Privacy hints

Table of content

We process personal data only to the extent necessary for the respective purpose and where a legal basis exists.

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, names, contact details, IP addresses, communication content or other information transmitted when using our website or contacting us.

The specific purposes of the processing, the data processed in each case, the legal bases, potential recipients and retention periods are described in the following sections.

§ 1 Name and address of the controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Mataono GmbH
Kraftwerk Mitte 7
01067 Dresden
Phone: 0351 – 41 88 840-0
E-Mail: info@mataono.com

§ 2 Legal basis of the processing

We process personal data only where a legal basis exists. The legal basis applicable in each individual case is explained for the respective processing operation in the following sections.

Depending on the processing operation, the following legal bases may apply in particular:

  • Art. 6 (1) (a) GDPR where the data subject has consented to the processing;
  • Art. 6 (1) (b) GDPR where processing is necessary for the performance of a contract or in order to take steps at the request of the data subject prior to entering into a contract;
  • Art. 6 (1) (c) GDPR where processing is necessary for compliance with a legal obligation;
  • Art. 6 (1) (d) GDPR where processing is necessary to protect vital interests;
  • Art. 6 (1) (e) GDPR where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority;
  • Art. 6 (1) (f) GDPR where processing is necessary for the purposes of legitimate interests and these interests are not overridden by the interests, fundamental rights or freedoms of the data subject.

Where special categories of personal data are processed, this takes place only if an additional condition under Art. 9 (2) GDPR is met.

Where processing is based on consent, that consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

§ 3 Duration of storage of personal data

We store personal data only for as long as necessary for the respective processing purpose. We may also store data where statutory retention obligations apply or where further storage is necessary for the establishment, exercise or defence of legal claims.

The specific retention period or the criteria used to determine it are specified for the respective processing operation in the following sections. Where no specific retention period can be stated, we take into account in particular:

  • the time required to process an enquiry,
  • the duration of an existing contractual or organisational relationship,
  • statutory retention periods,
  • the necessity for the establishment, exercise or defence of legal claims,
  • the necessity for secure technical operation and the handling of security incidents,
  • the withdrawal of consent where there is no other legal basis for continued storage.

Once the processing purpose no longer applies and there is no legal basis for continued storage, the personal data is deleted or anonymised. Where statutory retention obligations apply, processing is restricted to compliance with those obligations for the duration of the retention period.

§ 4 Rights of data subjects

Subject to the applicable legal requirements, you have the following rights:

  • the right of access to your personal data and to obtain a copy under Art. 15 GDPR,
  • the right to rectification of inaccurate and completion of incomplete personal data under Art. 16 GDPR,
  • the right to erasure of your personal data under Art. 17 GDPR,
  • the right to restriction of processing under Art. 18 GDPR,
  • the right to data portability under Art. 20 GDPR,
  • the right to object to processing under Art. 21 GDPR,
  • the right to withdraw consent under Art. 7 (3) GDPR at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal,
  • the right, under the conditions of Art. 22 GDPR, not to be subject to a decision based solely on automated processing, including profiling,
  • the right to lodge a complaint with a supervisory authority under Art. 77 GDPR.

To exercise your rights, you may contact us or our data protection officer at any time. Where we have reasonable doubts concerning your identity, we may request additional information necessary to confirm your identity.

You may lodge a complaint in particular with a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement.
The supervisory authority responsible for us is:
Sächsische Datenschutz- und Transparenzbeauftragte
Besucheradresse: Maternistraße 17, 01067 Dresden
Postadresse: Postfach 11 01 32, 01330 Dresden
Telefon: 0351 85471-101
E-Mail: post@sdtb.sachsen.de
https://www.datenschutz.sachsen.de/

§ 5 Legitimate interests in the processing pursued by the controller or by a third party

Where we base processing on Art. 6 (1) f GDPR, we specify for the respective processing activity the legitimate interests pursued by us or by a third party.

Before processing, we assess whether it is necessary for the purposes of those interests and balance our interests or those of a third party against your interests, fundamental rights and freedoms. Particular consideration is given to the rights and interests of children.

§ 6 Right to object

Where we process personal data on the basis of Art. 6 (1) e or f GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation. This also applies to profiling based on these provisions.

We will then no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

Where personal data are processed for direct marketing purposes, you may object to this processing at any time. This also applies to profiling to the extent that it is related to such direct marketing. Following your objection, your personal data will no longer be processed for these purposes.

Where processing is based on your consent, there is no right to object in the above sense. Instead, you may withdraw your consent at any time with effect for the future.

§ 7 Requirement to provide personal data

For individual processing activities, the provision of certain personal data may be required by law or contract or may be necessary to enter into or perform a contract, process an enquiry or registration, perform a statutory, public or ecclesiastical task, or provide a function requested by you.

The information required for the respective processing activity is indicated in the relevant input form or in the description of the processing activity in this privacy statement. Where possible, required information is identified as mandatory.

If required data are not provided, we may be unable to process an enquiry or registration, enter into or perform a contract, provide a service or perform a statutory task. The specific consequences are explained in connection with the respective processing activity. Information that is not required may be provided voluntarily. You will not suffer any disadvantage if you do not provide voluntary information.

If you have questions about whether particular information is required, you may contact the controller or, where appointed, the data protection officer using the contact details provided at the beginning of this privacy statement.

§ 8 Provision of the website and hosting

We use hosting services provided by Hetzner Online GmbH to make this website available and operate it securely. When you access our website, the hosting provider processes technically necessary personal data on our behalf. This may include in particular your IP address, the date and time of access, the page or file requested, the amount of data transferred, the previously visited page, information about the browser and operating system used, and technical connection and security data.

The processing is carried out to deliver the website, ensure its functionality and stability, detect technical errors, and prevent attacks or misuse. The legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in the secure, stable and functional operation of our website.

The hosting provider processes personal data as a processor. The processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Server log data generated when the website is accessed are stored for 30 days and then deleted or anonymised, unless longer storage is necessary to investigate a specific security incident. Further details on the processing of server log files can be found in the section "Server log files".

Hetzner Online GmbH
Industriestrasse 25
91710 Gunzenhausen
Germany

Further information on data protection at the hosting provider can be found at: https://www.hetzner.com/legal/privacy-policy/.

§ 9 Transfers to third countries

Where we transfer personal data to recipients outside the European Union or the European Economic Area, we do so only in accordance with the statutory requirements of Arts. 44 to 49 GDPR.

A transfer may be based in particular on an adequacy decision of the European Commission pursuant to Art. 45 GDPR or on appropriate safeguards pursuant to Art. 46 GDPR. Appropriate safeguards include in particular Standard Contractual Clauses adopted by the European Commission or Binding Corporate Rules. Where necessary, supplementary safeguards are agreed. In exceptional cases provided for by law, a transfer may be based on Art. 49 GDPR.

For transfers to the United States, the adequacy decision concerning the EU-U.S. Data Privacy Framework may be used where the respective US recipient is certified for the relevant data categories. The former EU-US Privacy Shield is not used as a basis for data transfers.

Whether a transfer to a third country takes place and the basis on which it is made are explained in more detail for the respective processing activity.

§ 10 Cookies and comparable technologies

Our website uses cookies and comparable technologies. Cookies are small text files stored on your device. Comparable technologies include Local Storage, Session Storage and other methods of storing information on or accessing information from your device. Session entries are generally deleted at the end of the session; persistent entries remain until their respective retention period expires or until they are deleted.

Consent is not required under Sec. 25 (2) no. 2 TDDDG where storing or accessing information is strictly necessary to provide a digital service expressly requested by you. In these cases, the subsequent processing of personal data is based on Art. 6 (1) f GDPR. Our legitimate interest lies in the secure and functional operation of the website and the provision of the functions requested by you.

Cookies and comparable technologies that are not strictly necessary are used only after you have given your prior consent. The legal basis for storing or accessing information on your device is Sec. 25 (1) TDDDG. The subsequent processing of personal data is based on Art. 6 (1) a GDPR. This applies in particular to technologies used for analytics, audience measurement, marketing or the integration of non-essential external content.

You may withdraw or change your consent pursuant to Art. 7 (3) GDPR at any time with effect for the future using the privacy or cookie settings provided on our website. The lawfulness of processing carried out before the withdrawal remains unaffected.

You can also delete cookies and comparable stored information or restrict their storage through your browser settings. This may impair individual functions of the website. Preventing or deleting cookies in the browser does not replace the withdrawal of consent already given.

Further information on the technologies actually used, their providers, purposes and retention periods can be found in the information on the respective services and, where a consent management facility is provided, in its privacy settings.

§ 11 Server log files

When our website is accessed, server log files are processed automatically. The data collected may include in particular the IP address, date and time of access, the URL requested, the HTTP status code, the amount of data transferred, the previously visited page, browser type and version, the operating system used, and technical connection data. As long as the IP address permits a person to be identified, the data are not collected anonymously.

The processing is carried out to make the website technically available, ensure its stability and security, detect errors, and prevent misuse or attacks. The legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in the secure, stable and functional operation of our website.

The server log files are stored for 30 days and then deleted or anonymised so that they can no longer be linked to an individual. Personal data are retained for longer only where this is necessary to investigate or document a specific security incident. In that case, the data concerned are deleted or anonymised as soon as they are no longer required for this purpose.

As a rule, server log files are not combined with other data sources. They may be analysed or combined in an individual case where there are specific indications of a security incident or misuse.

§ 12 Contact by email

If you contact us by email, we process the personal data you provide in order to handle your request and communicate with you. This may include in particular your name, email address, any telephone number provided, the content of your message, attached documents, and the date and time of the communication.

If your request relates to a contract, registration or pre-contractual measures, the processing is based on Art. 6 (1) b GDPR. For other requests, the legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in properly handling and responding to incoming requests. Where processing is necessary to comply with a legal obligation, it is based on Art. 6 (1) c GDPR. Where it takes place in the context of a public or ecclesiastical task entrusted to us, Art. 6 (1) e GDPR may apply.

Recipients of the data are the internal departments responsible for handling your request. IT and email service providers used by us may also have access to the data. Where these service providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

We delete data processed in connection with your request as soon as the request has been finally dealt with and there are no statutory retention obligations or other legal grounds for further storage. Where data are required to comply with retention obligations or to establish, exercise or defend legal claims, they are retained for those purposes and subsequently deleted.

§ 13 Contact form

If you use a contact form provided on our website, we process the data you enter in order to handle your request and communicate with you. The data processed are shown in the respective input form. They may include in particular your name, email address, telephone number and the content of your message. The date and time of transmission and technical data required for secure transmission may also be processed.

Information marked as mandatory in the respective form is required to process your request. Without this information, we may not be able to process the request. Information not marked as mandatory is voluntary.

If your request relates to a contract, registration or pre-contractual measures, the processing is based on Art. 6 (1) b GDPR. For other requests, the legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in properly handling and responding to incoming requests. Where processing is necessary to comply with a legal obligation, it is based on Art. 6 (1) c GDPR. Where it takes place in the context of a public or ecclesiastical task entrusted to us, Art. 6 (1) e GDPR may apply.

Data submitted through the contact form are forwarded to the internal departments responsible for handling the request. Hosting, IT and email service providers used by us may also have access to the data. Where these service providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

We delete data processed in connection with your request as soon as the request has been finally dealt with and there are no statutory retention obligations or other legal grounds for further storage. Where data are required to comply with retention obligations or to establish, exercise or defend legal claims, they are retained for those purposes and subsequently deleted.

§ 14 Privacy policy on the use and application of Matomo

The responsible person has integrated the component Matomo in this application. Matomo is an open source software tool for usage analysis. Usage analysis is the collection and analysis of data about user behavior on applications. In the web the tool records from which website the user has accessed this website, which subpages have been accessed and how often and how long subpages have been viewed by the user. In a mobile app the tool records time spent in the application and user interactions. This analysis is used to optimize the application.

The software is operated on the server of the responsible person. All log files are stored exclusively on this server.

The legal basis for processing data is the legitimate interest of the controller to optimise and evaluate the use of the application (Art. 6 par. 1 (f) GDPR). A weighing of interests of the controller and of the data subject has been carried out.

Matomo places a cookie on the IT system of the user concerned. The cookie enables the analysis of usage. Each time one of the individual pages is called up, the Internet browser on the IT system of the person concerned is automatically prompted to transmit data to our server for the purpose of online analysis. In this process, we obtain knowledge of the IP address of the person concerned, which serves, among other things, to trace the origin of the visitors. In addition to the IP address, the access time, location from which the access originated and the frequency of visits to our website are stored. The IP address is made anonymous immediately upon collection.

By adjusting the settings of the Internet browser used, the setting of cookies by Matomo can be permanently rejected. In addition, set cookies can be deleted at any time via the Internet browser or other software. Furthermore, it is possible to object to the recording of the use by Matomo. The person concerned must set an opt-out cookie for this purpose. If the cookie settings of the Internet browser used are reset, this cookie would have to be set again.

The setting of the opt-out cookie may lead to restrictions in the functionality of the website.

Further information and Matomo's current data protection regulations can be found at https://matomo.org/privacy/ abgerufen werden.

§ 15 Privacy Policy on the Use and Usage of YouTube

The responsible person has integrated components of YouTube on this website. YouTube is an Internet video portal that enables video producers to post video clips and other users to view, evaluate and comment on them free of charge. The integration of videos enables the presentation of advertising material, knowledge and other interesting videos.

The operating company of YouTube is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

When embedding YouTube videos on our website, we use the Nocookie link provided by YouTube. This means that the user is not yet analyzed when a website is called that has integrated the YouTube component (YouTube video). YouTube and Google do not know which specific subpage of the website is visited by the user until the video is played.

If the person concerned is logged in to YouTube at the same time, YouTube recognizes which specific subpage of our website the person concerned is visiting by calling up a subpage containing a YouTube video. This information is collected by YouTube and Google and assigned to the respective YouTube account of the person concerned.

YouTube and Google receive information via the YouTube component that the person concerned has visited our website if the person concerned is logged on to YouTube at the same time as the video is being played. If YouTube and Google do not want the data subject to submit this information to YouTube and Google in this way, the data subject may prevent the submission by logging out of his/her YouTube account before accessing our website.

The data protection regulations published by YouTube, which are available at https://policies.google.com/privacy/update?hl=en , provide information about the collection, processing and use of personal data by YouTube and Google.

§ 16 Error analysis and technical error logging

We use Sentry-compatible error logging to detect, analyse and resolve technical errors. The processing serves to ensure the technical functionality of our website, resolve errors and improve the stability of our systems.

The data processed may include in particular the IP address, date and time of the error, the URL accessed, browser and device information, the operating system, the error message, technical session data and information about the function affected. The data generated in an individual case depend on the type of error and the function affected.

The legal basis is Art. 6 (1) f GDPR. Our legitimate interest lies in the secure, stable and as error-free as possible operation of our website and the functions provided through it.

The error data are processed within the technical infrastructure used by us. Access is granted to the internal departments responsible for error analysis and, where necessary, to hosting and IT service providers used by us. Where these service providers process personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.

The error data are stored for 90 days and then deleted. They are stored for longer only where this is necessary to investigate or resolve a specific technical or security-related incident. After the matter has been resolved, the data are deleted unless statutory retention obligations or other legal grounds require further storage.

The error data are not used for advertising purposes or to create user profiles.

§ 17 Integration of Google reCAPTCHA

We use Google reCAPTCHA v2 to protect our forms against spam, automated attacks and misuse. The service analyses whether an entry is made by a natural person or by automated means.

The contractual provider and processor is Google Cloud EMEA Limited, based in Dublin, Ireland. The data processed may include in particular the IP address, browser and device information, operating system, date and time of access, the page accessed, and mouse, keyboard and other interaction data. reCAPTCHA also uses cookies or comparable technologies, in particular _GRECAPTCHA, for risk analysis and abuse prevention.

Where reCAPTCHA stores information on your device or accesses information stored there, this is based on Sec. 25 (2) no. 2 TDDDG. The access is necessary to provide securely the form function expressly requested by you and to protect it against automated misuse.

The legal basis for processing personal data is Art. 6 (1) f GDPR. Our legitimate interest lies in preventing spam and misuse and ensuring the IT security of our forms. You may object to this processing on grounds relating to your particular situation pursuant to Art. 21 GDPR.

Since 2 April 2026, Google processes reCAPTCHA Customer Data as a processor in accordance with the Google Cloud Terms of Service and the Google Cloud Data Processing Addendum. The processing on behalf is governed by Art. 28 GDPR.

Processing may take place in third countries, in particular the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework for covered data categories. Where a transfer is not covered by the associated adequacy decision, Google uses in particular Standard Contractual Clauses adopted by the European Commission in accordance with the Google Cloud contractual terms.

We process the verification result provided by reCAPTCHA only for as long as necessary to verify and secure the respective form submission. Further processing and deletion of Customer Data processed by Google are governed by the Google Cloud contractual terms and the Data Processing Addendum.

Further information is available in the Google reCAPTCHA information and the Google Cloud Data Processing Addendum.

§ 18 Unterhaltung einer LinkedIn-Seite

Zum Zweck der Unternehmenspräsentation und Bewerberansprache unterhält der Verantwortliche eine Seite auf LinkedIn.

Die Verarbeitung der personenbezogenen Daten der Nutzer erfolgt auf Grundlage der berechtigten Interessen des Verantwortlichen an einer effektiven Information der Nutzer und Kommunikation mit den Nutzern gem. Art. 6 Abs. 1 (f) DSGVO. Falls die Nutzer von LinkedIn um eine Einwilligung in die vorbeschriebene Datenverarbeitung gebeten werden, ist die Rechtsgrundlage der Verarbeitung Art. 6 Abs. 1 (a), Art. 7 DSGVO.

Beitreiber von LinkedIn ist die LinkedIn Corporation, 2029 Stierlin Court Mountain View, CA, 94043, USA, vertreten im europäischen Raum durch LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. Es wird darauf hingewiesen, dass dabei Daten der Nutzer außerhalb des Raumes der Europäischen Union verarbeitet werden können. Hierdurch können sich für die Nutzer Risiken ergeben, weil so z.B. die Durchsetzung der Rechte der Nutzer erschwert werden könnte.

Für den Fall von Auskunftsanfragen und der Geltendmachung von Nutzerrechten, wird darauf hingewiesen, dass diese am effektivsten bei LinkedIn geltend gemacht werden können. Nur der Anbieter hat Zugriff auf die Daten der Nutzer und kann direkt entsprechende Maßnahmen ergreifen und Auskünfte geben. Sollten Sie dennoch Hilfe benötigen, dann können Sie sich an den Verantwortlichen wenden.

Für eine detaillierte Darstellung der Verarbeitung und der Widerspruchsmöglichkeiten (Opt-Out), wird nachfolgend auf die verlinkten Angaben des Anbieters hingewiesen.

Die Datenschutzrichtlinien von LinkedIn können auf https://www.linkedin.com/legal/privacy-policy eingesehen werden.

Der Widerspruch gegen die Verarbeitungen, die auf Einwilligung beruhen, kann unter https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. abgegeben werden.

§ 19 Usage of HubSpot

On this website we use HubSpot for different purposes. HubSpot is a software company from the USA with a branch office in Ireland. Contact: HubSpot, 2nd Floor 30 North Wall Quay, Dublin 1, Ireland, Telephone: +353 1 5187500.

HubSpot is an integrated software solution that we use to cover different aspects of our online marketing. This includes, among others:

  • Email marketing
  • reporting
  • contact management (e.g., user segmentation & CRM) and
  • contact forms.

Our registration service enables visitors to our website to find out more about our company, to download contents and to provide their contact information, together with further demographic information. This information, together with the contents of our website are stored on the servers of our software partner HubSpot. We can use it to make contact with visitors to our website and to determine which of our company’s services are interesting for them. All information collected by us is subject to this data privacy policy. We use all information collected exclusively for optimizing our marketing measures.

As part of the optimization of our marketing activities, HubSpot may collect and process the following data:

  • Geographical position
  • Browser type
  • Navigation information
  • Reference URL
  • Performance data
  • Information about how often the application is used
  • Mobile apps data
  • HubSpot subscription service credentials
  • Files that are displayed on site
  • Domain names
  • Viewed pages
  • Aggregated use
  • Version of the operating system
  • Internet service provider
  • IP address
  • Device identification
  • Duration of the visit
  • Where the application was downloaded from
  • Operating system
  • Events that occur within the application
  • Access times
  • Clickstream data
  • Device model and version

We also use HubSpot’s contact forms. More information about this can be found at section "Integration of HubSpot contact forms" of this Privacy Policy.

The legal basis of the processing is your consent according to Art. 6 (1)(a) GDPR. If you do not want Hubspot to collect and process the aforementioned data, you can refuse your consent or withdraw it at any time with effect for the future.

The data will be stored for as long as it is necessary for the purpose of the procession. The data will be deleted as soon as it is no longer needed for the processing purposes.

Data may be transferred to the USA as part of processing by Hubspot. The security of the transmission is ensured by so-called standard contractual clauses, which guarantee that the processing of personal data is subject to a security level that corresponds to that of the GDPR. If the standard contractual clauses are not sufficient to establish an adequate level of security, Art. 49 (1)(a) GDPR can serve as a legal basis. Please note the reference to the risk of data transfer to an unsafe third-country under section "Integration of HubSpot contact forms".

§ 20 Integration of HubSpot contact forms

We use the service HubSpot to provide the following contact forms. For this purpose, we forward your data to HubSpot, which processes the data exclusively on our behalf. See data protection information on "Usage of HubSpot".

Please note: If you contact us via contact forms, personal data may be transferred to service providers in third countries. These third countries do not have an adequate level of data protection. If the data is transferred to the U.S., there is a risk that your data may be processed by U.S. authorities for control and monitoring purposes without you possibly having any legal remedies. The security of the transfer is regularly safeguarded via so-called standard contractual clauses, which ensure that the processing of personal data is subject to a level of security that corresponds to that of the GDPR. If the standard contractual clauses are not sufficient to establish an adequate level of security, your acknowledgement of the privacy policy in the context of the contact forms is considered consent within the meaning of Art. 49 (1) a DSGVO, which justifies a data transfer to insecure third countries.

(1) Free offer of digital content

In order to provide you with selected digital content (e.g. whitepapers and e-books), we collect personal data from you.

  • Data collected: Email address, first name, last name, phone number, organization, role in the organization, Discovered via.
  • Processing purpose: Personalized sending of the requested digital content.
  • Storage period: the data will be stored for as long as it is necessary to achieve the purpose. After the content has been sent, the data will be deleted unless you explicitly consent to the use of the data for contacting you in the context of the content provided.
  • Legal basis: Art. 6 (1) b DSGVO (fulfillment of contract)

(2) Newsletter

If you subscribe to our newsletter, we store your e-mail address and use it to send the newsletter. Your email address will not be published or shared with third parties.

  • Data collected: Email address, first name, last name, phone number, organization, role in the organization, Discovered via.
  • Purpose of processing: sending the requested newsletter.
  • Storage period: the data will be stored as long as it is necessary to achieve the purpose. For the newsletter, the data will be stored as long as a sending of a newsletter is foreseen and you have not objected to the use of your data.
  • Legal basis: Art. 6 (1) a DSGVO (consent).
Cancellation: You can unsubscribe from our newsletter at any time via a link contained in each issue. We will then delete your e-mail address from our distribution list. Alternatively, you can unsubscribe from the newsletter at any time by sending an email to newsletter@descript.de.

(3) Get-to-know interview

If you request an appointment for a get-to-know-you conversation, we will use your information to contact you and work with you to schedule and conduct an appointment.

  • Data collected: Email address, last name, first name, phone number, organization, role in the organization, discovered via, description of activities.
  • Purpose of processing: preparation and follow-up, coordination and implementation of the requested meeting to get to know each other.
  • Storage period: the data will be stored for as long as necessary to achieve the purpose. The data will be stored for as long as necessary to prepare, follow up and carry out the appointment.
  • Legal basis: Art. 6 (1) f DSGVO (Legitimate Interest).

(4) Webinars

If you register for a free webinar, we will use your data to send you the invitation and information related to the webinar.

  • Data collected: Last name, first name, phone number, organization, role in the organization, Discovered via.
  • Purpose of processing: sending the requested invitation to the webinar, preparing, conducting and following up the webinar, as well as using the personal data for marketing purposes.
  • Storage period: the data is stored for as long as necessary to achieve the purpose. If the consent for marketing purposes is revoked, the data stored by us will be deleted. Legal basis: Art. 6 (1) b in conjunction with. Art. 6 (1) a DSGVO.
  • Legal basis: By registering for the webinar, you also automatically agree to your personal data being processed for marketing purposes. The legal basis is your consent given to us beforehand in accordance with Art. 6 (1) a DSGVO. Consent to the use of the collected personal data for marketing purposes is a prerequisite for participation in free webinars. You can separately object to the use of personal data for marketing purposes at any time.

§ 21 Privacy Policy on the Use and Usage of Spotify

We use the provider Spotify for the integration of audio material (music and podcasts). Spotify is operated by Spotify AB, headquartered at Regeringsgatan 19, SE-111 53 Stockholm.

On some of our Internet pages, we use plugins from the provider Spotify. When you call up the web pages of our website that are provided with such a plugin, a connection to the Spotify servers is established and the plugin is displayed. This transmits to the Spotify server which of our Internet pages you have visited. If you are logged in to Spotify as a user, Spotify can assign this information to your personal user account. When using the plugin, such as clicking on the start button of an audio file or playlist, this information is also assigned to your user account. You can prevent this assignment by logging out of your Spotify user account before using our website and deleting the corresponding cookies from Spotify.

For the purpose and scope of the data collection and the further processing and use of the data by Spotify, as well as your rights in this regard and setting options for protecting your privacy, please refer to Spotify's privacy policy: https://spotify.com/de/legal/privacy-policy

§ 22 Privacy Policy on the Use and Usage of Meta Pixel

We use the visitor action pixel from Meta on our website to measure conversions. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. The data collected is also transferred by Meta to the USA and other third countries. Meta is a participant in the EU-US Data Privacy Framework, which regulates the correct and secure transfer of personal data of EU citizens to the USA. More at https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

The behavior of our site visitors can be tracked after they have been redirected to our website by clicking on a Meta advertisement. This allows us to evaluate the effectiveness of Meta ads for statistical and market research purposes and optimize them for future advertising measures.

The data collected is anonymous to us as the operator of this website and we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Meta so that a connection to the respective user profile is possible and Meta can use the data for its own advertising purposes in accordance with the Meta Privacy Policy. This allows Meta to place advertisements on Meta pages and outside Meta. This use of the data cannot be influenced by us as the website operator.

The Meta pixel is used on the basis of Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in effective advertising measures, including social media. If a corresponding consent has been requested (e.g. consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR; the consent can be revoked at any time.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. Details can be found here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Meta, we and Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its transfer to Meta. The processing carried out by Meta after forwarding is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing data protection information when using the Meta pixel and for the secure implementation of the pixel on our website in accordance with data protection law. Meta is responsible for the data security of Meta products. You can assert data subject rights (e.g. requests for information) regarding the data processed by Meta directly with Meta. If you assert your data subject rights with us, we are obliged to forward them to Meta.

You can find further information on the protection of your privacy in Meta's data protection information: https://www.facebook.com/privacy/center/.

You can also deactivate settings for advertisements at https://www.facebook.com/settings/?tab=privacy or https://www.instagram.com/accounts/privacy_and_security/. To do this, you must be logged in to Facebook or Instagram.

If you do not have a Facebook or Instagram account, you can deactivate usage-based advertising from Meta on the website of the European Interactive Digital Advertising Alliance: https://www.youronlinechoices.com/de/praferenzmanagement/.

§ 23 Facebook Conversion API

We have integrated Facebook Conversion API on this website. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the data collected is also transferred to the USA and other third countries.

Facebook Conversion API enables us to record the website visitor's interactions with our website and pass them on to Facebook in order to improve advertising performance on Facebook.

In particular, the time of the call, the website called up, your IP address and your user agent and, if applicable, other specific data (e.g. products purchased, value of the shopping cart and currency) are recorded. You can find a complete overview of the data that can be collected here: https://developers.facebook.com/docs/marketing-api/conversions-api/parameters.

The use of this service is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG. Consent can be revoked at any time.

If personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of data and its transfer to Facebook. The joint responsibility is limited exclusively to the collection of the data and its forwarding to Facebook. The processing carried out by Facebook after forwarding is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in an agreement on joint processing. The text of the agreement can be found at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook tool and for the secure implementation of the tool on our website in accordance with data protection law. Facebook is responsible for the data security of Facebook products. You can assert data subject rights (e.g. requests for information) regarding the data processed by Facebook directly with Facebook. If you assert your data subject rights with us, we are obliged to forward them to Facebook.

Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

You can find further information on protecting your privacy in Facebook's privacy policy: https://de-de.facebook.com/about/privacy/.

The company is certified in accordance with the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA that is intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&id=a2zt0000000GnywAAC&status=Active

§ 24 Heyflow

We use an external service provider for the provision of our online offer: Heyflow GmbH, Jungfernstieg 49, 20354 Hamburg, Germany (hereinafter referred to as "Heyflow"). Heyflow itself stores your data exclusively on European servers. However, there is a possibility that your data may be accessible to facilities in the United States of America, as Heyflow uses sub-processors based in the USA. Since the Commission of the European Union has determined that the data protection laws of the United States do not ensure an adequate level of protection for personal data collected from data subjects in the European Union, Heyflow provides additional measures and safeguards for data transfers to the United States in accordance with the requirements of the GDPR to ensure an adequate level of protection. For example, through the conclusion of standard contractual clauses between Heyflow and the sub-processors.

(1) Description and scope of data processing

Heyflow processes your data for us so that we can provide you with our online services. For this purpose, your IP address is automatically transmitted to Heyflow in order to transmit the content and functions of our online services to your browser or device.

The following data may be collected:

  • information about the browser type and version used
  • the operating system of your computer
  • the internet service provider you use
  • the IP address of your terminal device
  • the date and time of your access to the funnel
  • websites from which you came to our website ("referrer")

(2) Legal basis for data processing

Heyflow stores the data mentioned under (1). in so-called log files. This is done to ensure

  • ensuring a smooth connection to the website,
  • to ensure a comfortable use of our website
  • the evaluation of system security and stability and
  • for other administrative purposes.

The temporary storage of the IP address by the system is also necessary to enable the website to be delivered to your computer. For this purpose, the IP address of your computer must remain stored for the duration of the session.

Our legitimate interest in data processing also lies in these purposes. The legal basis for data processing is therefore Art. 6 para. 1 sentence 1 lit. f GDPR.

(3) Duration of the processing

The personal data processed by Heyflow will be deleted as soon as it is no longer required to achieve the purpose for which it was collected:

  • In the case of the collection of data for the provision of the website, this is the case when the respective session has ended.
  • In the case of storage of the IP address in log files, this is the case after 7 days at the latest.

(4) Rights of data subjects

The provisions of headline "Rights of the data subject" apply.

§ 25 Erstellung von Angeboten und Kostenvoranschlägen für Neukunden

Wir verarbeiten die von Ihnen bereitgestellten personenbezogenen Daten ausschließlich zur Bearbeitung Ihrer Anfrage und zur Erstellung eines Angebotes oder Kostenvoranschlags (Art. 6 Abs. 1 Buchstabe b DSGVO).

Sollte es zur erstmaligen Beauftragung kommen, übernehmen wir Ihre personenbezogenen Daten für die Vertragserfüllung (Art. 6 Abs. 1 Buchstabe b DSGVO). Erfolgt keine weitere Zusammenarbeit, werden die Daten gesperrt und aufbewahrt, um eine mögliche zukünftige Zusammenarbeit zu erleichtern.

§ 26 Privacy Policy on the Use and Usage of Loom

Loom is a platform that makes it possible to make recordings of the computer screen and at the same time record the person recording via a webcam and with sound. This way viewers of a video in which something is shown or explained can see the author at the same time.

The operating company of Loom is Loom, Inc., 140 2nd Street, 3rd Floor, San Francisco, CA 94105, USA.

The Loom video embedded on our pages contains the video itself, text information about the video, the publication date, the number of views and information about the author, a field for entering text relating to selected parts of the video, emoji for submitting a reaction to the video and a share menu. This includes the option to share on other platforms. No registration is required to submit a text comment, but a name is required. However, this can be chosen freely.

If the person concerned is logged in to Loom at the same time, Loom recognizes which specific video of our website the person concerned is visiting by calling up a subpage that embeds a Loom video. This information is collected by Loom and assigned to the respective Loom account of the data subject.

The data protection regulations published by Loom, which are available at https://www.loom.com/privacy , provide information about the collection, processing and use of personal data by Loom.

§ 27 Nutzung des Noahworks KI-Creators

Auf unserer Website bieten wir mit dem Noahworks KI-Creator ein interaktives Formular-Tool an, das es Ihnen ermöglicht, aus Stichpunkten, Schlagwörtern oder kurzen Beschreibungen mithilfe Künstlicher Intelligenz automatisch Textvorschläge zu erzeugen.

Art und Umfang der Datenverarbeitung

Bei der Nutzung des KI-Creators können Sie freiwillig Eingaben in die bereitgestellten Formularfelder vornehmen. Diese Eingaben werden nach dem Absenden an unseren Server übermittelt, wo daraus ein sogenannter Prompt (Eingabeanweisung) erzeugt wird. Anschließend wird dieser Prompt im Rahmen einer Anfrage an die Schnittstelle (API) des Dienstes OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA, übermittelt, um dort eine KI-gestützte Textgenerierung durchzuführen.

Es kann vorkommen, dass Sie in den Eingabefeldern personenbezogene Daten angeben. Dies liegt in Ihrer eigenen Verantwortung. Wir empfehlen, keine sensiblen oder identifizierenden Daten (z. B. Namen, Kontaktdaten, Gesundheitsangaben) einzugeben, sofern dies für Ihre Anfrage nicht erforderlich ist.

Zweck der Verarbeitung

Die Verarbeitung erfolgt ausschließlich zur Bereitstellung der vom Nutzer angeforderten KI-gestützten Textvorschläge und damit zur Verbesserung der Nutzererfahrung auf unserer Website.

Rechtsgrundlage

Die Verarbeitung erfolgt – soweit Sie selbst Eingaben tätigen – auf Grundlage Ihrer Einwilligung gemäß Art. 6 Abs. 1 lit. a DSGVO. Soweit keine personenbezogenen Daten eingegeben werden, erfolgt die Verarbeitung auf Grundlage unseres berechtigten Interesses an einer nutzerfreundlichen und innovativen Gestaltung unseres Online-Angebots gemäß Art. 6 Abs. 1 lit. f DSGVO.

Weitergabe von Daten an Dritte / Drittlandübermittlung

Die Weitergabe der aus Ihren Eingaben generierten Prompts erfolgt an OpenAI zur Generierung der KI-Antwort. Die Verarbeitung durch OpenAI erfolgt in den Vereinigten Staaten von Amerika (USA).Mit OpenAI wurde ein Datenschutzrahmen gemäß den Standardvertragsklauseln der EU-Kommission abgeschlossen, um ein angemessenes Schutzniveau für übermittelte Daten sicherzustellen. Weitere Informationen finden Sie unter: openai.com/privacy

Speicherdauer

Die übermittelten Eingaben und erzeugten Prompts werden auf unseren Servern nur so lange gespeichert, wie dies für die Verarbeitung der Anfrage und ggf. zur Fehlersuche notwendig ist. Eine weitergehende Speicherung oder Auswertung der Inhalte erfolgt nicht.

§ 28 Status of and amendments to this privacy notice

We review this privacy notice regularly and amend it where the processing activities we carry out change or where legal, technical or organisational developments make an amendment necessary.

The version of this privacy notice published on this website at the relevant time applies.