We have drawn up this privacy policy (version 04.09.2025-313050509) in order to provide you with information in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (data for short) we as the controller - and the processors commissioned by us (e.g. providers) - process, will process in the future and what lawful options you have. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process about you.
Data protection declarations usually sound very technical and use legal jargon. This privacy policy, on the other hand, is intended to describe the most important things to you as simply and transparently as possible. As far as it is conducive to transparency, technical Terms explained in a reader-friendly waylinks to further information and Graphics for use. We use it to inform you in clear and simple language that we only process personal data as part of our business activities if there is a corresponding legal basis. This is certainly not possible if we provide explanations that are as brief, unclear and legally technical as possible, as is often standard on the Internet when it comes to data protection. I hope you find the following explanations interesting and informative and perhaps there is one or two pieces of information that you did not yet know.
If you still have any questions, please contact the responsible body named below or in the legal notice, follow the links provided and view further information on third-party websites. Our contact details can of course also be found in the legal notice.
Area of application
This privacy policy applies to all personal data processed by us in the company and to all personal data processed by companies commissioned by us (processors). By personal data, we mean information within the meaning of Art. 4 No. 1 GDPR, such as a person's name, email address and postal address. The processing of personal data ensures that we can offer and bill our services and products, whether online or offline. The scope of this privacy policy includes
- all online presences (websites, online stores) that we operate
- Social media presence and e-mail communication
- Mobile apps for smartphones and other devices
In short: The privacy policy applies to all areas in which personal data is processed in the company in a structured manner via the channels mentioned. If we enter into legal relationships with you outside of these channels, we will inform you separately if necessary.
Legal basis
In the following privacy policy, we provide you with transparent information on the legal principles and regulations, i.e. the legal basis of the General Data Protection Regulation, which enable us to process personal data.
As far as EU law is concerned, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can of course access this EU General Data Protection Regulation online on EUR-Lex, the access point to EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679 read more.
We only process your data if at least one of the following conditions applies:
- Consent (Article 6(1)(a) GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
- Contract (Article 6(1)(b) GDPR): In order to fulfill a contract or pre-contractual obligations with you, we process your data. For example, if we conclude a purchase contract with you, we need personal information in advance.
- Legal obligation (Article 6(1)(c) GDPR): If we are subject to a legal obligation, we process your data. For example, we are legally obliged to keep invoices for accounting purposes. These usually contain personal data.
- Legitimate interests (Article 6(1)(f) GDPR): In the case of legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and efficiently. This processing is therefore a legitimate interest.
Other conditions such as recording in the public interest, the exercise of official authority and the protection of vital interests do not generally apply to us. If such a legal basis is relevant, it will be indicated at the appropriate point.
In addition to the EU regulation, national laws also apply:
- In Austria this is the Federal Act on the Protection of Individuals with regard to the Processing of Personal Data (Data Protection Act), in short DSG.
- In Germany this applies Federal Data Protection Act, short BDSG.
If other regional or national laws apply, we will inform you of this in the following sections.
Contact details of the person responsible
If you have any questions about data protection or the processing of personal data, you will find below the contact details of the controller in accordance with Article 4(7) of the EU General Data Protection Regulation (GDPR):
Leukauf-Rossi GmbH
Joseph-Lister-Gasse 31/10/3
1130 Vienna, Austria
Authorized to represent: Sylvia Leukauf-Rossi
E-Mail: office@taschenfabrikantin.at
Phone: +43 6991 587 77 95
Imprint: https://www.taschenfabrikantin.at/impressum/
Storage duration
It is a general criterion for us that we only store personal data for as long as is absolutely necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for the data processing no longer exists. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to exist, for example for accounting purposes.
If you wish your data to be deleted or revoke your consent to data processing, the data will be deleted as quickly as possible and insofar as there is no obligation to store it.
We will inform you below about the specific duration of the respective data processing if we have further information on this.
Rights under the General Data Protection Regulation
In accordance with Articles 13, 14 GDPR, we inform you of the following rights to which you are entitled in order to ensure fair and transparent processing of data:
- According to Article 15 GDPR, you have a right to information as to whether we process your data. If this is the case, you have the right to receive a copy of the data and the following information:
- the purpose for which we carry out the processing;
- the categories, i.e. the types of data that are processed;
- who receives this data and, if the data is transferred to third countries, how security can be guaranteed;
- how long the data will be stored;
- the existence of the right to rectification, erasure or restriction of processing and the right to object to processing;
- that you can lodge a complaint with a supervisory authority (links to these authorities can be found below);
- the origin of the data if we have not collected it from you;
- whether profiling is carried out, i.e. whether data is automatically analyzed in order to create a personal profile of you.
- According to Article 16 GDPR, you have a right to rectification of data, which means that we must correct data if you find errors.
- According to Article 17 GDPR, you have the right to erasure ("right to be forgotten"), which specifically means that you may request the erasure of your data.
- According to Article 18 GDPR, you have the right to restriction of processing, which means that we may only store the data but not use it any further.
- According to Article 20 GDPR, you have the right to data portability, which means that we will provide you with your data in a commonly used format upon request.
- According to Article 21 GDPR, you have the right to object, which will result in a change in the processing after enforcement.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you can object to the processing. We will then check as quickly as possible whether we can legally comply with this objection.
- If data is used for direct marketing purposes, you can object to this type of data processing at any time. We may then no longer use your data for direct marketing.
- If data is used for profiling purposes, you can object to this type of data processing at any time. We may then no longer use your data for profiling.
- Under Article 22 GDPR, you may have the right not to be subject to a decision based solely on automated processing (e.g. profiling).
- According to Article 77 GDPR, you have the right to lodge a complaint. This means that you can lodge a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.
In short: You have rights - do not hesitate to contact the responsible body listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been violated in any other way, you can lodge a complaint with the supervisory authority. For Austria, this is the data protection authority, whose website you can find at https://www.dsb.gv.at/ find. In Germany, there is a data protection officer for each federal state. For more information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) contact. The following local data protection authority is responsible for our company:
Website modular systems Introduction
| Website builder systems Privacy policy summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Optimization of our service performance 📓 Processed data: Data such as technical usage information such as browser activity, clickstream activity, session heatmaps as well as contact details, IP address or your geographical location. You can find more details on this below in this privacy policy and in the providers' privacy policies. 📅 Storage duration: depends on the provider ⚖️ Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interests), Art. 6 para. 1 lit. a GDPR (consent) |
What are website builder systems?
We use a modular website system for our website. Modular systems are special forms of a content management system (CMS). With a modular system, website operators can create a website very easily and without programming knowledge. In many cases, web hosters also offer modular systems. By using a modular system, your personal data can also be collected, stored and processed. In this data protection text, we provide you with general information about data processing by modular systems. You can find more detailed information in the provider's data protection declarations.
Why do we use website builder systems for our website?
The biggest advantage of a modular system is its ease of use. We want to offer you a clear, simple and well-organized website that we can easily operate and maintain ourselves - without external support. A modular system now offers many helpful functions that we can use even without programming knowledge. This allows us to design our web presence according to our wishes and offer you an informative and enjoyable time on our website.
What data is stored by a modular system?
Exactly which data is stored depends, of course, on the website builder system used. Each provider processes and collects different data from the website visitor. As a rule, however, technical usage information such as operating system, browser, screen resolution, language and keyboard settings, hosting provider and the date of your website visit are collected. Tracking data (e.g. browser activity, clickstream activity, session heatmaps, etc.) may also be processed. Personal data may also be collected and stored. This usually involves contact data such as email address, telephone number (if you have provided this), IP address and geographical location data. You can find out exactly which data is stored in the provider's privacy policy.
How long and where is the data stored?
We will inform you about the duration of data processing below in connection with the website building block system used, if we have further information on this. You can find detailed information about this in the provider's privacy policy. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. The provider may store your data according to its own specifications, over which we have no influence.
Right of objection
You always have the right to information, correction and deletion of your personal data. If you have any questions, you can also contact the person responsible for the website builder system used at any time. Contact details can be found either in our privacy policy or on the website of the relevant provider.
You can delete, deactivate or manage cookies that providers use for their functions in your browser. Depending on which browser you use, this works in different ways. Please note, however, that not all functions may then work as usual.
Legal basis
We have a legitimate interest in using a website building block system to optimize our online service and to present it to you in an efficient and user-friendly manner. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use the modular system if you have given your consent.
Insofar as the processing of data is not absolutely necessary for the operation of the website, the data will only be processed on the basis of your consent. This applies in particular to tracking activities. The legal basis in this respect is Art. 6 para. 1 lit. a GDPR.
In this privacy policy, we have provided you with the most important general information about data processing. If you would like more detailed information in this regard, you will find further information - if available - in the following section or in the provider's privacy policy.
WordPress.com privacy policy
| WordPress.com Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Optimization of our service performance 📓 Processed data: Data such as technical usage information such as browser activity, clickstream activity, session heatmaps as well as contact details, IP address or your geographical location. You can find more details below in this privacy policy. 📅 Storage duration: It mainly depends on the type of data stored and the specific settings. ⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests) |
What is WordPress?
We use the well-known content management system WordPress.com for our website. The service provider is the American company Automattic Inc, 60 29th Street #343, San Francisco, CA 94110, USA.
In 2003, the company saw the light of day and developed into one of the best-known content management systems (CMS) in the world in a relatively short space of time. A CMS is software that helps us to design our website and present content in an attractive and organized way. The content can be text, audio and video.
By using WordPress, your personal data may also be collected, stored and processed. As a rule, mainly technical data such as operating system, browser, screen resolution or hosting provider are stored. However, personal data such as IP address, geographical data or contact details may also be processed.
Why do we use WordPress on our website?
We have many strengths, but real programming is not one of our core competencies.
Nevertheless, we want to have a powerful and attractive website that we can also manage and maintain ourselves. With a modular website system or a content management system like WordPress, we can do just that. With WordPress, we don't have to be programming aces to offer you a beautiful website. Thanks to WordPress, we can operate our website quickly and easily even without prior technical knowledge. If technical problems occur or we have special requests for our website, there are always our specialists who feel at home in HTML, PHP, CSS and co.
Thanks to the ease of use and comprehensive functions of WordPress, we can design our website according to our wishes and offer you a good user experience.
What data is processed by WordPress?
Non-personal data includes technical usage information such as browser activity, clickstream activity, session heatmaps and data about your computer, operating system, browser, screen resolution, language and keyboard settings, internet provider and date of the page visit.
Personal data is also collected. These are primarily contact data (e-mail address or telephone number, if you provide these), IP address or your geographical location.
WordPress can also use cookies to collect data. This often includes data about your behavior on our website. For example, it can record which subpages you particularly like to view, how long you spend on individual pages, when you leave a page again (bounce rate) or which default settings (e.g. language selection) you have made. Based on this data, WordPress can also better adapt its own marketing measures to your interests and user behavior. The next time you visit our website, you will therefore be shown our website as you have previously set it.
WordPress may also use technologies such as pixel tags (web beacons), for example to clearly identify you as a user and possibly offer interest-based advertising.
How long and where is the data stored?
How long the data is stored depends on various factors. So it mainly depends on the type of data stored and the specific settings of the website. In principle, WordPress deletes the data when it is no longer needed for its own purposes. There are of course exceptions, especially if legal obligations require the data to be stored for longer. Web server logs containing your IP address and technical data are deleted by WordPress or Automattic after 30 days. Automattic uses the data for this period to analyze the traffic on its own websites (e.g. all WordPress pages) and to resolve potential problems. Deleted content on WordPress websites is also kept in the recycle bin for 30 days to enable recovery, after which it may remain in backups and caches until it is deleted. The data is stored on Automattic's American servers.
How can I delete my data or prevent data storage?
You have the right and opportunity to access your personal data at any time and to object to its use and processing. You can also lodge a complaint with a state supervisory authority at any time.
In your browser, you also have the option of individually managing, deleting or deactivating cookies. Please note, however, that deactivated or deleted cookies may have a negative impact on the functions of our WordPress site. Depending on which browser you use, the management of cookies works slightly differently. In the "Cookies" section, you will find the relevant links to the instructions for the most popular browsers.
Legal basis
If you have consented to the use of WordPress, the legal basis for the corresponding data processing is this consent. According to Art. 6 para. 1 lit. a GDPR (consent), this consent constitutes the legal basis for the processing of personal data, as may occur when WordPress collects data.
We also have a legitimate interest in using WordPress to optimize our online service and present it to you in an attractive manner. The legal basis for this is Art. 6 para. 1 lit. f GDPR (legitimate interests). Nevertheless, we only use WordPress if you have given your consent.
WordPress or Automattic processes your data in the USA, among other places. Automattic is an active participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data from EU citizens to the USA. You can find more information on this at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.
In addition, Automattic uses so-called standard contractual clauses (= Art. 46 (2) and (3) GDPR). Standard Contractual Clauses (SCCs) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through the EU-US Data Privacy Framework and the standard contractual clauses, Automattic undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
You can find more details on the privacy policy and which data is processed by WordPress and in what way at https://automattic.com/privacy/.
Email marketing introduction
| Email marketing summary 👥 Affected parties: Newsletter subscribers 🤝 Purpose: Direct advertising by e-mail, notification of system-relevant events 📓 Processed data: Data entered during registration, but at least the e-mail address. You can find more details on this in the respective email marketing tool used. 📅 Storage period: Duration of the existence of the subscription ⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests) |
What is email marketing?
In order to keep you up to date, we also use the option of e-mail marketing. If you have agreed to receive our e-mails or newsletters, your data will also be processed and stored. Email marketing is a sub-area of online marketing. It involves sending news or general information about a company, products or services by email to a specific group of people who are interested in them.
If you want to take part in our e-mail marketing (usually by newsletter), you normally just need to register with your e-mail address. To do this, you fill out an online form and send it off. However, we may also ask you to provide your title and name so that we can write to you personally.
Basically, the registration for newsletters works with the help of the so-called "double opt-in procedure". After you have registered for our newsletter on our website, you will receive an e-mail confirming your newsletter registration. This ensures that the e-mail address belongs to you and that no one has registered with a third-party e-mail address. We or a notification tool used by us logs each individual registration. This is necessary so that we can prove that the registration process is legally correct. As a rule, the time of registration, the time of registration confirmation and your IP address are saved. In addition, it is also logged when you make changes to your stored data.
Why do we use email marketing?
We naturally want to stay in contact with you and always present you with the most important news about our company. To do this, we use email marketing - often simply referred to as "newsletters" - as an essential part of our online marketing. If you agree to this or if it is permitted by law, we will send you newsletters, system e-mails or other notifications by e-mail. When we use the term "newsletter" in the following text, we mainly mean regularly sent e-mails. Of course, we do not want to bother you in any way with our newsletters. That is why we make every effort to offer only relevant and interesting content. For example, you can find out more about our company, our services or products. As we are constantly improving our offers, you will always find out via our newsletter when there is news or when we are offering special, lucrative promotions. If we commission a service provider who offers a professional mailing tool for our email marketing, we do so in order to be able to offer you fast and secure newsletters. The purpose of our e-mail marketing is basically to inform you about new offers and also to achieve our business goals.
What data is processed?
If you become a subscriber to our newsletter via our website, you confirm your membership of an e-mail list by e-mail. In addition to your IP address and e-mail address, your title, name, address and telephone number may also be stored. However, only if you consent to this data storage. The data marked as such is necessary so that you can participate in the service offered. Providing this information is voluntary, but if you do not provide it, you will not be able to use the service. In addition, information about your device or your preferred content on our website may also be stored. You can find out more about the storage of data when you visit a website in the "Automatic data storage" section. We record your declaration of consent so that we can always prove that it complies with our laws.
Duration of data processing
If you unsubscribe your e-mail address from our e-mail/newsletter distribution list, we may store your address for up to three years on the basis of our legitimate interests so that we can still prove your consent at that time. We may only process this data if we have to defend ourselves against any claims.
However, if you confirm that you have given us your consent to the newsletter registration, you can submit an individual deletion request at any time. If you permanently revoke your consent, we reserve the right to store your e-mail address in a blacklist. As long as you have voluntarily subscribed to our newsletter, we will of course retain your e-mail address.
Right of objection
You can cancel your newsletter subscription at any time. All you have to do is withdraw your consent to the newsletter subscription. This usually only takes a few seconds or one or two clicks. You will usually find a link to cancel your newsletter subscription at the end of every email. If you really cannot find the link in the newsletter, please contact us by e-mail and we will cancel your newsletter subscription immediately.
Legal basis
Our newsletter is sent on the basis of your consent (Article 6(1)(a) GDPR). This means that we may only send you a newsletter if you have actively subscribed to it beforehand. We may also send you advertising messages if you have become our customer and have not objected to the use of your email address for direct advertising.
Information on specific email marketing services and how they process personal data, if available, can be found in the following sections.
Data protection notice for Brevo (newsletter mailing)
What is Brevo?
We use the following service to send our newsletter Brevoa service provided by Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin. Brevo is an email marketing platform through which we can send personalized newsletters and use various functions such as design, dispatch and evaluation.
Why do we use Brevo?
Brevo not only provides us with the dispatch infrastructure, but also enables evaluations that help us to improve the newsletter. This allows us to track whether a newsletter has been opened and which links have been clicked on. This information is used exclusively to better adapt content to the interests of our readers.
What data is processed?
When you register for the newsletter, we store the data you provide (at least your e-mail address, optionally your first name and surname). In addition, technical information such as date, time and IP address are recorded at the time of registration. This data is used for legally compliant documentation of your registration. Interaction data, such as click behavior in the newsletter, may also be processed.
Storage location and storage duration
The data is stored on servers in Germany. As soon as you cancel your subscription, your personal data will be deleted both by us and by Brevo. In principle, Brevo deletes personal data no later than two years after termination of the contractual relationship. If you wish, you can request early deletion at any time.
Revocation of consent
You can cancel your subscription at any time. All you need to do is click on the unsubscribe link at the end of each newsletter. If this link is not visible, you can also contact us directly by e-mail. After unsubscribing, all stored personal data will be deleted. You also have the right to information about the stored data and the right to rectification, blocking or erasure at any time.
Legal basis
The processing takes place on the basis of your Consent pursuant to Art. 6 para. 1 lit. a GDPR. In certain cases, data processing may also be limited to legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR for example, if direct marketing is legally permissible. The entire registration process is documented in order to be able to prove legality at any time.
Further information on data processing by Brevo can be found in the official privacy policy:
https://www.brevo.com/de/legal/privacypolicy/
Cookie Consent Management Platform Introduction
| Cookie Consent Management Platform Summary 👥 Affected parties: Website visitors 🤝 Purpose: Obtaining and managing consent for certain cookies and thus the use of certain tools 📓 Processed data: Data for managing the cookie settings set, such as IP address, time of consent, type of consent, individual consents. You can find more details on this in the respective tool used. 📅 Storage duration: Depends on the tool used, you have to be prepared for periods of several years ⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit.f GDPR (legitimate interests) |
What is a Cookie Consent Management Platform?
We use Consent Management Platform (CMP) software on our website, which makes it easier for us and you to handle scripts and cookies correctly and securely. The software automatically creates a cookie pop-up, scans and checks all scripts and cookies, provides you with the cookie consent required under data protection law and helps us and you to keep track of all cookies. Most cookie consent management tools identify and categorize all existing cookies. As a website visitor, you then decide for yourself whether and which scripts and cookies you allow or do not allow. The following graphic shows the relationship between browser, web server and CMP.
Why do we use a cookie management tool?
Our aim is to offer you the best possible transparency in the area of data protection. We are also legally obliged to do so. We want to provide you with as much information as possible about all tools and all cookies that can store and process your data. It is also your right to decide for yourself which cookies you accept and which you do not. In order to grant you this right, we first need to know exactly which cookies have landed on our website in the first place. Thanks to a cookie management tool that regularly scans the website for all existing cookies, we know about all cookies and can provide you with GDPR-compliant information about them. You can then accept or reject cookies via the consent system.
What data is processed?
As part of our cookie management tool, you can manage each individual cookie yourself and have complete control over the storage and processing of your data. The declaration of your consent is stored so that we do not have to ask you every time you visit our website and we can also prove your consent if required by law. This is stored either in an opt-in cookie or on a server. The storage period of your cookie consent varies depending on the provider of the cookie management tool. In most cases, this data (e.g. pseudonymous user ID, time of consent, details of cookie categories or tools, browser, device information) is stored for up to two years.
Duration of data processing
We will inform you about the duration of data processing below, if we have further information on this. In general, we only process personal data for as long as is absolutely necessary for the provision of our services and products. Data that is stored in cookies is stored for different lengths of time. Some cookies are deleted as soon as you leave the website, while others may be stored in your browser for several years. The exact duration of data processing depends on the tool used; in most cases you should be prepared for a storage period of several years. You can usually find precise information about the duration of data processing in the respective data protection declarations of the individual providers.
Right of objection
You also have the right and the option to withdraw your consent to the use of cookies at any time. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser.
Information on special cookie management tools, if available, can be found in the following sections.
Legal basis
If you consent to cookies, your personal data will be processed and stored via these cookies. If we use your Consent (Article 6(1)(a) GDPR), this consent is also the legal basis for the use of cookies and the processing of your data. Cookie consent management platform software is used to manage consent to cookies and to enable you to give your consent. The use of this software enables us to operate the website in an efficient and legally compliant manner, which is a legitimate interest (Article 6(1)(f) GDPR).
BorlabsCookie privacy policy
We use BorlabsCookie on our website, which is, among other things, a tool for storing your cookie consent. The service provider is the German company Borlabs - Benjamin A. Bornschein, Rübenkamp 32, 22305 Hamburg, Germany.
You can find out more about the data processed through the use of BorlabsCookie in the Privacy Policy on https://de.borlabs.io/datenschutz/.
Security & Anti-Spam
| Security & Anti-Spam Privacy Policy Summary 👥 Data subjects: Visitors to the website 🤝 Purpose: Cybersecurity 📓 Processed data: Data such as your IP address, name or technical data such as browser version You can find more details on this below and in the individual data protection texts. 📅 Storage period: Most of the data is stored until it is no longer required for the provision of the service ⚖️ Legal basis: Art. 6 para. 1 lit. a GDPR (consent), Art. 6 para. 1 lit. f GDPR (legitimate interests) |
What is security & anti-spam software?
With so-called security and anti-spam software, you and we can protect ourselves from various spam or phishing emails and possible other cyberattacks. Spam refers to advertising emails from a mass mailing that you did not request yourself. Such emails are also known as data junk and can also cause costs. Phishing emails, on the other hand, are messages that aim to build trust via fake messages or websites in order to obtain personal data. Anti-spam software generally protects against unwanted spam messages or malicious emails that could introduce viruses into our system. We also use general firewall and security systems to protect our computers from unwanted network attacks.
Why do we use security & anti-spam software?
We attach great importance to security on our website. After all, it's not just about our security, but above all about yours. Unfortunately, cyber threats have become part of everyday life in the world of IT and the Internet. Hackers often try to steal personal data from an IT system with the help of a cyber attack. And that is why a good defense system is absolutely essential. A security system monitors all incoming and outgoing connections to our network or computer. To achieve even greater security against cyber attacks, we also use other external security services in addition to the standardized security systems on our computer. This prevents unauthorized data traffic and protects us from cybercrime.
What data is processed by security & anti-spam software?
Exactly which data is collected and stored depends of course on the respective service. However, we always strive to use only programs that collect data very sparingly or only store data that is necessary for the performance of the service offered. In principle, the service may store data such as name, address, IP address, e-mail address and technical data such as browser type or browser version. Any performance and log data may also be collected in order to detect possible incoming threats in good time. This data is processed as part of the services and in compliance with the applicable laws. This also includes the GDPR for US providers (via the standard contractual clauses). In some cases, these security services also work with third-party providers who may store and/or process data under instructions and in accordance with the data protection guidelines and other security measures. Data is usually stored via cookies.
Duration of data processing
We will inform you about the duration of data processing below if we have further information on this. For example, security programs store data until you or we revoke the data storage. In general, personal data is only stored for as long as is absolutely necessary for the provision of the services. Unfortunately, in many cases we do not receive precise information from the providers about the length of storage.
Right of objection
You also have the right and the option to withdraw your consent to the use of cookies or third-party security software at any time. This works either via our cookie management tool or via other opt-out functions. For example, you can also prevent data collection by cookies by managing, deactivating or deleting cookies in your browser.
As such security services may also use cookies, we recommend that you read our general privacy policy on cookies. To find out exactly which of your data is stored and processed, you should read the privacy policies of the respective tools.
Legal basis
We use the security services mainly on the basis of our legitimate interests (Art. 6 para. 1 lit. f GDPR) in a good security system against various cyber attacks.
Certain processing operations, in particular the use of cookies and the use of security functions, require your consent. If you have consented to your data being processed and stored by integrated security services, this consent is the legal basis for data processing (Art. 6 para. 1 lit. a GDPR). Most of the services we use set cookies in your browser to store data. We therefore recommend that you read our data protection text on cookies carefully and view the privacy policy or cookie guidelines of the respective service provider.
Information on special tools - if available - can be found in the following sections.
Wordfence privacy policy
We use Wordfence, a WordPress security plug-in, for our website. The service provider is the American company Defiant, Inc, 1700 Westlake Ave N Ste 200, Seattle, WA 98109, USA.
Wordfence also processes your data in the USA, among other places. We would like to point out that, in the opinion of the European Court of Justice, there is currently no adequate level of protection for data transfers to the USA. This may entail various risks for the legality and security of data processing.
Wordfence uses so-called standard contractual clauses (= Art. 46. para. 2 and 3 GDPR) as the basis for data processing with recipients based in third countries (outside the European Union, Iceland, Liechtenstein, Norway, i.e. in particular in the USA) or data transfer there. Standard Contractual Clauses (SCCs) are templates provided by the EU Commission and are intended to ensure that your data complies with European data protection standards even if it is transferred to third countries (such as the USA) and stored there. Through these clauses, Wordfence undertakes to comply with the European level of data protection when processing your relevant data, even if the data is stored, processed and managed in the USA. These clauses are based on an implementing decision of the EU Commission. You can find the decision and the corresponding standard contractual clauses here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The data processing conditions (Data Protection Regulation), which correspond to the standard contractual clauses, can be found at https://www.wordfence.com/help/general-data-protection-regulation/.
You can find out more about the data that is processed through the use of Wordfence in the privacy policy on https://www.wordfence.com/privacy-policy/.
All texts are protected by copyright.
Source: Privacy policy created with the data protection generator for Germany by AdSimple. Please also take a look at our Sample data protection declaration to.
























































































































































