., 132 Hawthorne St, San Francisco, CA 94107, United States.
Nature and scope of data processing
Sentry is an error-tracking tool that helps us to detect code errors at an early stage and ensure the technical functionality of our website. In doing so, anonymised information about the device and the moment the error is detected is collected. In some circumstances, user sessions may be recorded to facilitate troubleshooting. However, Functional Software, Inc. does not analyse this data for advertising purposes. Further information on this can be found in Sentry’s privacy policy: https://sentry.io/privacy/.
Legal basis
The use of Sentry is based on your consent in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. You have the right to withdraw your consent at any time. The company is certified under the ‘EU-US Data Privacy Framework’ (DPF), an agreement between the European Union and the USA which aims to ensure compliance with European data protection standards when processing data in the USA. Certification under the DPF obliges companies to comply with these data protection standards.
Data processing
To ensure that personal data is processed in accordance with our specifications and in compliance with the GDPR, we have entered into a data processing agreement (DPA) with the provider.