acadora.
FeaturesInside the editorHow it works
Log inStart free

Privacy

Privacy Policy of acadora.ai concerning the processing of personal data.

1. Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data means any data by which you can be personally identified. Detailed information on data protection can be found in the Privacy Policy set out below.

Data Collection on This Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. The operator’s contact details can be found in the section entitled “Information on the Controller” in this Privacy Policy.

How do we collect your data?

Some data is collected when you provide it to us. This may, for example, include data that you enter in a contact form. Other data is collected automatically by our IT systems when you visit the website or after you have given your consent. This primarily comprises technical data (e.g. internet browser, operating system or time of page access). This data is collected automatically as soon as you access this website.

What do we use your data for?

Some of the data is collected to ensure that the website is provided without errors. Other data may be used to analyse your user behaviour.

What rights do you have regarding your data?

You have the right at any time to obtain, free of charge, information about the source, recipients and purpose of your stored personal data. You also have the right to request the rectification or erasure of this data. If you have given consent to data processing, you may withdraw that consent at any time with effect for the future. You also have the right, under certain circumstances, to request restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority. You may contact us at any time regarding these and any other questions concerning data protection. Analytics Tools and Third-Party Tools When you visit this website, your browsing behaviour may be statistically evaluated. This is carried out primarily using analytics programs. Detailed information on these analytics programs can be found in the following Privacy Policy.

2. Hosting

We host the content of our website with the following provider: webgo The provider is webgo GmbH, Heidenkampsweg 81, 20097 Hamburg, Germany (hereinafter “webgo”). When you visit our website, webgo collects various log files, including your IP address. For details, please refer to webgo’s privacy policy: https://www.webgo.de/datenschutz/. webgo is used on the basis of Article 6(1)(f) GDPR. We have a legitimate interest in ensuring that our website is displayed as reliably as possible. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TTDSG, insofar as the consent covers the storage of cookies or access to

information on the user’s terminal device (e.g. for device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time. Data Processing We have entered into a data processing agreement (DPA) for the use of the above service. This agreement is required under data protection law and ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

3. General Information and Mandatory Disclosures Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data as confidential and in accordance with applicable data protection legislation and this Privacy Policy. When you use this website, various personal data is collected. Personal data means data by which you can be personally identified. This Privacy Policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done. Please note that data transmission over the internet (e.g. communication by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties is not possible. Information on the Controller The controller responsible for data processing on this website is: The provider of this website is: Acadeo GmbH

Managing Directors: Dr Jonathan Schulte, Julian Schulte
Registered office: Rathausstraße 43, 57537 Wissen, Germany

Email: support@acadora.ai

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data (e.g. names, email addresses or similar information). Storage Period Unless a more specific storage period is stated in this Privacy Policy, your personal data will remain with us until the purpose for processing the data no longer applies. If you submit a legitimate request for erasure or withdraw your consent to data processing, your data will be erased unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the data will be erased once those grounds cease to apply. General Information on the Legal Bases for Data Processing on This Website Where you have consented to data processing, we process your personal data on the basis of Article 6(1)(a) GDPR or Article 9(2)(a) GDPR where special categories of personal data within the meaning of Article 9(1) GDPR are processed. Where express consent has been given to the transfer of personal data to third countries, the data processing is also based on Article 49(1)(a) GDPR. Where you have consented to the storage of cookies or to access to information on your terminal device (e.g. by means of device fingerprinting), the data processing is additionally based on Section 25(1) TTDSG. Consent may be withdrawn at any time. Where your data is required for the performance of a contract or in order to take steps prior to entering into a contract, we process your data on the basis of Article 6(1)(b) GDPR. We also process your data on the basis of Article 6(1)(c) GDPR where this is necessary for compliance with a legal obligation. Data processing may also be based on our legitimate interests pursuant to Article 6(1)(f) GDPR. The legal bases applicable in each individual case are explained in the following sections of this Privacy Policy.

Information on Transfers to Third Countries Without an Adequate Level of Data Protection and Transfers to US Companies Not Certified Under the DPF Among other things, we use tools provided by companies established in third countries that do not provide an adequate level of data protection, as well as US-based tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in those countries. Please note that a level of data protection comparable to that in the EU cannot be guaranteed in third countries that do not provide an adequate level of data protection. Please note that, in principle, the United States is regarded as a safe third country providing a level of data protection comparable to that in the EU. A transfer of data to the United States is therefore permissible where the recipient is certified under the EU-US Data Privacy Framework (DPF) or has appropriate additional safeguards in place. Information on transfers to third countries, including the recipients of the data, can be found in this Privacy Policy. Recipients of Personal Data In the course of our business activities, we work with various external parties. In some cases, this requires personal data to be transferred to those external parties. We disclose personal data to external parties only where this is necessary for the performance of a contract, where we are legally required to do so (e.g. disclosure of data to tax authorities), where we have a legitimate interest in the disclosure pursuant to Article 6(1)(f) GDPR, or where another legal basis permits the disclosure. Where processors are used, we disclose our customers’ personal data only on the basis of a valid data processing agreement. In the case of joint processing, an agreement governing joint processing is entered into. Withdrawal of Your Consent to Data Processing Many data processing operations are possible only with your express consent. You may withdraw consent that you have already given at any time. The lawfulness of data processing carried out prior to withdrawal remains unaffected by the withdrawal.

Right to Object to Data Collection in Specific Cases and to Direct Marketing (Article 21 GDPR) WHERE DATA PROCESSING IS BASED ON ARTICLE 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ARTICLE 21(1) GDPR). WHERE YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSES OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL THEREAFTER NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ARTICLE 21(2) GDPR). Right to Lodge a Complaint with the Competent Supervisory Authority In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies. Right to Data Portability You have the right to receive data that we process by automated means on the basis of your consent or in performance of a contract, or to have it transmitted to a third party, in a

commonly used, machine-readable format. Where you request the direct transfer of the data to another controller, this will be carried out only where technically feasible. Access, Rectification and Erasure Within the scope of the applicable statutory provisions, you have the right at any time to obtain, free of charge, access to your stored personal data, information concerning its source and recipients and the purpose of the data processing, and, where applicable, the right to rectification or erasure of that data. You may contact us at any time regarding this and any other questions concerning personal data. Right to Restriction of Processing You have the right to request restriction of the processing of your personal data. You may contact us at any time for this purpose. The right to restriction of processing applies in the following cases: ●

If you contest the accuracy of the personal data stored by us, we will generally need time to verify this. For the duration of the verification, you have the right to request restriction of the processing of your personal data. ●

If the processing of your personal data was or is unlawful, you may request restriction of data processing instead of erasure. ●

If we no longer require your personal data, but you require it for the establishment, exercise or defence of legal claims, you have the right to request restriction of the processing of your personal data instead of erasure. ●

If you have objected pursuant to Article 21(1) GDPR, your interests and our interests must be balanced. Until it has been determined whose interests prevail, you have the right to request restriction of the processing of your personal data. Where you have restricted the processing of your personal data, such data may, apart from storage, be processed only with your consent or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State. SSL or TLS Encryption

For security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the website operator, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the change in the browser’s address bar from “http://” to “https://” and by the lock symbol in your browser bar. When SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.

4. Data Collection on This Website Cookies

Our websites use so-called “cookies”. Cookies are small data packets and do not cause any damage to your terminal device. They are stored on your terminal device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted when your visit ends. Persistent cookies remain stored on your terminal device until you delete them yourself or they are automatically deleted by your web browser. Cookies may be set by us (first-party cookies) or originate from third-party companies (third-party cookies). Third-party cookies enable certain services provided by third-party companies to be integrated into websites (e.g. cookies used to process payment services). Cookies perform various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g. the shopping basket function or the display of videos). Other cookies may be used to evaluate user behaviour or for advertising purposes. Cookies that are necessary for carrying out the electronic communications process, for providing certain functions requested by you (e.g. the shopping basket function), or for optimising the website (e.g. cookies used to measure web audiences) (“necessary cookies”) are stored on the basis of Article 6(1)(f) GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies in order to provide its services in a technically error-free and optimised manner. Where consent to the storage of

cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of that consent (Article 6(1)(a) GDPR and Section 25(1) TTDSG); consent may be withdrawn at any time. You can configure your browser to notify you when cookies are set, to allow cookies only in individual cases, to exclude the acceptance of cookies in specific cases or generally, and to activate the automatic deletion of cookies when the browser is closed. Disabling cookies may restrict the functionality of this website. Details of the cookies and services used on this website can be found in this Privacy Policy. Consent Management with Borlabs Cookie Our website uses the consent technology provided by Borlabs Cookie to obtain your consent to the storage of certain cookies in your browser or to the use of certain technologies, and to document that consent in compliance with data protection law. The provider of this technology is Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany (hereinafter “Borlabs”). When you access our website, a Borlabs cookie is stored in your browser in which the consents you have given or the withdrawal of those consents are recorded. This data is not disclosed to the provider of Borlabs Cookie. The collected data is stored until you ask us to erase it, delete the Borlabs cookie yourself, or the purpose for storing the data no longer applies. Mandatory statutory retention periods remain unaffected. Details regarding data processing by Borlabs Cookie can be found at https://de.borlabs.io/kb/welche-daten-speichert-borlabs-cookie/. Borlabs Cookie consent technology is used to obtain the consents required by law for the use of cookies. The legal basis is Article 6(1)(c) GDPR. Contact Form If you send us enquiries via the contact form, the information you provide in the enquiry form, including the contact details entered there, will be stored by us for the purpose of processing

the enquiry and in the event of follow-up questions. We do not disclose this data without your consent. This data is processed on the basis of Article 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary in order to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), where such consent has been requested; consent may be withdrawn at any time. The data you enter in the contact form will remain with us until you ask us to erase it, withdraw your consent to storage, or the purpose for storing the data no longer applies (e.g. after your enquiry has been fully processed). Mandatory statutory provisions, in particular retention periods, remain unaffected. Enquiries by Email, Telephone or Fax If you contact us by email, telephone or fax, your enquiry, including all personal data arising from it (name, enquiry), will be stored and processed by us for the purpose of handling your request. We do not disclose this data without your consent. This data is processed on the basis of Article 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary in order to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), where such consent has been requested; consent may be withdrawn at any time. The data you send to us in connection with contact enquiries will remain with us until you ask us to erase it, withdraw your consent to storage, or the purpose for storing the data no longer applies (e.g. after your request has been fully processed). Mandatory statutory provisions, in particular statutory retention periods, remain unaffected. Communication via WhatsApp

For communication with our customers and other third parties, we use, among other services, the instant messaging service WhatsApp. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Communications are protected by end-to-end encryption (peer-to-peer), which prevents WhatsApp or other third parties from accessing the content of the communications. WhatsApp does, however, have access to metadata generated in the course of the communication process (e.g. sender, recipient and time). We further note that, according to its own statements, WhatsApp shares personal data of its users with its US-based parent company, Meta. Further details on data processing can be found in WhatsApp’s privacy policy at: https://www.whatsapp.com/legal/#privacy-policy. WhatsApp is used on the basis of our legitimate interest in communicating as quickly and effectively as possible with customers, prospective customers and other business and contractual partners (Article 6(1)(f) GDPR). Where corresponding consent has been requested, the data processing is carried out exclusively on the basis of that consent; consent may be withdrawn at any time with effect for the future. The content of communications exchanged between you and us via WhatsApp will remain with us until you ask us to erase it, withdraw your consent to storage, or the purpose for storing the data no longer applies (e.g. after your enquiry has been fully processed). Mandatory statutory provisions, in particular retention periods, remain unaffected. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt00000011sfnAAA&status=Active We use the “WhatsApp Business” version of WhatsApp.

Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://www.whatsapp.com/legal/business-data-transfer-addendum. We have configured our WhatsApp accounts so that they do not automatically synchronise data with the address books on the smartphones used. We have entered into a data processing agreement (DPA) with the above provider. Google Forms We have integrated Google Forms into this website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”). Google Forms enables us to create online forms in order to record messages, enquiries and other submissions from visitors to our website in a structured manner. All entries you make are processed on Google’s servers. Google Forms stores a cookie containing a unique ID in your browser (NID cookie). This cookie stores various information, such as your language settings. Google Forms is used on the basis of our legitimate interest in identifying your request in the most user-friendly manner possible (Article 6(1)(f) GDPR). Where corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time. The data you enter in the form will remain with us until you ask us to erase it, withdraw your consent to storage, or the purpose for storing the data no longer applies (e.g. after your enquiry has been fully processed). Mandatory statutory provisions, in particular retention periods, remain unaffected. Further information can be found in Google’s privacy policy at https://policies.google.com/.

The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt000000001L5AAI&status=Active Data Processing We have entered into a data processing agreement (DPA) for the use of the above service. This agreement is required under data protection law and ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR. Registration on This Website You can register on this website in order to use additional features. We use the data entered during registration only for the purpose of providing the relevant offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise, we will reject the registration. We use the email address provided during registration to inform you of important changes, such as changes to the scope of the offering or technically necessary changes. The data entered during registration is processed for the purpose of administering the user relationship established by the registration and, where applicable, initiating further contracts (Article 6(1)(b) GDPR). The data collected during registration is stored by us for as long as you remain registered on this website and is subsequently erased. Statutory retention periods remain unaffected. Registration with Google

Instead of registering directly on this website, you may register using Google. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. To register using Google, you need only enter your Google username and password. Google will identify you and confirm your identity to our website. When you sign in using Google, we may be able to use certain information from your account to complete your profile with us. You determine whether and which information is made available through your Google security settings, which can be found at: https://myaccount.google.com/security and https://myaccount.google.com/permissions. The data processing associated with registration through Google is based on our legitimate interest in enabling our users to register as easily as possible (Article 6(1)(f) GDPR). Since use of the registration function is voluntary and users themselves determine the relevant access permissions, no overriding rights of data subjects that would preclude the processing are apparent. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt000000001L5AAI&status=Active Registration with Facebook Connect Instead of registering directly on this website, you may register using Facebook Connect. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, however, the collected data is also transferred to the United States and other third countries.

If you choose to register using Facebook Connect and click the “Login with Facebook” or “Connect with Facebook” button, you will automatically be redirected to the Facebook platform. You can sign in there using your login details. This links your Facebook profile to this website or our services. Through this link, we gain access to the data stored in your Facebook account. This primarily includes: ●

Facebook name ●

Facebook profile picture and cover photo ●

Facebook cover photo ●

Email address stored with Facebook
●

Facebook ID ●

Facebook friends lists ●

Facebook likes ●

Date of birth ●

Gender ●

Country ●

Language This data is used to set up, provide and personalise your account. Registration through Facebook Connect and the associated data processing operations are carried out on the basis of your consent (Article 6(1)(a) GDPR). You may withdraw this consent at any time with effect for the future. Insofar as personal data is collected on our website using the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are joint controllers for this processing (Article 26 GDPR). The joint controllership is limited exclusively to the collection of the data and its transmission to Facebook. Processing carried out by Facebook after the transmission does

not form part of the joint controllership. Our respective joint obligations have been set out in a joint controllership arrangement. The wording of the arrangement can be found at: https://www.facebook.com/legal/controller_addendum. Under this arrangement, we are responsible for providing privacy information when the Facebook tool is used and for implementing the tool on our website in a manner compliant with data protection law. Facebook is responsible for the data security of Facebook products. You may exercise data subject rights (e.g. requests for access) concerning data processed by Facebook directly against Facebook. If you exercise your data subject rights against us, we are required to forward the request to Facebook. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php. Further information can be found in Facebook’s Terms of Service and Privacy Policy at: https://de-de.facebook.com/about/privacy/ and https://de-de.facebook.com/legal/terms/. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt0000000GnywAAC&status=Active Comment Function on This Website For the comment function on this website, in addition to your comment, we store information concerning the time at which the comment was created, your email address and, if you do not post anonymously, the username you have selected.

Storage Period for Comments Comments and the associated data are stored and remain on this website until the content to which the comment relates has been completely deleted or the comments must be deleted for legal reasons (e.g. offensive comments). Legal Basis Comments are stored on the basis of your consent (Article 6(1)(a) GDPR). You may withdraw consent that you have given at any time. An informal notification by email to us is sufficient. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal. ProvenExpert We have integrated ProvenExpert review badges into this website. The provider is Expert Systems AG, Quedlinburger Str. 1, 10589 Berlin, Germany, https://www.provenexpert.com. The ProvenExpert badge enables us to display customer reviews submitted about our company on ProvenExpert in the form of a badge on our website. When you visit our website, a connection to ProvenExpert is established, allowing ProvenExpert to determine that you have visited our website. ProvenExpert also records your language settings in order to display the badge in the selected national language. ProvenExpert is used on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in presenting customer reviews in a manner that is as transparent and verifiable as possible. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time.

5. Analytics Tools and Advertising Google Tag Manager

We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is a tool that enables us to integrate tracking or statistics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, store cookies or carry out independent analyses. It is used solely to manage and deploy the tools integrated through it. Google Tag Manager does, however, collect your IP address, which may also be transferred to Google’s parent company in the United States. Google Tag Manager is used on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in integrating and managing various tools on its website quickly and easily. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt000000001L5AAI&status=Active Google Analytics This website uses functions of the Google Analytics web analytics service. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics enables the website operator to analyse the behaviour of website visitors. In this context, the website operator receives various usage data, such as page views,

length of visit, operating systems used and the user’s origin. This data is combined under a user ID and assigned to the relevant website visitor’s terminal device. Google Analytics may also enable us to record, among other things, your mouse and scrolling movements and clicks. Google Analytics also uses various modelling approaches to supplement the collected datasets and uses machine-learning technologies for data analysis. Google Analytics uses technologies that enable users to be recognised for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). The information collected by Google concerning the use of this website is generally transferred to a Google server in the United States and stored there. This service is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://privacy.google.com/businesses/controllerterms/mccs/. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt000000001L5AAI&status=Active IP Anonymisation Google Analytics IP anonymisation is enabled. As a result, Google truncates your IP address within Member States of the European Union or in other states party to the Agreement on the European Economic Area before it is transmitted to the United States. Only in exceptional cases is the full IP address transferred to a Google server in the United States

and truncated there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, compile reports on website activity and provide the website operator with other services relating to website and internet usage. The IP address transmitted by your browser in connection with Google Analytics will not be combined with other data held by Google. Browser Plugin You can prevent Google from collecting and processing your data by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de. Further information on how Google Analytics handles user data can be found in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de. Google Signals We use Google Signals. When you visit our website, Google Analytics collects, among other things, your location, search history and YouTube history, as well as demographic data (visitor data). This data may be used for personalised advertising with the assistance of Google Signals. If you have a Google account, visitor data collected by Google Signals is linked to your Google account and used for personalised advertising messages. The data is also used to compile anonymised statistics regarding the user behaviour of our users. Data Processing We have entered into a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics. Google Analytics E-Commerce Measurement This website uses the Google Analytics “E-Commerce Measurement” function. E-Commerce Measurement enables the website operator to analyse the purchasing behaviour of website visitors in order to improve its online marketing campaigns. Information such as orders placed, average order values, shipping costs and the time from viewing a product to

purchasing it is collected. Google may combine this data under a transaction ID assigned to the relevant user or the user’s device. Google Ads The website operator uses Google Ads. Google Ads is an online advertising program provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads enables us to display advertisements in the Google search engine or on third-party websites when a user enters certain search terms into Google (keyword targeting). Targeted advertisements may also be displayed on the basis of user data held by Google (e.g. location data and interests) (audience targeting). As the website operator, we can quantitatively evaluate this data, for example by analysing which search terms resulted in our advertisements being displayed and how many advertisements led to corresponding clicks. This service is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://policies.google.com/privacy/frameworks and https://privacy.google.com/businesses/controllerterms/mccs/. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt000000001L5AAI&status=Active Google AdSense

This website uses Google AdSense, a service for integrating advertisements. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google AdSense enables us to display targeted advertisements from third-party companies on our website. The content of the advertisements is based on your interests, which Google determines from your previous user behaviour. Contextual information, such as your location, the content of the website visited or Google search terms entered by you, is also taken into account when selecting a suitable advertisement. Google AdSense uses cookies, web beacons (invisible graphics) and comparable recognition technologies. These technologies make it possible to evaluate information such as visitor traffic on these pages. Information collected by Google AdSense concerning the use of this website (including your IP address) and the delivery of advertising formats is transferred to a Google server in the United States and stored there. Google may disclose this information to its contractual partners. However, Google will not combine your IP address with other data stored about you. This service is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://privacy.google.com/businesses/controllerterms/mccs/. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt000000001L5AAI&status=Active

Google Ads Remarketing This website uses Google Ads Remarketing functions. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads Remarketing enables us to assign people who interact with our online offering to specific audiences in order subsequently to display interest-based advertising to them within the Google advertising network (remarketing or retargeting). The advertising audiences created using Google Ads Remarketing may also be linked to Google’s cross-device functions. In this way, interest-based, personalised advertising messages adapted to you on one terminal device (e.g. a mobile phone) on the basis of your previous usage and browsing behaviour may also be displayed on another of your terminal devices (e.g. a tablet or PC). If you have a Google account, you can object to personalised advertising at the following link: https://www.google.com/settings/ads/onweb/. This service is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time. Further information and the applicable privacy provisions can be found in Google’s privacy policy at: https://policies.google.com/technologies/ads?hl=de. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt000000001L5AAI&status=Active Audience Creation Using Customer Match

For audience creation, we use, among other things, Google Ads Remarketing’s Customer Match function. In this process, we provide Google with certain customer data (e.g. email addresses) from our customer lists. If the relevant customers are Google users and are signed in to their Google accounts, suitable advertising messages are displayed to them within the Google network (e.g. on YouTube, Gmail or the search engine). Meta Pixel (Formerly Facebook Pixel) This website uses the visitor action pixel provided by Facebook/Meta for conversion measurement. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, however, the collected data is also transferred to the United States and other third countries. This makes it possible to track the behaviour of website visitors after they have been redirected to the provider’s website by clicking on a Facebook advertisement. This enables the effectiveness of Facebook advertisements to be evaluated for statistical and market research purposes and future advertising measures to be optimised. The collected data is anonymous to us as the operator of this website, and we cannot draw any conclusions regarding the identity of users. The data is, however, stored and processed by Facebook, meaning that it may be linked to the relevant user profile and Facebook may use the data for its own advertising purposes in accordance with Facebook’s Data Use Policy (https://de-de.facebook.com/about/privacy/). This enables Facebook to display advertisements both on Facebook pages and outside Facebook. We, as the website operator, cannot influence this use of the data. This service is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time. We use the advanced matching function within Meta Pixel. Advanced matching enables us to transmit to Meta (Facebook) various types of data concerning our customers and prospective customers that we collect through our website (e.g. place of residence, federal state, postcode, hashed email addresses, names, gender,

date of birth or telephone number). Enabling this function allows us to target our Facebook advertising campaigns even more precisely at people who are interested in our offerings. Advanced matching also improves the attribution of website conversions and expands Custom Audiences. Insofar as personal data is collected on our website using the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, are joint controllers for this processing (Article 26 GDPR). The joint controllership is limited exclusively to the collection of the data and its transmission to Facebook. Processing carried out by Facebook after the transmission does not form part of the joint controllership. Our respective joint obligations have been set out in a joint controllership arrangement. The wording of the arrangement can be found at: https://www.facebook.com/legal/controller_addendum. Under this arrangement, we are responsible for providing privacy information when the Facebook tool is used and for implementing the tool on our website in a manner compliant with data protection law. Facebook is responsible for the data security of Facebook products. You may exercise data subject rights (e.g. requests for access) concerning data processed by Facebook directly against Facebook. If you exercise your data subject rights against us, we are required to forward the request to Facebook. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381. Further information on protecting your privacy can be found in Facebook’s privacy information: https://de-de.facebook.com/about/privacy/. You can also disable the “Custom Audiences” remarketing function in the advertising settings at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. You must be signed in to Facebook to do so.

If you do not have a Facebook account, you can disable Facebook’s usage-based advertising on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt0000000GnywAAC&status=Active Facebook Conversion API We have integrated Facebook Conversion API into this website. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, however, the collected data is also transferred to the United States and other third countries. Facebook Conversion API enables us to record website visitors’ interactions with our website and transmit them to Facebook in order to improve advertising performance on Facebook. In particular, the time of access, the website accessed, your IP address and user agent, as well as, where applicable, other specific data (e.g. products purchased, shopping basket value and currency), are collected for this purpose. A complete overview of the data that may be collected can be found at: https://developers.facebook.com/docs/marketing-api/conversions-api/parameters. This service is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time. Insofar as personal data is collected on our website using the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square,

Grand Canal Harbour, Dublin 2, Ireland, are joint controllers for this processing (Article 26 GDPR). The joint controllership is limited exclusively to the collection of the data and its transmission to Facebook. Processing carried out by Facebook after the transmission does not form part of the joint controllership. Our respective joint obligations have been set out in a joint controllership arrangement. The wording of the arrangement can be found at: https://www.facebook.com/legal/controller_addendum. Under this arrangement, we are responsible for providing privacy information when the Facebook tool is used and for implementing the tool on our website in a manner compliant with data protection law. Facebook is responsible for the data security of Facebook products. You may exercise data subject rights (e.g. requests for access) concerning data processed by Facebook directly against Facebook. If you exercise your data subject rights against us, we are required to forward the request to Facebook. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381. Further information on protecting your privacy can be found in Facebook’s privacy information: https://de-de.facebook.com/about/privacy/. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt0000000GnywAAC&status=Active Data Processing We have entered into a data processing agreement (DPA) for the use of the above service. This agreement is required under data protection law and ensures that the provider

processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR. Facebook Custom Audiences We use Facebook Custom Audiences. The provider of this service is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. When you visit or use our websites and apps, use our free or paid offerings, submit data to us, or interact with our company’s Facebook content, we collect your personal data in the process. If you consent to our use of Facebook Custom Audiences, we will transmit this data to Facebook, enabling Facebook to display suitable advertising to you. Your data may also be used to define audiences (Lookalike Audiences). Facebook processes this data as our processor. Details can be found in Facebook’s applicable terms: https://www.facebook.com/legal/terms/customaudience. This service is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://www.facebook.com/legal/terms/customaudience and https://www.facebook.com/legal/terms/dataprocessing. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt0000000GnywAAC&status=Active TikTok Pixel

We have integrated TikTok Pixel into this website. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (hereinafter “TikTok”). TikTok Pixel enables us to display interest-based advertising on TikTok (TikTok Ads) to website visitors who have viewed our offerings. At the same time, TikTok Pixel enables us to determine how effective our advertising on TikTok is. This allows the effectiveness of TikTok advertisements to be evaluated for statistical and market research purposes and optimised for future advertising measures. Various usage data is processed in this context, such as IP address, page views, length of visit, operating systems used and the user’s origin, information concerning the advertisement clicked by a person on TikTok, or an event that was triggered (timestamp). This data is combined under a user ID and assigned to the relevant website visitor’s terminal device. This service is used on the basis of your consent pursuant to Article 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time. Transfers of data to third countries are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://www.tiktok.com/legal/page/eea/privacy-policy/de-DE and https://ads.tiktok.com/i18n/official/policy/controller-to-controller. Data Processing We have entered into a data processing agreement (DPA) for the use of the above service. This agreement is required under data protection law and ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR. Pinterest Tag We have integrated Pinterest Tag into this website. The provider is Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.

Pinterest Tag is used to record certain actions that you perform on our website. The data may subsequently be used to display interest-based advertising to you on our website or on another website within the Pinterest Tag advertising network. For this purpose, Pinterest Tag collects, among other things, a tag ID, your location and the referrer URL. Action-specific data, such as order value, order quantity, order number, category of purchased items and video views, may also be collected. Pinterest Tag uses technologies that enable users to be recognised across websites for the purpose of analysing user behaviour (e.g. cookies or device fingerprinting). Where consent has been obtained, the above service is used exclusively on the basis of Article 6(1)(a) GDPR and Section 25 TTDSG. Consent may be withdrawn at any time. Where no consent has been obtained, this service is used on the basis of Article 6(1)(f) GDPR; the website operator has a legitimate interest in marketing measures that are as effective as possible. Pinterest operates worldwide, meaning that data may also be transferred to the United States. According to Pinterest, such transfers are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://policy.pinterest.com/de/privacy-policy. Further information on Pinterest Tag can be found at: https://help.pinterest.com/de/business/article/track-conversions-with-pinterest-tag. Data Processing We have entered into a data processing agreement (DPA) for the use of the above service. This agreement is required under data protection law and ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

6. Newsletter Newsletter Data

If you wish to subscribe to the newsletter offered on the website, we require your email address and information that enables us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected, or it is collected only on a voluntary basis. We use the newsletter service providers described below to administer the newsletter. Mailchimp with Performance Measurement Disabled This website uses Mailchimp services to send newsletters. The provider is The Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA. Mailchimp is a service that can be used, among other things, to organise the sending of newsletters. If you enter data for the purpose of subscribing to the newsletter (e.g. your

email address), that data is stored on Mailchimp’s servers in the United States. We have

disabled performance measurement in Mailchimp, meaning that Mailchimp will not evaluate your behaviour when opening our newsletters. If you do not wish your data to be transferred to Mailchimp, you must unsubscribe from the newsletter. A corresponding link is provided in every newsletter message. The data processing is based on your consent (Article 6(1)(a) GDPR). You may withdraw this consent at any time by unsubscribing from the newsletter. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal. The data you provide to us for the purpose of subscribing to the newsletter is stored by us or the newsletter service provider until you unsubscribe from the newsletter and is deleted from the newsletter distribution list after you unsubscribe. Data stored by us for other purposes remains unaffected. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://mailchimp.com/eu-us-data-transfer-statement/ and https://mailchimp.com/legal/data-processing-addendum/#Annex_C_-_Standard_Contractual _Clauses.

After you unsubscribe from the newsletter distribution list, your email address may be stored by us or the newsletter service provider on a suppression list where this is necessary to prevent future mailings. Data on the suppression list is used solely for this purpose and is not combined with other data. This serves both your interests and our interest in complying with the legal requirements governing the sending of newsletters (legitimate interest within the meaning of Article 6(1)(f) GDPR). Storage on the suppression list is not subject to a fixed time limit. You may object to the storage where your interests override our legitimate interest. Further details can be found in Mailchimp’s privacy provisions at: https://mailchimp.com/legal/terms/. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt0000000TXVKAA4&status=Active Data Processing We have entered into a data processing agreement (DPA) for the use of the above service. This agreement is required under data protection law and ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR. ActiveCampaign This website uses ActiveCampaign to send newsletters. The provider is ActiveCampaign, Inc., 1 N Dearborn, 5th Floor, Chicago, Illinois 60602, USA. ActiveCampaign is a service that can be used, among other things, to organise and analyse the sending of newsletters. The data you enter for the purpose of subscribing to the newsletter is stored on ActiveCampaign’s servers in the United States.

Data Analysis by ActiveCampaign ActiveCampaign enables us to analyse our newsletter campaigns. For example, we can see whether a newsletter message has been opened and which links, if any, have been clicked. This allows us, among other things, to determine which links are clicked particularly frequently. We can also determine whether certain predefined actions were performed after a message was opened or a link was clicked (conversion rate). For example, we can determine whether you made a purchase after clicking on the newsletter. ActiveCampaign also enables us to divide (“cluster”) newsletter recipients into different categories. Newsletter recipients can, for example, be divided by age, gender or place of residence. This enables newsletters to be tailored more effectively to the relevant target audiences. If you do not want ActiveCampaign to analyse your data, you must unsubscribe from the newsletter. A corresponding link is provided in every newsletter message. Detailed information on ActiveCampaign’s functions can be found at: https://www.activecampaign.com/email-marketing. ActiveCampaign’s privacy policy can be found at: https://www.activecampaign.com/privacy-policy. Legal Basis The data processing is based on your consent (Article 6(1)(a) GDPR). You may withdraw this consent at any time. The lawfulness of data processing operations already carried out remains unaffected by the withdrawal. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://www.activecampaign.com/legal/newscc and https://www.activecampaign.com/de/legal/gdpr-updates/privacy-shield. Storage Period

The data you provide to us for the purpose of subscribing to the newsletter is stored by us or the newsletter service provider until you unsubscribe from the newsletter and is deleted from the newsletter distribution list after you unsubscribe. Data stored by us for other purposes remains unaffected. After you unsubscribe from the newsletter distribution list, your email address may be stored by us or the newsletter service provider on a suppression list where this is necessary to prevent future mailings. Data on the suppression list is used solely for this purpose and is not combined with other data. This serves both your interests and our interest in complying with the legal requirements governing the sending of newsletters (legitimate interest within the meaning of Article 6(1)(f) GDPR). Storage on the suppression list is not subject to a fixed time limit. You may object to the storage where your interests override our legitimate interest. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt0000000GnH6AAK&status=Active Data Processing We have entered into a data processing agreement (DPA) for the use of the above service. This agreement is required under data protection law and ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

7. Plugins and Tools YouTube with Enhanced Privacy

This website embeds videos from YouTube. The website operator is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit one of our pages on which YouTube is embedded, a connection to YouTube’s servers is established. The YouTube server is informed which of our pages you have visited. If you are signed in to your YouTube account, you allow YouTube to associate your browsing behaviour directly with your personal profile. You can prevent this by signing out of your YouTube account. We use YouTube in enhanced privacy mode. According to YouTube, videos played in enhanced privacy mode are not used to personalise browsing on YouTube. Advertisements displayed in enhanced privacy mode are also not personalised. No cookies are set in enhanced privacy mode. However, so-called local storage elements are stored in the user’s browser; these contain personal data in a manner similar to cookies and may be used for recognition purposes. Details on enhanced privacy mode can be found at: https://support.google.com/youtube/answer/171780. Activating a YouTube video may, where applicable, trigger further data processing operations over which we have no control. YouTube is used in the interest of presenting our online offerings in an appealing manner. This constitutes a legitimate interest within the meaning of Article 6(1)(f) GDPR. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time. Further information on data protection at YouTube can be found in its privacy policy at: https://policies.google.com/privacy?hl=de. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at:

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt000000001L5AAI&status=Active Google Fonts (Local Hosting) This website uses Google Fonts provided by Google to ensure consistent font display. The Google Fonts are installed locally. No connection to Google servers is established. Further information on Google Fonts can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy: https://policies.google.com/privacy?hl=de. Font Awesome (Local Hosting) This website uses Font Awesome to ensure consistent font display. Font Awesome is installed locally. No connection to servers operated by Fonticons, Inc. is established. Further information on Font Awesome can be found in Font Awesome’s privacy policy at: https://fontawesome.com/privacy. SolidWP We have integrated SolidWP into this website. The provider is iThemes Media LLC, 1720 South Kelly Avenue, Edmond, OK 73013, USA (hereinafter “SolidWP”). SolidWP is used to protect our website against unwanted access and malicious cyberattacks. For this purpose, SolidWP collects, among other things, your IP address, the time and source of login attempts, and log data (e.g. the browser used). SolidWP is installed locally on our servers. SolidWP transmits the IP addresses of repeat attackers to a central SolidWP database in the United States (Network Brute Force Protection) in order to prevent such attacks in the future. SolidWP is used on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its website against cyberattacks as effectively as possible. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TTDSG, insofar as the consent covers the

storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time. ChatGPT We use ChatGPT for customer communications. The provider is OpenAI, 3180 18th St, San Francisco, CA 94110, USA, https://openai.com. If you initiate a conversation with us through our website and ChatGPT is activated, your inputs, including metadata, are transmitted to ChatGPT’s servers and processed there in order to generate an appropriate response. OpenAI reserves the right to process inputs made in ChatGPT further in order to train its own algorithm. We are unable to assess precisely how the data is processed. ChatGPT is used on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in communicating with customers as efficiently as possible using modern technical solutions. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and Section 25(1) TTDSG. Consent may be withdrawn at any time. Further information can be found at: https://openai.com/policies/privacy-policy. ManageWP We manage this website using the ManageWP tool. The provider is GoDaddy.com WP Europe, Trg republike 5, 11000 Belgrade, Serbia (hereinafter “ManageWP”). ManageWP enables us, among other things, to monitor the security and performance of our website and create automatic backups. ManageWP therefore has access to all website content, including our databases. ManageWP is hosted on the provider’s servers. ManageWP is used on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in operating its website(s) as effectively and securely as possible. Where corresponding consent has been requested, processing is carried out exclusively on the

basis of Article 6(1)(a) GDPR and Section 25(1) TTDSG, insofar as the consent covers the storage of cookies or access to information on the user’s terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent may be withdrawn at any time. The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an arrangement between the European Union and the United States intended to ensure compliance with European data protection standards for data processing in the United States. Every company certified under the DPF undertakes to comply with these data protection standards. Further information is available from the provider at: https://www.dataprivacyframework.gov/s/participant-search/participant-detail?contact=true&i d=a2zt0000000TN9xAAG&status=Active Data Processing We have entered into a data processing agreement (DPA) for the use of the above service. This agreement is required under data protection law and ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.

8. E-Commerce and Payment Providers Processing Customer and Contract Data

We collect, process and use personal customer and contract data for the purpose of establishing, structuring and amending our contractual relationships. We collect, process and use personal data concerning the use of this website (usage data) only insofar as this is necessary to enable the user to use the service or to bill the user. The legal basis is Article 6(1)(b) GDPR. The collected customer data is erased after completion of the order or termination of the business relationship and expiry of any applicable statutory retention periods. Statutory retention periods remain unaffected. Payment Services

We integrate payment services provided by third-party companies into our website. If you make a purchase from us, your payment data (e.g. name, payment amount, bank account details, credit card number) is processed by the payment service provider for the purpose of processing the payment. The respective contractual and privacy provisions of the relevant provider apply to these transactions. Payment service providers are used on the basis of Article 6(1)(b) GDPR (contract performance) and in the interest of a payment process that is as smooth, convenient and secure as possible (Article 6(1)(f) GDPR). Where your consent is requested for specific actions, Article 6(1)(a) GDPR is the legal basis for the data processing; consent may be withdrawn at any time with effect for the future. We use the following payment services/payment service providers in connection with this website: PayPal The provider of this payment service is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”). Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full. Details can be found in PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full. Apple Pay The provider of this payment service is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. Apple’s privacy policy can be found at: https://www.apple.com/legal/privacy/de-ww/. Google Pay The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google’s privacy policy can be found at: https://policies.google.com/privacy. Stripe

For customers within the EU, the provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter “Stripe”). Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://stripe.com/de/privacy and https://stripe.com/de/guides/general-data-protection-regulation. Further details can be found in Stripe’s privacy policy at: https://stripe.com/de/privacy. Klarna The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter “Klarna”). Klarna offers various payment options (e.g. payment by instalments). If you choose to pay using Klarna (Klarna Checkout solution), Klarna will collect various personal data from you. Klarna uses cookies to optimise the use of the Klarna Checkout solution. Details on the use of Klarna cookies can be found at: https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf. Further details can be found in Klarna’s privacy policy at: https://www.klarna.com/de/datenschutz/. Paydirekt The provider of this payment service is Paydirekt GmbH, Hamburger Allee 26-28, 60486 Frankfurt am Main, Germany (hereinafter “Paydirekt”). If you make a payment using Paydirekt, Paydirekt collects various transaction data and forwards it to the bank with which you are registered for Paydirekt. In addition to the data required for the payment, Paydirekt may collect further data in connection with processing the transaction, such as a delivery address or individual items in the shopping basket. Paydirekt then authenticates the transaction using the authentication procedure stored with the relevant bank. The payment amount is subsequently transferred from your account to our account. Neither we nor third parties have access to your account details. Details on payments using Paydirekt can be found in Paydirekt’s Terms and Conditions and privacy provisions at: https://www.paydirekt.de/agb/index.html.

Sofort Bank Transfer The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich, Germany (hereinafter “Sofort GmbH”). The “Sofortüberweisung” procedure enables us to receive real-time confirmation of payment from Sofort GmbH and to commence performance of our obligations without delay. If you select “Sofortüberweisung” as the payment method, you transmit your PIN and a valid TAN to Sofort GmbH, enabling it to sign in to your online banking account. After signing in, Sofort GmbH automatically checks your account balance and executes the transfer to us using the TAN you have transmitted. It then sends us immediate confirmation of the transaction. After sign-in, your account transactions, overdraft credit limit, existence of other accounts and their balances are also checked automatically. In addition to the PIN and TAN, the payment data entered by you and personal data concerning you are transmitted to Sofort GmbH. The personal data comprises your first and last name, address, telephone number(s), email address, IP address and, where applicable, other data required to process the payment. Transmission of this data is necessary to establish your identity unequivocally and prevent attempted fraud. Details on payments using Sofortüberweisung can be found at: https://www.klarna.com/sofort/. Amazon Pay The provider of this payment service is Amazon Payments Europe S.C.A., 38 avenue J.F. Kennedy, L-1855 Luxembourg. Details on the handling of your data can be found in Amazon Pay’s privacy policy at: https://pay.amazon.de/help/201212490?ld=APDELPADirect. Mollie The provider of this payment service is Mollie B.V., Keizersgracht 126, 1015CW Amsterdam, the Netherlands (hereinafter “Mollie”). Mollie enables us to integrate various payment methods into our website. Details can be found in Mollie’s privacy policy: https://www.mollie.com/de/privacy. PayOne

The provider of this payment service is PAYONE GmbH, Lyoner Straße 9, 60528 Frankfurt am Main, Germany (hereinafter “PayOne”). Details can be found in PayOne’s privacy policy: https://www.payone.com/DE-de/datenschutz. giropay The provider of this payment service is paydirekt GmbH, Stephanstraße 14-16, 60313 Frankfurt am Main, Germany (hereinafter “giropay”). Details can be found in giropay’s privacy policy: https://www.paydirekt.de/agb/index.html. American Express The provider of this payment service is American Express Europe S.A., Theodor-Heuss-Allee 112, 60486 Frankfurt am Main, Germany (hereinafter “American Express”). American Express may transfer data to its parent company in the United States. Transfers of data to the United States are based on Binding Corporate Rules. Details can be found at: https://www.americanexpress.com/en-nl/company/legal/privacy-centre/european-implementi ng-principles/. Further information can be found in American Express’s privacy policy: https://www.americanexpress.com/de/legal/online-datenschutzerklarung.html. Mastercard The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter “Mastercard”). Mastercard may transfer data to its parent company in the United States. Transfers of data to the United States are based on Mastercard’s Binding Corporate Rules. Details can be found at: https://www.mastercard.de/de-de/datenschutz.html and https://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf. VISA

The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “VISA”). The United Kingdom is regarded as a third country providing an adequate level of data protection. This means that the United Kingdom provides a level of data protection equivalent to that in the European Union. VISA may transfer data to its parent company in the United States. Transfers of data to the United States are based on the European Commission’s Standard Contractual Clauses. Details can be found at: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu- zustandigkeitsfragen-fur-den-ewr.html. Further information can be found in VISA’s privacy policy: https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html.

© 2026 acadora · a StudyTexter productImprintPrivacyTermsWithdrawal