Privacy Policy
Preamble
With the following Privacy Policy, we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) we process, for what purposes, and to what extent. This Privacy Policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as the “online offering”).
The terms used are not gender-specific.
Preamble (App)
With the following Privacy Policy, we would like to inform you about the types of your personal data we process, for what purposes, and to what extent in the context of providing our application.
The terms used are not gender-specific.
Last updated: 10 June 2026
Table of Contents
- Preamble
- Preamble (App)
- Controller
- Overview of Processing Activities
- Applicable Legal Bases
- Security Measures
- General Information on Data Storage and Deletion
- Rights of Data Subjects
- Disclosure of Data to Employers in B2B Use
- Business Services
- Business Processes and Procedures
- Provision of the Online Offering and Web Hosting
- Use of Cookies
- Processing of Data in the Context of Applications (Apps)
- Registration, Login and User Account
- Contact and Inquiry Management
- Video Conferences, Online Meetings, Webinars and Screen Sharing
- Presence on Social Networks (Social Media)
- Plug-ins and Embedded Functions and Content
- Changes and Updates
Controller
Lunchzeit LTD
Dimitri Zinieri 9
8220 Chloraka
Paphos
Republic of Cyprus
Authorised representatives: Florian Gansemer
Email address: [email protected]
Phone: +49 261 973 335 25
Legal notice: https://lunchzeit.com/de/impressum/
Overview of Processing Activities
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of Data Processed
- Master data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Images and/or video recordings.
- Audio recordings.
- Log data.
Categories of Data Subjects
- Service recipients and clients.
- Prospective customers.
- Communication partners.
- Users.
- Business and contractual partners.
- Depicted persons.
- Customers.
Purposes of Processing
- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Office and organisational procedures.
- Organisational and administrative procedures.
- Content Delivery Network (CDN).
- Feedback.
- Provision of our online offering and user-friendliness.
- IT infrastructure.
- Financial and payment management.
- Public relations.
- Business processes and commercial procedures.
Applicable Legal Bases
Applicable legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in individual cases, we will inform you of these in the Privacy Policy.
- Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject.
Applicable legal bases under the Swiss Federal Act on Data Protection (FADP): If you are located in Switzerland, we process your data on the basis of the Swiss Federal Act on Data Protection (FADP). Unlike the GDPR, the FADP generally does not require a legal basis to be cited for the processing of personal data, provided that the processing is carried out in good faith, is lawful and proportionate (Art. 6(1) and (2) FADP). Personal data is collected by us only for a specific purpose recognisable to the data subject and is only processed in a manner compatible with that purpose (Art. 6(3) FADP).
Note on the applicability of the GDPR and the Swiss FADP: These data protection notices serve both for information purposes under the Swiss FADP and under the General Data Protection Regulation (GDPR). For reasons of broader geographical applicability and clarity, we use the terminology of the GDPR. In particular, instead of the terms used in the Swiss FADP such as “processing” of “personal data”, “overriding interest” and “particularly sensitive personal data”, the GDPR terms “processing” of “personal data”, “legitimate interest” and “special categories of data” are used. However, the legal meaning of the terms continues to be determined in accordance with the Swiss FADP where it applies.
Security Measures
We take appropriate technical and organisational measures in accordance with the legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, in order to ensure a level of security appropriate to the risk.
These measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to data as well as access, input, disclosure, security of availability and separation of data. We have also established procedures to ensure the exercise of data subjects’ rights, the deletion of data and responses to data threats. Furthermore, we take the protection of personal data into account in the development or selection of hardware, software and procedures in accordance with the principle of privacy by design and privacy by default.
IP address truncation: Where IP addresses are processed by us or by the service providers and technologies we use, and where processing a complete IP address is not necessary, the IP address is truncated (also referred to as “IP masking”). In this process, the last two digits or the last part of the IP address after a dot are removed or replaced by placeholders. Truncating the IP address is intended to prevent or significantly hinder the identification of a person based on their IP address.
Securing online connections via TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL, serving as an indicator to users that their data is being transmitted securely and in encrypted form.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with statutory requirements as soon as the underlying consents are revoked or no further legal bases for processing exist. This applies to cases in which the original processing purpose ceases to apply or the data is no longer needed. Exceptions to this rule apply where statutory obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and deletion of data that applies specifically to certain processing activities.
Where multiple retention periods or deletion deadlines are specified for a given piece of data, the longest period always applies. Data that is no longer retained for its original purpose but for statutory or other reasons is processed exclusively for the reasons justifying its retention.
Retention and deletion of data: The following general deadlines apply for retention and archiving under Swiss law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, accounting documents and invoices, as well as all necessary work instructions and other organisational documents (Art. 958f of the Swiss Code of Obligations (CO)).
- 10 years – Data necessary to account for potential compensation claims or similar contractual claims and rights, as well as for dealing with related inquiries, based on past business experience and standard industry practices, is stored for the duration of the statutory limitation period of ten years, unless a shorter period of five years applies in certain cases (Art. 127, 130 CO). Claims for rent, interest and other periodic obligations, for the delivery of food, for board and lodging, and those arising from craftsmanship, retail sales, medical care, professional services of lawyers, agents, notaries, and from employment relationships, become time-barred after five years (Art. 128 CO).
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw consent given at any time.
- Right of access: You have the right to request confirmation as to whether personal data concerning you is being processed, and to obtain access to that data and to further information and a copy of the data, in accordance with statutory requirements.
- Right to rectification: You have the right, in accordance with statutory requirements, to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right, in accordance with statutory requirements, to request that data concerning you be erased without undue delay, or alternatively, to request restriction of processing of the data in accordance with statutory requirements.
- Right to data portability: You have the right to receive the data concerning you that you have provided to us, in a structured, commonly used and machine-readable format, or to request its transmission to another controller, in accordance with statutory requirements.
- Right to lodge a complaint with a supervisory authority: In accordance with statutory requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes the GDPR.
Rights of data subjects under the Swiss FADP:
As a data subject under the Swiss FADP, you have the following rights:
- Right of access: You have the right to request confirmation as to whether personal data concerning you is being processed, and to receive the information necessary for you to exercise your rights under this Act and to ensure transparent data processing.
- Right to data portability: You have the right to request the delivery of personal data you have provided to us in a commonly used electronic format.
- Right to rectification: You have the right to request the rectification of inaccurate personal data concerning you.
- Right to object, erasure and destruction: You have the right to object to the processing of your data, and to request that personal data concerning you be erased or destroyed.
Disclosure of Data to Employers in B2B Use
Lunchzeit is used within the framework of corporate contracts whereby the respective employer (hereinafter “corporate customer”) provides our platform for their employees. Administrators of the corporate customer have access to the following data via the administration interface:
- User management: A list of the company’s registered users (name, email address or comparable identification data), for the purpose of account management, e.g. creating or deleting user accounts.
- Master data: Profile data entered by the user themselves, such as department affiliation and interests.
- Aggregated statistics: Anonymised evaluations at company level, e.g. total number of active users or number of lottery participants per month. These statistics do not allow any conclusions to be drawn about individual persons.
Purpose: The disclosure of data serves the management of the corporate account and the provision of usage overviews for the corporate customer.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interests of the corporate customer in account management).
Note on responsibility: The corporate customer is independently responsible as controller under data protection law with regard to its use of the data made available to it. Users may contact their employer directly regarding any data protection concerns relating to the processing carried out by the corporate customer.
Business Services
We process personal data of our contractual and business partners, such as customers, clients, prospects, suppliers and other cooperation partners (collectively “contractual partners”), for the purpose of initiating, performing and completing contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken at the request of the contractual partner, as well as communication in connection with the respective contractual relationship.
The processing serves in particular to fulfil our primary and ancillary contractual obligations. These include the provision of agreed services, any update and information obligations, the handling of warranty and other service disruptions, the processing of withdrawals, cancellations of ongoing obligations, reversal transactions, reimbursements, and the handling of other contract-related declarations and inquiries. Both one-time contracts and ongoing contractual relationships are covered.
Data processed includes in particular master data such as name, address and, where applicable, company name, contact data such as email address and telephone number, contract and service data such as contract subject matter, contract term, order or transaction number, usage and service data, payment and billing data, as well as communication content and histories. Where necessary, we also process data disclosed or transmitted to us in the course of executing an order.
We also process data to protect our rights and to fulfil statutory obligations. This includes in particular commercial and tax law retention obligations, documentation obligations, and where applicable, obligations to provide evidence and accountability. In addition, processing is carried out on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and contractual partners against misuse, endangerment of data, trade secrets and other legal interests. This may include the involvement of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax advisors, legal advisors or other subcontractors, to the extent necessary for the performance of the contract or to fulfil statutory obligations.
Personal data is only disclosed to third parties to the extent necessary for the fulfilment of the contract, the implementation of pre-contractual measures, the pursuit of legitimate interests or the fulfilment of statutory obligations. We provide separate information on any further processing, in particular for marketing purposes, within this Privacy Policy.
We will inform contractual partners of the specific data required in each case at the time of data collection, e.g. through appropriate labelling in online forms or through personal contact.
Data is deleted once it is no longer required for the aforementioned purposes and no statutory retention obligations apply. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the context of a specific order is deleted after completion of the order and expiry of any applicable retention periods, provided no further statutory or contractual obligations require storage.
The legal basis for processing is Art. 6(1)(b) GDPR for the implementation of pre-contractual measures and for the performance of the respective contractual relationship, as well as Art. 6(1)(c) GDPR for compliance with statutory obligations. Where processing is based on legitimate interests, it is carried out on the basis of Art. 6(1)(f) GDPR for the pursuit of our legitimate interests in proper and efficient business organisation, internal administration, documentation of business transactions, the assertion and defence of legal claims, ensuring IT and data security, preventing misuse and fraud, as well as the financial management and development of our business operations.
- Types of data processed: Master data (e.g. full name, home address, contact details, customer number); Payment data (e.g. bank details, invoices, payment history); Contact data (e.g. postal and email addresses or telephone numbers). Contract data (e.g. contract subject, term, customer category).
- Data subjects: Service recipients and clients; Prospective customers. Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; Communication; Office and organisational procedures; Organisational and administrative procedures. Business processes and commercial procedures.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legal obligation (Art. 6(1)(c) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
- Provision of software and platforms: We process the data of our customers and users (hereinafter collectively referred to as “users”) in order to provide them with our contractual services and, on the basis of legitimate interests, to ensure the security of our offering and to further develop it. The required information is identified as such in the context of the order, purchase or comparable contractual conclusion, and includes the information required for service provision and billing as well as contact information for any follow-up queries; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legal obligation (Art. 6(1)(c) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
Business Processes and Procedures
Personal data of service recipients and clients – including customers, clients or, in specific cases, clients of professional services, patients or business partners, as well as other third parties – is processed within the framework of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates business operations in areas such as customer management, sales, payment processing, accounting and project management.
The data collected serves to fulfil contractual obligations and to organise business processes efficiently. This includes the processing of business transactions, the management of customer relationships, the optimisation of sales strategies, and ensuring internal billing and financial processes. In addition, the data supports the protection of the controller’s rights and promotes administrative tasks and the organisation of the company.
Personal data may be disclosed to third parties where necessary to fulfil the aforementioned purposes or statutory obligations. Data is deleted once statutory retention periods have expired or the purpose of processing has ceased. This also includes data that must be retained for longer periods due to tax and statutory documentation obligations.
- Types of data processed: Master data; Payment data; Contact data; Content data; Contract data; Usage data; Meta, communication and procedural data. Log data.
- Data subjects: Service recipients and clients; Prospective customers; Communication partners; Business and contractual partners. Customers.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; Office and organisational procedures; Business processes and commercial procedures; Security measures; Provision of our online offering and user-friendliness; Financial and payment management. Communication.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR); Legitimate interests (Art. 6(1)(f) GDPR). Legal obligation (Art. 6(1)(c) GDPR).
Further information on processing activities, procedures and services:
- Customer management and CRM: Procedures required in the context of customer management and Customer Relationship Management (CRM), e.g. customer acquisition in compliance with data protection requirements, measures to promote customer retention and loyalty, effective customer communication, complaints management and customer service with consideration for data protection, data management and analysis to support customer relationships, management of CRM systems, secure account management, customer segmentation and target group formation; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- Customer account: Customers may create an account within our online offering (e.g. a customer or user account). Where registration of a customer account is required, customers are informed of this as well as of the details required for registration. Customer accounts are not public and cannot be indexed by search engines. During registration and subsequent logins and use of the customer account, we store the IP addresses of customers together with the access times, in order to verify registration and to prevent misuse of the customer account. If the customer account is cancelled, the data of the customer account will be deleted after the time of cancellation, unless it is retained for purposes other than provision via the customer account, or must be retained for legal reasons (e.g. internal storage of customer data, orders or invoices). It is the responsibility of customers to back up their data upon cancellation of their customer account; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- Accounting, accounts payable and accounts receivable: Procedures required for the recording, processing and control of business transactions in the area of accounts payable and accounts receivable (e.g. creating and reviewing incoming and outgoing invoices, monitoring and managing open items, processing payment transactions, handling dunning procedures, account reconciliation in the context of receivables and liabilities); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legal obligation (Art. 6(1)(c) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
- Financial accounting and taxes: Procedures required for the recording, management and control of financially relevant business transactions, as well as the calculation, reporting and payment of taxes (e.g. posting of business transactions, preparation of quarterly and annual financial statements, processing of payment transactions, handling of dunning procedures, account reconciliation, tax advice, preparation and submission of tax returns); Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legal obligation (Art. 6(1)(c) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
Provision of the Online Offering and Web Hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or end device.
- Types of data processed: Usage data; Meta, communication and procedural data; Log data. Content data.
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness; IT infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)); Security measures. Content Delivery Network (CDN).
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
- Provision of the online offering on own/dedicated server hardware: We use server hardware operated by us, together with the associated storage space, computing capacity and software, for the provision of our online offering; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
- Collection of access data and log files: Access to our online offering is logged in the form of so-called “server log files”. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, a notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used for security purposes, e.g. to avoid server overload (especially in the event of abusive attacks, so-called DDoS attacks), and to ensure server utilisation and stability; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Deletion of data: Log file information is stored for a maximum period of 30 days and then deleted or anonymised. Data whose further retention is necessary for evidentiary purposes is exempt from deletion until the final clarification of the respective incident.
- Email sending and hosting: The web hosting services we use also include the sending, receiving and storing of emails. For these purposes, the addresses of recipients and senders, as well as further information concerning the email sending process (e.g. the providers involved) and the content of the respective emails, are processed. The aforementioned data may also be processed for the purpose of detecting spam. Please note that emails on the internet are generally not sent in encrypted form. Emails are typically encrypted during transmission, but (unless an end-to-end encryption method is used) not on the servers from which they are sent and received. We therefore cannot assume any responsibility for the transmission path of emails between the sender and the receipt at our server; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
- Content Delivery Network: We use a Content Delivery Network (CDN). A CDN is a service by means of which content of an online offering, in particular large media files such as graphics or programme scripts, can be delivered faster and more securely with the help of regionally distributed and internet-connected servers; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
- Hetzner: Services in the field of provision of IT infrastructure and related services (e.g. storage space and/or computing capacity); Service provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.hetzner.com; Privacy Policy: https://docs.hetzner.com/de/general/company-and-policy/data-protection-at-hetzner. Data Processing Agreement: https://docs.hetzner.com/de/general/company-and-policy/data-protection-at-hetzner.
- Cloudflare: Content Delivery Network (CDN); Service provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.cloudflare.com; Privacy Policy: https://www.cloudflare.com/privacypolicy/; Data Processing Agreement: https://www.cloudflare.com/cloudflare-customer-dpa/. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.cloudflare.com/cloudflare-customer-scc/), Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses.
Use of Cookies
The term “cookies” refers to functions that store and retrieve information on users’ end devices. Cookies may be used for various purposes, such as for the functionality, security and convenience of online offerings and for the analysis of visitor traffic. We use cookies in accordance with statutory requirements. Where required, we obtain users’ prior consent. Where consent is not required, we rely on our legitimate interests. This applies where the storage and retrieval of information is essential in order to provide the content and functions expressly requested. This includes, for example, the storage of settings and ensuring the functionality and security of our online offering. Consent may be withdrawn at any time. We provide clear information about the scope of consent and the cookies used.
Notes on legal bases: Whether we process personal data using cookies depends on whether consent has been obtained. Where consent exists, it serves as the legal basis. Without consent, we rely on our legitimate interests as described above in this section and in the context of the respective services and procedures.
Storage period: The following types of cookies are distinguished with regard to storage period:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest when a user leaves an online offering and closes their end device (e.g. browser or mobile application).
- Permanent cookies: Permanent cookies remain stored even after the end device is closed. For example, the login status can be stored and preferred content can be displayed directly when the user revisits a website. Likewise, usage data collected with the help of cookies can be used for reach measurement. Unless we provide users with explicit information on the type and duration of cookies (e.g. when obtaining consent), users should assume that cookies are permanent and that the storage period may be up to two years.
General information on withdrawal and objection (opt-out): Users may withdraw consents they have given at any time and may also object to processing in accordance with statutory requirements, including by means of the privacy settings of their browser.
- Types of data processed: Meta, communication and procedural data (e.g. IP addresses, time details, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Consent (Art. 6(1)(a) GDPR).
Further information on processing activities, procedures and services:
- Processing of cookie data on the basis of consent: We use a consent management solution by means of which users’ consent to the use of cookies, or to the procedures and providers mentioned in the consent management solution, is obtained. This procedure serves to obtain, log, manage and withdraw consent, in particular with regard to the use of cookies and comparable technologies used to store, read and process information on users’ end devices. Within this procedure, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers mentioned in the consent management procedure. Users also have the option to manage and withdraw their consent. Consent declarations are stored in order to avoid repeated requests and to provide evidence of consent in accordance with statutory requirements. Storage is carried out server-side and/or in a cookie (so-called opt-in cookie) or by means of comparable technologies, in order to be able to assign consent to a specific user or their device. Unless specific information is available on the providers of consent management services, the following general information applies: The duration of storage of consent is up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, the scope of consent (e.g. categories of cookies and/or service providers concerned) and information about the browser, system and end device used; Legal bases: Consent (Art. 6(1)(a) GDPR).
- Cookiebot: Storage and management of consents (agreement to cookies and data processing), logging of user decisions, display of notices on data protection and cookies, enabling users to withdraw or adjust their consents; Service provider: Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark; Website: https://www.cookiebot.com/en; Privacy Policy: https://www.cookiebot.com/en/privacy-policy/; Data Processing Agreement: Provided by the service provider; Further information: Data stored (on the service provider’s server): The user’s IP number in anonymised form (the last three digits are set to 0), date and time of consent, browser details, the URL from which consent was sent, an anonymous, random and encrypted key value, the user’s consent status.
Processing of Data in the Context of Applications (Apps)
We process the data of users of our application to the extent necessary to provide users with the application and its functionalities, to monitor its security, and to further develop it. We may also contact users in compliance with statutory requirements where communication is necessary for the purposes of administering or using the application. In all other respects, with regard to the processing of user data, we refer to the privacy notices in this Privacy Policy.
Legal bases: The processing of data necessary for providing the functionalities of the application serves to fulfil contractual obligations. This also applies where providing the functions requires authorisation from users (e.g. granting device permissions). Where the processing of data is not necessary for providing the functionalities of the application but serves the security of the application or our commercial interests (e.g. collection of data for optimisation or security purposes), it is carried out on the basis of our legitimate interests. Where users are expressly asked for their consent to the processing of their data, processing of the data covered by the consent is carried out on the basis of that consent.
- Types of data processed: Master data; Usage data; Meta, communication and procedural data; Payment data. Contract data.
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; Security measures. Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
- Commercial use: We process the data of users of our application, registered users and any trial users (hereinafter collectively referred to as “users”) in order to provide them with our contractual services and, on the basis of legitimate interests, to ensure the security of our application and to further develop it. The required information is identified as such in the context of the use, order, purchase or comparable contractual conclusion, and may include the information required for the provision of services and any billing, as well as contact information for any follow-up queries; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
- Storage of a universally unique identifier (UUID): For the purposes of analysing the use and functionality of the application and storing user settings, the application stores a so-called universally unique identifier (UUID). This identifier is generated at the time of installation (but is not linked to the device and is therefore not a device identifier in this sense), remains stored between application launches and updates, and is deleted when users remove the application from their device.
- No location history or movement profiles: Location data is only used on a point-in-time basis and is not processed to create a location history or movement profile of the devices used or their users.
Registration, Login and User Account
Users may create a user account. During registration, users are informed of the required mandatory details, which are processed for the purpose of providing the user account on the basis of contractual performance. The data processed includes in particular login information (username, password and an email address).
In the context of the use of our registration and login functions and the use of the user account, we store the IP address and the time of each user action. Storage is carried out on the basis of our legitimate interests, as well as those of users, in protection against misuse and other unauthorised use. In principle, this data is not disclosed to third parties, unless it is necessary to pursue our claims or there is a statutory obligation to do so.
Users may be notified by email of events relevant to their user account, such as technical changes.
- Types of data processed: Master data; Contact data; Content data; Usage data. Log data.
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; Security measures; Organisational and administrative procedures. Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”. Deletion upon cancellation.
- Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
- Registration under real name: Due to the nature of our community, we ask users to use our offering only under their real name. The use of pseudonyms is not permitted; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
- User profiles are not public: User profiles are not publicly visible or accessible.
- Two-factor authentication: Two-factor authentication provides an additional layer of security for your user account and ensures that only you can access your account, even if someone else knows your password. For this purpose, in addition to your password, you are required to perform a further authentication step (e.g. entering a code sent to a mobile device). We will inform you of the procedure used; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
- Deletion of data upon cancellation: If users have cancelled their user account, their data relating to the user account will be deleted, subject to any statutory permission, obligation or consent of the user; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Contact and Inquiry Management
When contacting us (e.g. by post, contact form, email, telephone or via social media) and in the context of existing user and business relationships, we process the personal data of the persons making inquiries to the extent necessary to respond to the contact inquiries and any measures requested.
- Types of data processed: Contact data; Content data. Meta, communication and procedural data.
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; Organisational and administrative procedures; Feedback (e.g. collecting feedback via online form). Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR).
Further information on processing activities, procedures and services:
- Contact form: When users contact us via our contact form, email or other communication channels, we process the personal data transmitted to us in order to respond to and handle the respective enquiry. This generally includes details such as name, contact information and, where applicable, further information provided to us and required for appropriate handling. We use this data exclusively for the stated purpose of the contact and communication; Legal bases: Performance of a contract and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
Video Conferences, Online Meetings, Webinars and Screen Sharing
We use platforms and applications of third-party providers (hereinafter referred to as “conference platforms”) for the purpose of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as “conference”). In selecting conference platforms and their services, we comply with statutory requirements.
Data processed by conference platforms: In the context of participation in a conference, conference platforms process the personal data of participants listed below. The scope of processing depends in part on the data required in the context of a specific conference (e.g. provision of access data or real name) and on any optional information provided by participants. In addition to processing for the purposes of conducting the conference, participants’ data may also be processed by conference platforms for security purposes or service optimisation. Data processed includes personal data (first name, last name), contact information (email address, telephone number), access data (access codes or passwords), profile pictures, details of professional status/function, the IP address of internet access, details of participants’ end devices, their operating system, browser and its technical and language settings, information on the content of communication processes, i.e. entries in chats as well as audio and video data, and the use of other available functions (e.g. surveys). Communications content is encrypted to the technical extent provided by the conference provider. If participants are registered as users with the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.
Logging and recordings: Where text entries, participation results (e.g. from surveys) or video or audio recordings are logged, participants are informed of this in advance and, where required, asked for their consent.
Data protection measures for participants: Please refer to the privacy notices of the conference platforms for details of how your data is processed by them, and select the optimal security and privacy settings available within the conference platform settings. Please also ensure data protection and privacy in the background of your recording during a video conference (e.g. by informing other household members, closing doors, and using, where technically possible, the function to blur the background). Links to conference rooms and access data must not be shared with unauthorised third parties.
Notes on legal bases: Where, in addition to the conference platforms, we also process users’ data and ask users for their consent to the use of conference platforms or certain functions (e.g. consent to the recording of conferences), the legal basis for processing is that consent. Furthermore, our processing may be necessary to fulfil our contractual obligations (e.g. in participant lists, in the event of documenting meeting results, etc.). In all other respects, users’ data is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.
- Types of data processed: Master data; Contact data; Content data; Usage data; Images and/or video recordings; Audio recordings. Log data.
- Data subjects: Communication partners; Users. Depicted persons.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; Communication. Office and organisational procedures.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
- Google Meet: Video conferences and online meetings with audio and video transmission, screen sharing, chat messages, appointment and participant management, and dial-in via link or browser. Storage and transmission of connection, usage and communication data for the provision of the services; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://meet.google.com/; Privacy Policy: https://business.safety.google/privacy/; Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses.
- Microsoft Teams: Used for conducting online events, conferences and communication with internal and external participants; Service provider: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.microsoft.com/en-us/microsoft-teams/; Privacy Policy: https://www.microsoft.com/en-us/privacy/privacystatement. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses, Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses.
- Whereby: Video conferences, web conferences and webinars; Service provider: Video Communication Services AS, Gate 1 no. 101, 6700 Måløy, Norway; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://whereby.com/; Privacy Policy: https://whereby.com/information/tos/privacy-policy/. Basis for third-country transfers: EU/EEA – Standard Contractual Clauses, Switzerland – Standard Contractual Clauses.
- Zoom: Video conferences, online meetings, webinars, screen sharing, optional session recording, chat function, integration with calendars and other apps; Service provider: Zoom Video Communications, Inc., 55 Almaden Blvd., Suite 600, San Jose, CA 95113, USA; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.zoom.com; Privacy Policy: https://www.zoom.com/en/trust/privacy/privacy-statement/; Data Processing Agreement: https://media.zoom.com/download/assets/zoom-global-dpa.pdf. Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses, Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses.
Presence on Social Networks (Social Media)
We maintain online presences within social networks and process users’ data in this context in order to communicate with users active there or to provide information about us.
We draw attention to the fact that user data may be processed outside the territory of the European Union. This may give rise to risks for users, for example because the enforcement of users’ rights could be made more difficult as a result.
Furthermore, users’ data within social networks is generally processed for market research and advertising purposes. For example, usage profiles may be created based on users’ usage behaviour and the resulting interests. These profiles may in turn be used to place advertisements inside and outside the networks that are presumed to correspond to users’ interests. For this purpose, cookies are generally stored on users’ computers, in which usage behaviour and interests are saved. Moreover, data may also be stored in the usage profiles independently of the devices used by users (particularly where users are members of the respective platforms and are logged in there).
For a detailed description of the respective processing activities and opt-out options, we refer to the privacy policies and information provided by the operators of the respective networks.
In the case of requests for information and the assertion of data subject rights, we would also like to point out that these can be exercised most effectively with the providers. Only the providers have access to users’ data and can take appropriate measures and provide information directly. If you nevertheless require assistance, please feel free to contact us.
- Types of data processed: Contact data; Content data. Usage data.
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Communication; Feedback. Public relations.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”.
- Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
- LinkedIn: Social network – We are jointly responsible with LinkedIn Ireland Unlimited Company for the collection (but not the further processing) of visitor data used to create “Page Insights” (statistics) for our LinkedIn profiles. This data includes information about the types of content that users view or interact with, and actions taken by them, as well as details about the devices used, such as IP addresses, operating system, browser type, language settings and cookie data, as well as information from user profiles such as professional function, country, industry, seniority level, company size and employment status. Privacy information on the processing of user data by LinkedIn can be found in LinkedIn’s privacy notices: https://www.linkedin.com/legal/privacy-policy.
We have concluded a specific agreement with LinkedIn Ireland (“Page Insights Joint Controller Addendum”, https://legal.linkedin.com/pages-joint-controller-addendum), which in particular governs the security measures LinkedIn must observe and in which LinkedIn has agreed to fulfil data subjects’ rights (i.e. users may, for example, send access or deletion requests directly to LinkedIn). The rights of users (in particular the right to access, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint responsibility is limited to the collection of data and its transmission to LinkedIn Ireland Unlimited Company, a company based in the EU. Further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, in particular regarding the transmission of data to the parent company LinkedIn Corporation in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for third-country transfers: EU/EEA – Data Privacy Framework (DPF), Standard Contractual Clauses, Switzerland – Data Privacy Framework (DPF), Standard Contractual Clauses. Opt-out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. - Xing: Social network; Service provider: New Work SE, Am Strandkai 1, 20457 Hamburg, Germany; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://www.xing.com/. Privacy Policy: https://privacy.xing.com/en/privacy-policy.
Plug-ins and Embedded Functions and Content
We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos or maps (hereinafter collectively referred to as “content”).
The integration always requires that the third-party providers of this content process the IP addresses of users, since without an IP address they would not be able to send the content to the user’s browser. The IP address is therefore required for the display of this content or these functions. We endeavour to use only such content whose respective providers use the IP address solely for the delivery of content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. The “pixel tags” can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and other details about the use of our online offering, and may also be linked to such information from other sources.
Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is that consent. Otherwise, users’ data is processed on the basis of our legitimate interests (i.e. an interest in efficient, economical and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this Privacy Policy.
- Types of data processed: Usage data. Meta, communication and procedural data.
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online offering and user-friendliness.
- Retention and deletion: Deletion in accordance with the information in the section “General Information on Data Storage and Deletion”. Storage of cookies for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of up to two years).
- Legal bases: Consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).
Further information on processing activities, procedures and services:
- Google Fonts (hosted on own server): Provision of font files for the purpose of a user-friendly presentation of our online offering; Service provider: Google Fonts are hosted on our own server; no data is transmitted to Google; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Changes and Updates
We ask you to regularly inform yourself about the content of our Privacy Policy. We update the Privacy Policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require your participation (e.g. consent) or another individual notification.
Where we provide addresses and contact details of companies and organisations in this Privacy Policy, please note that addresses may change over time and we ask you to verify the details before making contact.