1. Home
  2. Privacy Policy

Privacy Policy

Privacy Policy

Table of Contents

  • Introduction and Overview
  • Scope of Application
  • Legal Basis
  • Contact information for the data controller
  • Retention period
  • Rights under the General Data Protection Regulation
  • Data Processing Security
  • Communication
  • Cookies
  • Website Builder Systems: Introduction
  • Blogs and Publications Introduction
  • Cookie Consent Management Platform Introduction
  • Security & Anti-Spam
  • Web Design Introduction
  • Closing Remarks

Introduction and Overview

We have prepared this Privacy Policy (Version 02/14/2026-313105770) to provide you with information in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (hereinafter “data”) we, as the data controller—and the processors we have commissioned (e.g., service providers)—process, will process in the future, and what legal options you have. The terms used are to be understood as gender-neutral.
In short: We provide you with comprehensive information about the data we process regarding you.

Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, is designed to explain the most important points to you as simply and transparently as possible. Where it helps with transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and graphics . We use clear and simple language to inform you that, in the course of our business activities, we process personal data only when there is a corresponding legal basis for doing so. This certainly isn’t possible if we provide explanations that are as brief, unclear, and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps there is some information here that you were not yet aware of.
If you still have questions, please contact the responsible party listed below or in the legal notice, follow the provided links, and review additional information on third-party websites. You can, of course, also find our contact information in the legal notice.

Scope of Application

This Privacy Policy applies to all personal data processed by us within the company and to all personal data processed by companies we have commissioned (processors). By “personal data,” we mean information as defined in Article 4(1) of the GDPR, such as a person’s name, email address, and mailing address. The processing of personal data enables us to offer and bill for our services and products, whether online or offline. The scope of this Privacy Policy includes:

  • all online platforms (websites, online stores) that we operate
  • Social media presence and email communication
  • mobile apps for smartphones and other devices

In short: This Privacy Policy applies to all areas within the company where personal data is processed in a structured manner via the channels mentioned. Should we enter into a legal relationship with you outside of these channels, we will inform you separately if necessary.

Legal Basis

In the following privacy policy, we provide you with transparent information regarding the legal principles and regulations—that is, the legal basis under the General Data Protection Regulation—that allow us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of April 27, 2016. You can, of course, access this EU General Data Protection Regulation online at EUR-Lex, the portal for EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679 .

We process your data only if at least one of the following conditions applies:

  1. Consent (Article 6(1)(a) of the GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
  2. Contract (Article 6(1)(b) of the GDPR): We process your data to fulfill a contract or pre-contractual obligations with you. For example, if we enter into a purchase agreement with you, we need personal information in advance.
  3. Legal obligation (Article 6(1)(c) of the GDPR): We process your data when we are subject to a legal obligation. For example, we are legally required to retain invoices for accounting purposes. These typically contain personal data.
  4. Legitimate Interests (Article 6(1)(f) of the GDPR): In cases where legitimate interests do not restrict your fundamental rights, we reserve the right to process personal data. For example, we must process certain data in order to operate our website securely and economically efficiently. This processing therefore constitutes a legitimate interest.

Other conditions, such as the processing of data in the public interest, the exercise of official authority, or the protection of vital interests, do not generally apply to us. However, if such a legal basis were to apply, it will be indicated in the relevant section.

In addition to the EU regulation, national laws also apply:

  • In Austria this is the Federal Act on the Protection of Individuals with Regard to the Processing of Personal Data (Data Protection Act), or DSG.
  • In Germany the Federal Data Protection Act, or BDSG.

If additional regional or national laws apply, we will provide you with information about them in the following sections.

Contact information for the data controller

If you have any questions regarding data protection or the processing of personal data, please find below the contact details of the data controller as specified in Article 4(7) of the EU General Data Protection Regulation (GDPR):
Professional Association for Meditation through Dance – Sacred Dance Heidelberg e.V.

Email: info@sacreddancecommunity.com
Phone: 0049-1727117231
Legal Notice: sacreddancecommunity.com/impressum/

Retention period

It is our general policy to retain personal data only for as long as is strictly necessary to provide our services and products. This means that we delete personal data as soon as the reason for processing it no longer exists. In some cases, we are legally required to retain certain data even after the original purpose has ceased to exist, for example, for accounting purposes.

If you wish to have your data deleted or withdraw your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.

We will provide you with information below regarding the specific duration of each data processing activity, provided we have further details on this matter.

Rights under the General Data Protection Regulation

In accordance with Articles 13 and 14 of the GDPR, we are informing you of the following rights to which you are entitled to ensure that your data is processed fairly and transparently:

  • Under Article 15 of the GDPR, you have the right to request information about whether we process your data. If this is the case, you have the right to receive a copy of the data and to be informed of the following:
    • for what purpose we process the data;
    • the categories, i.e., the types of data that are processed;
    • who receives this data, and if the data is transferred to third countries, how security can be ensured;
    • how long the data is stored;
    • the existence of the right to rectification, erasure, or restriction of processing, and the right to object to processing;
    • that you can file a complaint with a supervisory authority (links to these authorities are provided below);
    • the source of the data, if we did not collect it from you;
    • whether profiling is carried out—that is, whether data is automatically analyzed to create a personal profile of you.
  • Under Article 16 of the GDPR, you have the right to have your data corrected, which means that we must correct any errors you find.
  • Under Article 17 of the GDPR, you have the right to erasure (“right to be forgotten”), which specifically means that you may request the erasure of your data.
  • Under Article 18 of the GDPR, you have the right to restrict processing, which means that we may only store the data but may not use it further.
  • Under Article 20 of the GDPR, you have the right to data portability, which means that, upon request, we will provide you with your data in a commonly used format.
  • Under Article 21 of the GDPR, you have the right to object, which, once exercised, will result in a change to the processing.
    • If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interests), you may object to the processing. We will then review your objection as soon as possible to determine whether we can legally comply with it.
    • If your data is used for direct marketing purposes, you may object to this type of data processing at any time. We will then no longer be permitted to use your data for direct marketing.
    • If your data is used for profiling, you may object to this type of data processing at any time. We will no longer be permitted to use your data for profiling after that.
  • Under Article 22 of the GDPR, you may have the right not to be subject to a decision based solely on automated processing (such as profiling).
  • Under Article 77 of the GDPR, you have the right to lodge a complaint. This means that you may lodge a complaint with the data protection authority at any time if you believe that the processing of personal data violates the GDPR.

In short: You have rights—don’t hesitate to contact the responsible party listed above!

If you believe that the processing of your data violates data protection laws or that your data protection rights have been infringed in any other way, you may file a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/ . In Germany, there is a data protection officer for each federal state. For further information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) . The following local data protection authority is responsible for our company:

Bavarian Data Protection Authority

State Commissioner for Data Protection: Prof. Dr. Thomas Petri
Address: Wagmüllerstr. 18, 80538 Munich
Phone: 089/21 26 72-0
Email address: poststelle@datenschutz-bayern.de
Website: https://www.datenschutz-bayern.de/

Data Processing Security

To protect personal data, we have implemented both technical and organizational measures. Whenever possible, we encrypt or pseudonymize personal data. In this way, we do everything in our power to make it as difficult as possible for third parties to infer personal information from our data.

Article 25 of the GDPR refers to “data protection through technology design and privacy-friendly default settings,” meaning that security must always be a priority—whether in software (e.g., forms) or hardware (e.g., access to the server room)—and appropriate measures must be implemented. Below, we will discuss specific measures where necessary.

TLS encryption with HTTPS

TLS, encryption, and HTTPS sound very technical—and they are. We use HTTPS (which stands for “Hypertext Transfer Protocol Secure”) to transmit data over the internet in a way that prevents eavesdropping.
This means that the entire transmission of all data from your browser to our web server is secure—no one can “eavesdrop.”

We have thus introduced an additional layer of security and comply with data protection through design (Article 25(1) of the GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the Internet, we can ensure the protection of confidential data.
You can recognize the use of this data transmission security feature by the small padlock icon in the top-left corner of the browser, to the left of the web address (e.g., examplepage.de), and the use of the https scheme (instead of http) as part of our web address.
If you would like to learn more about encryption, we recommend searching Google for “Hypertext Transfer Protocol Secure wiki” to find useful links to further information.

Communication

Communication Summary

👥 Who this applies to: Anyone who communicates with us by phone, email, or online form

📓 Processed data: e.g., phone number, name, email address, form data entered. For more details, please refer to the specific contact method used

🤝 Purpose: Handling communication with customers, business partners, etc.

📅 Retention period: Duration of the business transaction and applicable legal requirements

⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(b) GDPR (contract), Art. 6(1)(f) GDPR (legitimate interests)

When you contact us and communicate with us by phone, email, or through our online form, we may process your personal data.

The data is processed for the purpose of handling and addressing your inquiry and the related business transaction. The data will be stored for as long as necessary or as required by law.

Affected individuals

These changes affect everyone who contacts us through the communication channels we provide.

Phone

When you call us, the call data is stored in pseudonymized form on the respective device and with the telecommunications provider used. In addition, data such as your name and phone number may subsequently be sent via email and stored for the purpose of responding to your inquiry. The data will be deleted as soon as the business transaction has been completed and legal requirements permit.

Email

When you communicate with us via email, data may be stored on your device (computer, laptop, smartphone, etc.) and on the email server. The data will be deleted as soon as the matter has been resolved and legal requirements permit.

Online Forms

When you contact us via the online form, your data is stored on our web server and, if necessary, forwarded to one of our email addresses. The data will be deleted as soon as the matter has been resolved and legal requirements permit.

Legal Basis

The processing of data is based on the following legal grounds:

  • Art. 6(1)(a) GDPR (Consent): You give us your consent to store your data and to use it for purposes related to the business transaction;
  • Art. 6(1)(b) of the GDPR (Contract): It is necessary for the performance of a contract with you or a processor, such as a telephone service provider, or we need to process the data for pre-contractual activities, such as preparing a quote;
  • Art. 6(1)(f) GDPR (Legitimate Interests): We aim to handle customer inquiries and business communications in a professional manner. To do so, certain technical systems—such as email programs, Exchange servers, and mobile network operators—are necessary to ensure efficient communication.

Cookies

Cookies Summary

👥 Data subjects: Website visitors

🤝 Purpose: depends on the specific cookie. For more details, see below or contact the software provider that sets the cookie.

📓 Data processed: This depends on the specific cookie used. For more details, please see below or contact the software provider that sets the cookie.

📅 Storage duration: depends on the specific cookie and can range from hours to years

⚖️ Legal basis: Article 6(1)(a) of the GDPR (consent), Article 6(1)(f) of the GDPR (legitimate interests)

What are cookies?

Our website uses HTTP cookies to store user-specific data.
Below, we explain what cookies are and why they are used so that you can better understand the following privacy policy.

Whenever you browse the internet, you use a web browser. Some well-known browsers include Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. Most websites store small text files in your browser. These files are called cookies.

One thing is undeniable: cookies are really useful little helpers. Almost all websites use cookies. More specifically, they are HTTP cookies, as there are other types of cookies for different applications. HTTP cookies are small files that our website stores on your computer. These cookie files are automatically placed in the cookie folder, which is essentially the “brain” of your browser. A cookie consists of a name and a value. When defining a cookie, one or more attributes must also be specified.

Cookies store certain user data about you, such as your language or personal page settings. When you visit our site again, your browser sends this “user-specific” information back to our site. Thanks to cookies, our website recognizes you and provides you with the settings you’re accustomed to. In some browsers, each cookie has its own file; in others, such as Firefox, all cookies are stored in a single file.

The following diagram illustrates a possible interaction between a web browser, such as Chrome, and a web server. In this scenario, the web browser requests a website and receives a cookie from the server, which the browser uses again the next time a different page is requested.

There are both first-party cookies and third-party cookies. First-party cookies are created directly by our website, while third-party cookies are created by partner websites (e.g., Google Analytics). Each cookie must be evaluated individually, as each cookie stores different data. The expiration time of a cookie also varies from a few minutes to a few years. Cookies are not software programs and do not contain viruses, Trojans, or other “malware.” Cookies also cannot access information on your computer.

Here is an example of what cookie data might look like:

Name: _ga
Value: GA1.2.1326744211.152313105770-9
Purpose: Distinguishing website visitors
Expiration date: After 2 years

A browser should be able to support these minimum sizes:

  • At least 4,096 bytes per cookie
  • At least 50 cookies per domain
  • At least 3,000 cookies in total

What types of cookies are there?

The specific cookies we use depend on the services we employ and are explained in the following sections of this privacy policy. At this point, we would like to briefly discuss the different types of HTTP cookies.

There are four types of cookies:

Essential Cookies
These cookies are necessary to ensure the website’s basic functions. For example, these cookies are needed when a user adds a product to the shopping cart, then continues browsing other pages, and only proceeds to checkout later. These cookies ensure that the shopping cart is not cleared, even if the user closes their browser window.

Functional Cookies
These cookies collect information about user behavior and whether the user receives any error messages. They are also used to measure the loading time and the website’s performance across different browsers.

Functional Cookies
These cookies improve the user experience. For example, they store locations, font sizes, or form data that you have entered.

Advertising Cookies
These cookies are also known as targeting cookies. They are used to deliver personalized ads to the user. This can be very useful, but it can also be very annoying.

Usually, when you visit a website for the first time, you’ll be asked which of these types of cookies you’d like to allow. And, of course, this decision is also stored in a cookie.

If you'd like to learn more about cookies and don't mind reading technical documentation, we recommend https://datatracker.ietf.org/doc/html/rfc6265, the Internet Engineering Task Force (IETF) Request for Comments titled “HTTP State Management Mechanism.”

Purpose of processing via cookies

The purpose ultimately depends on the specific cookie. You can find more details below or by contacting the manufacturer of the software that sets the cookie.

What data is processed?

Cookies are small tools that help with many different tasks. Unfortunately, it is not possible to generalize about what data is stored in cookies, but we will inform you about the data that is processed or stored in the following privacy policy.

How long cookies are stored

The duration for which cookies are stored depends on the specific cookie and is explained in more detail below. Some cookies are deleted after less than an hour, while others may remain stored on a computer for several years.

You also have control over how long cookies are stored. You can manually delete all cookies at any time via your browser (see also “Right to Object” below). Furthermore, cookies that are based on your consent will be deleted at the latest upon revocation of your consent, although the lawfulness of their storage up to that point remains unaffected.

Right to object – how can I delete cookies?

You decide for yourself whether and how you want to use cookies. Regardless of which service or website the cookies come from, you always have the option to delete, disable, or allow only certain cookies. For example, you can block third-party cookies but allow all other cookies.

If you want to see which cookies have been stored in your browser, or if you want to change or delete cookie settings, you can find these options in your browser settings:

Chrome: Delete, enable, and manage cookies in Chrome

Safari: Managing Cookies and Website Data with Safari

Firefox: Clear cookies to remove data that websites have stored on your computer

Internet Explorer: Deleting and Managing Cookies

Microsoft Edge: Deleting and Managing Cookies

If you do not want to accept cookies at all, you can configure your browser to notify you whenever a cookie is about to be set. This allows you to decide on a case-by-case basis whether to accept each cookie or not. The procedure varies depending on the browser. If you are using Chrome, we recommend searching for instructions on Google using the search terms “delete cookies Chrome” or “disable cookies Chrome.”

Legal basis

The so-called “Cookie Directive” has been in effect since 2009. It stipulates that the storage of cookies requires consent (Article 6(1)(a) GDPR). However, reactions to these guidelines still vary widely among EU countries. In Austria, however, this directive was implemented in Section 165(3) of the Telecommunications Act (2021). In Germany, the Cookie Directive was not implemented as national law. Instead, this directive was largely implemented in Section 15(3) of the Telemedia Act (TMG), which was replaced by the Digital Services Act (DDG) in May 2024.

For strictly necessary cookies, even in the absence of consent, there are legitimate interests (Article 6(1)(f) of the GDPR), which are of an economic nature in most cases. We want to provide visitors to the website with a pleasant user experience, and certain cookies are often absolutely necessary for this purpose.

Unless strictly necessary cookies are used, this will only occur with your consent. The legal basis for this is Article 6(1)(a) of the GDPR.

The following sections provide more detailed information about the use of cookies, provided that the software in question uses cookies.

Website Builder Systems: Introduction

Website Builder Systems Privacy Policy Summary

👥 Data subjects: Website visitors

🤝 Purpose: To improve our services

📓 Processed data: Data such as technical usage information (e.g., browser activity, clickstream activity, session heatmaps), as well as contact information, IP address, or your geographic location. You can find more details below in this Privacy Policy and in the providers’ privacy policies.

📅 Retention period: depends on the provider

⚖️ Legal basis: Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(a) GDPR (consent)

What are website builders?

We use a website builder for our website. Website builders are a specific type of content management system (CMS). With a website builder, website operators can create a website very easily and without any programming knowledge. In many cases, web hosting providers also offer website builders. When using a website builder, your personal data may be collected, stored, and processed. In this privacy notice, we provide you with general information about data processing by website builders. For more detailed information, please refer to the provider’s privacy policy.

Why do we use website builders for our website?

The biggest advantage of a modular system is its ease of use. We want to provide you with a clear, simple, and user-friendly website that we can easily manage and maintain ourselves—without any external assistance. Modular systems now offer many helpful features that we can use even without programming knowledge. This allows us to design our website exactly as we want and ensure that your visit is both informative and enjoyable.

What data is stored by a modular system?

Exactly what data is stored naturally depends on the website builder system used. Each provider processes and collects different types of data from website visitors. However, technical usage information such as operating system, browser, screen resolution, language and keyboard settings, hosting provider, and the date of your website visit is typically collected. In addition, tracking data (e.g., browser activity, clickstream activity, session heatmaps, etc.) may also be processed. Furthermore, personal data may also be collected and stored. This usually includes contact information such as email address, phone number (if you have provided it), IP address, and geographic location data. You can find out exactly what data is stored in the provider’s privacy policy.

How long and where will the data be stored?

We provide further information below regarding the duration of data processing in connection with the website builder system used, to the extent that we have additional information on this matter. You can find detailed information on this in the provider’s privacy policy. In general, we process personal data only for as long as is strictly necessary to provide our services and products. The provider may store your data according to its own policies, over which we have no control.

Right to object

You always have the right to access, correct, and delete your personal data. If you have any questions, you can also contact the administrators of the website builder system used at any time. You can find their contact information either in our Privacy Policy or on the provider’s website.

You can delete, disable, or manage cookies that websites use for their functions in your browser. The process varies depending on which browser you use. Please note, however, that this may prevent some features from working as usual.

Legal basis

We have a legitimate interest in using a website builder to optimize our online service and present it to you in an efficient and user-friendly manner. The legal basis for this is Article 6(1)(f) of the GDPR (legitimate interests). However, we will only use the website builder if you have given your consent.

Unless the processing of data is strictly necessary for the operation of the website, data will be processed only with your consent. This applies in particular to tracking activities. The legal basis for this is Article 6(1)(a) of the GDPR.

In this privacy policy, we have provided you with the most important general information regarding data processing. If you would like more detailed information on this topic, you can find additional details—where available—in the following section or in the provider’s privacy policy.

WordPress.com Privacy Policy

WordPress.com Privacy Policy Summary

👥 Data subjects: Website visitors

🤝 Purpose: To improve our services

📓 Processed data: Data such as technical usage information (e.g., browser activity, clickstream activity, session heatmaps), as well as contact information, IP address, or your geographic location. You can find more details below in this Privacy Policy.

📅 Storage duration: This depends primarily on the type of data stored and the specific settings.

⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is WordPress?

We use the well-known content management system WordPress.com for our website. The service provider is the American company Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA.

The company was founded in 2003 and, in a relatively short time, grew to become one of the most well-known content management systems (CMS) worldwide. A CMS is software that helps us design our website and present content in an attractive and organized manner. This content can include text, audio, and video.
Through the use of WordPress, personal data about you may also be collected, stored, and processed. Generally, mainly technical data such as operating system, browser, screen resolution, or hosting provider is stored. However, personal data such as IP address, geographic data, or contact information may also be processed.

Why do we use WordPress on our website?

We have many strengths, but actual programming isn't really one of our core competencies.

Still, we want a high-performance, visually appealing website that we can manage and maintain ourselves. With a website builder or a content management system like WordPress, that’s exactly what’s possible. With WordPress, we don’t need to be programming experts to offer you a beautiful website. Thanks to WordPress, we can operate our website quickly and easily even without any prior technical knowledge. If technical issues ever arise or we have specific requests for our website, we still have our specialists who are well-versed in HTML, PHP, CSS, and more.

Thanks to WordPress’s user-friendly interface and extensive features, we can design our website to meet your needs and provide you with a great user experience.

What data does WordPress process?

Non-personal data includes, for example, technical usage information such as browser activity, clickstream activity, session heatmaps, and data about your computer, operating system, browser, screen resolution, language and keyboard settings, internet service provider, and the date of your visit to the site.

In addition, personal data is also collected. This primarily includes contact information (email address or phone number, if you provide it), your IP address, or your geographic location.

WordPress may also use cookies to collect data. These cookies often track information about your behavior on our website. For example, they may track which pages you visit most frequently, how long you stay on individual pages, when you leave a page (bounce rate), or which preferences (e.g., language selection) you have set. Based on this data, WordPress can also better tailor its own marketing efforts to your interests and user behavior. Consequently, the next time you visit our website, it will be displayed exactly as you previously configured it.

WordPress may also use technologies such as pixel tags (web beacons) to, for example, clearly identify you as a user and potentially serve you interest-based ads.

How long and where will the data be stored?

How long data is stored depends on various factors. Specifically, it depends primarily on the type of data stored and the website’s specific settings. Generally, WordPress deletes data once it is no longer needed for its own purposes. There are, of course, exceptions, especially when legal obligations require data to be retained for a longer period. Web server logs containing your IP address and technical data are deleted by WordPress or Automattic after 30 days. Until then, Automattic uses the data to analyze traffic on its own websites (such as all WordPress sites) and to resolve any potential issues. Deleted content on WordPress websites is also kept in the trash for 30 days to allow for restoration; after that, it may remain in backups and caches until they are deleted. The data is stored on Automattic’s servers in the United States.

How can I delete my data or prevent it from being stored?

You have the right and the option to access your personal data at any time and to object to its use and processing. You may also file a complaint with a government regulatory authority at any time.

In your browser, you also have the option to manage, delete, or disable cookies individually. Please note, however, that disabling or deleting cookies may have a negative impact on the functionality of our WordPress site. Depending on which browser you use, the process for managing cookies works slightly differently. Under the “Cookies” section, you will find links to the relevant instructions for the most popular browsers.

Legal basis

If you have consented to the use of WordPress, this consent serves as the legal basis for the corresponding data processing. Pursuant to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur during collection by WordPress.

We also have a legitimate interest in using WordPress to optimize our online service and present it to you in an appealing way. The legal basis for this is Article 6(1)(f) of the GDPR (legitimate interests). However, we only use WordPress if you have given your consent.

WordPress and Automattic process your data in the United States, among other places. Automattic is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data from EU citizens to the United States. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Automattic uses so-called Standard Contractual Clauses (Art. 46(2) and (3) of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Automattic commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the US. These clauses are based on an implementing decision by the EU Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

For more details about the privacy policy and what data is processed by WordPress and how, please visit https://automattic.com/privacy/.

Blogs and Publications Introduction

Blogs and Publications Privacy Policy Summary

👥 Data subjects: Website visitors

🤝 Purpose: To present and optimize our services, facilitate communication with website visitors, implement security measures, and manage operations

📓 Processed data: Data such as contact information, IP address, and published content.

You can find more details about this under "Tools Used."

📅 Retention period: depends on the tools used

⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests), Art. 6(1)(b) GDPR (contract)

What are blogs and publishing platforms?

We use blogs and other communication tools on our website that allow us to communicate with you and you to communicate with us. In doing so, we may store and process your data. This may be necessary to ensure that content is displayed correctly, communication functions properly, and security is enhanced. Our privacy policy provides a general overview of what data from you may be processed. Specific details regarding data processing always depend on the tools and features used. You can find detailed information about data processing in the privacy policies of the individual providers.

Why do we use blogs and other publishing platforms?

Our main goal with this website is to provide you with interesting and engaging content, and we also value your opinions and contributions. That’s why we want to foster a meaningful, interactive dialogue between us and you. With a variety of blogs and opportunities to share your thoughts, we can achieve exactly that. For example, you can leave comments on our content, respond to other comments, or, in some cases, write your own posts.

What data is processed?

Exactly which data is processed depends on the communication features we use. Very often, we store your IP address, username, and the content you post. We do this primarily to ensure security, prevent spam, and take action against illegal content. Cookies may also be used for data storage. These are small text files that are stored in your browser along with information. You can find more details about the data collected and stored in our individual sections and in the privacy policy of the respective provider.

Duration of data processing

We provide further information below regarding the duration of data processing, to the extent that we have additional details. For example, post and comment features store data until you revoke your consent to data storage. In general, personal data is stored only for as long as is strictly necessary to provide our services.

Right to object

You also have the right and the option to withdraw your consent to the use of cookies or third-party communication tools at any time. You can do this either through our cookie management tool or via other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.

Since cookies may also be used by publishing platforms, we recommend that you review our general privacy policy regarding cookies. To find out exactly what data is stored and processed about you, please read the privacy policies of the respective tools.

Legal basis

We use these communication tools primarily on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in maintaining prompt and effective communication with you or other customers, business partners, and visitors. To the extent that such use serves to fulfill contractual obligations or to enter into contractual relationships, the legal basis is also Art. 6(1)(b) GDPR.

Certain processing activities, in particular the use of cookies and the use of comment or messaging features, require your consent. If and to the extent that you have consented to the processing and storage of your data by embedded publishing platforms, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). Most of the communication features we use place cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie guidelines of the respective service provider.

Information about specific tools—if available—can be found in the following sections.

Blog Posts and Comment Features Privacy Policy

There are various online communication tools that we can use on our website. For example, we use blog posts and comment features. This gives you the opportunity to comment on content or write posts. If you use this feature, your IP address may be stored for security reasons. This helps us protect against illegal content such as insults, unauthorized advertising, or prohibited political propaganda. To determine whether comments are spam, we may also store and process user data based on our legitimate interest. If we launch a survey, we will also store your IP address for the duration of the survey to ensure that all participants vote only once. Cookies may also be used for storage purposes. All data we store about you (such as content or personal information) will remain stored until you object.

Cookie Consent Management Platform Introduction

Cookie Consent Management Platform Summary

👥 Affected parties: Website visitors

🤝 Purpose: To obtain and manage consent for specific cookies and, consequently, the use of specific tools

📓 Processed data: Data used to manage cookie settings, such as IP address, time of consent, type of consent, and specific consents. For more details, please refer to the respective tool.

📅 Retention period: Depends on the tool used; you should expect periods of several years

⚖️ Legal basis: Art. 6(1)(a) GDPR (consent), Art. 6(1)(f) GDPR (legitimate interests)

What is a cookie consent management platform?

We use a Consent Management Platform (CMP) on our website that makes it easier for both us and you to manage the scripts and cookies used correctly and securely. The software automatically displays a cookie pop-up, scans and monitors all scripts and cookies, provides the cookie consent required by data protection laws, and helps both us and you keep track of all cookies. Most cookie consent management tools identify and categorize all existing cookies. As a website visitor, you then decide for yourself whether and which scripts and cookies you allow or do not allow. The following diagram illustrates the relationship between the browser, web server, and CMP.

Why do we use a cookie management tool?

Our goal is to provide you with the highest possible level of transparency regarding data protection. We are also legally required to do so. We want to inform you as clearly as possible about all the tools and cookies that may store and process your data. It is also your right to decide for yourself which cookies you accept and which you do not. To grant you this right, we first need to know exactly which cookies are present on our website. Thanks to a cookie management tool that regularly scans the website for all existing cookies, we are aware of all cookies and can provide you with GDPR-compliant information about them. You can then accept or reject cookies via the consent system.

What data is processed?

Using our cookie management tool, you can manage each individual cookie yourself and have complete control over the storage and processing of your data. Your consent is stored so that we do not have to ask for it every time you visit our website and so that we can provide proof of your consent if required by law. This information is stored either in an opt-in cookie or on a server. The storage period for your cookie consent varies depending on the provider of the cookie management tool. In most cases, this data (such as a pseudonymous user ID, the time of consent, details regarding cookie categories or tools, browser, and device information) is stored for up to two years.

Duration of data processing

We provide information below regarding the duration of data processing, provided we have further details on this matter. In general, we process personal data only for as long as is strictly necessary to provide our services and products. Data stored in cookies is retained for varying lengths of time. Some cookies are deleted as soon as you leave the website, while others may remain stored in your browser for several years. The exact duration of data processing depends on the tool used; in most cases, you should expect a storage period of several years. You can usually find detailed information about the duration of data processing in the respective privacy policies of the individual providers.

Right to object

You also have the right and the option to withdraw your consent to the use of cookies at any time. You can do this either through our cookie management tool or via other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.

You can find information about specific cookie management tools—if available—in the following sections.

Legal basis

If you consent to cookies, your personal data will be processed and stored via these cookies. If we, through your consent (Article 6(1)(a) GDPR), this consent also serves as the legal basis for the use of cookies and the processing of your data. To manage consent for cookies and enable you to provide consent, we use cookie consent management platform software. The use of this software enables us to operate the website efficiently and in compliance with the law, which constitutes a legitimate interest (Article 6(1)(f) of the GDPR).

Security & Anti-Spam

Security & Anti-Spam Privacy Policy Summary

👥 Data subjects: Website visitors

🤝 Purpose: Cybersecurity

📓 Processed data: Data such as your IP address, name, or technical information such as your browser version

You can find more details below and in the individual privacy policies.

📅 Retention period: In most cases, data is stored until it is no longer needed to provide the service

⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is security and anti-spam software?

With security and anti-spam software, you and we can protect ourselves from various spam and phishing emails, as well as other potential cyberattacks. Spam refers to unsolicited bulk promotional emails that you did not request. Such emails are also known as junk mail and can incur costs. Phishing emails, on the other hand, are messages designed to build trust through fake messages or websites in order to obtain personal data. Anti-spam software generally protects against unwanted spam messages or malicious emails that could, for example, introduce viruses into our system. We also use general firewall and security systems that protect our computers from unwanted network attacks.

Why do we use security and anti-spam software?

We place a particularly high priority on security on our website. After all, it’s not just about our security, but above all about yours. Unfortunately, cyber threats have become an everyday reality in the world of IT and the internet. Hackers often attempt to steal personal data from IT systems through cyberattacks. That is why a robust defense system is absolutely essential. A security system monitors all incoming and outgoing connections to our network or computer. To achieve even greater protection against cyberattacks, we use additional external security services in addition to the standard security systems on our computers. This helps prevent unauthorized data traffic, thereby protecting us from cybercrime.

What data is processed by security and anti-spam software?

Exactly what data is collected and stored naturally depends on the specific service. However, we always strive to use only programs that collect data sparingly or store only the data necessary to provide the service offered. In general, the service may store data such as your name, address, IP address, email address, and technical data such as browser type or browser version. Performance and log data may also be collected to detect potential incoming threats in a timely manner. This data is processed within the scope of the services and in compliance with applicable laws. This includes the GDPR for U.S. providers (via the Standard Contractual Clauses). In some cases, these security services also collaborate with third-party providers who may store and/or process data under instruction and in accordance with the privacy policy and other security measures. Data storage is typically carried out via cookies.

Duration of data processing

We provide information below regarding the duration of data processing, to the extent that we have further details. For example, security programs store data until you or we revoke consent for data storage. In general, personal data is stored only for as long as is strictly necessary to provide the services. Unfortunately, in many cases, we do not receive precise information from providers regarding the duration of storage.

Right to object

You also have the right and the option to withdraw your consent to the use of cookies or third-party security software at any time. You can do this either through our cookie management tool or via other opt-out features. For example, you can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser.

Since such security services may also use cookies, we recommend that you review our general privacy policy regarding cookies. To find out exactly what data is stored and processed about you, you should read the privacy policies of the respective tools.

Legal basis

We use these security services primarily on the basis of our legitimate interests (Art. 6(1)(f) of the GDPR) in maintaining a robust security system against various cyberattacks.

Certain processing activities, in particular the use of cookies and security features, require your consent. If you have consented to the processing and storage of your data by integrated security services, this consent serves as the legal basis for data processing (Art. 6(1)(a) GDPR). Most of the services we use place cookies in your browser to store data. We therefore recommend that you carefully read our privacy policy regarding cookies and review the privacy policy or cookie guidelines of the respective service provider.

Information about specific tools—if available—can be found in the following sections.

UpdraftPlus Privacy Policy

We use UpdraftPlus, a backup and security system, for our website. The service provider is the British company Updraft WP Software Ltd., located at 11 Barringer Way, St. Neots, PE19 1LW, Cambridgeshire, United Kingdom.

Due to the United Kingdom’s withdrawal from the European Union, the GDPR no longer applies to data transfers to the UK. However, the European Commission has determined, pursuant to Article 45 of the GDPR, that the UK provides a level of protection equivalent to that of the GDPR. Data transfers to the UK are therefore permitted. You can view the decision here (download): https://eur-lex.europa.eu/legal-content/DE/TXT/PDF/?uri=CELEX:32021D1772

For more information about the data processed when using UpdraftPlus, please see the Privacy Policy at https://updraftplus.com/data-protection-and-privacy-centre/.

Web Design Introduction

Web Design Privacy Policy Summary

👥 Data subjects: Website visitors

🤝 Purpose: To improve the user experience

📓 Processed data: The specific data processed depends heavily on the services used. In most cases, this includes IP addresses, technical data, language settings, browser version, screen resolution, and browser name. You can find more details in the documentation for the respective web design tools.

📅 Retention period: depends on the tools used

⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What is web design?

We use various tools on our website to support our web design. Contrary to popular belief, web design isn’t just about making our website look nice; it’s also about functionality and performance. But of course, creating the right visual appeal for a website is also one of the main goals of professional web design. Web design is a subset of media design and deals with both the visual and the structural and functional aspects of a website. The goal is to use web design to enhance your experience on our website. In web design jargon, this is referred to as user experience (UX) and usability. User experience encompasses all the impressions and experiences a website visitor has while on a website. A subcategory of user experience is usability. This refers to the user-friendliness of a website. The primary focus here is on ensuring that content, subpages, or products are clearly structured so that you can find what you’re looking for quickly and easily. To provide you with the best possible experience on our website, we also use third-party web design tools. In this privacy policy, the category “Web Design” therefore includes all services that enhance the design of our website. These may include, for example, fonts, various plugins, or other integrated web design features.

Why do we use web design tools?

How you take in information on a website depends heavily on the site’s structure, functionality, and visual appeal. That is why high-quality, professional web design has become increasingly important to us. We are constantly working to improve our website and view this as an added service for you, our visitors. Furthermore, a beautiful and functional website also offers economic benefits for us. After all, you will only visit us and take advantage of our offerings if you feel completely at ease.

What data is stored by web design tools?

When you visit our website, web design elements may be embedded in our pages that can also process data. Exactly what data is involved depends, of course, largely on the tools used. Below, you can see exactly which tools we use for our website. For more detailed information about data processing, we also recommend that you read the respective privacy policy of the tools used. There, you will usually find out what data is processed, whether cookies are used, and how long the data is retained. For example, fonts such as Google Fonts automatically transmit information such as language settings, IP address, browser version, browser screen resolution, and browser name to Google’s servers.

Duration of data processing

How long data is processed varies greatly and depends on the web design elements used. For example, when cookies are used, the retention period can range from just one minute to several years. Please educate yourself on this matter. We recommend consulting both our general section on cookies and the privacy policies of the tools used. There you will generally find out exactly which cookies are used and what information is stored in them. Google Font files, for example, are stored for one year. This is intended to improve a website’s loading time. In principle, data is only retained for as long as necessary to provide the service. Data may also be stored for longer periods if required by law.

Right to object

You also have the right and the option to withdraw your consent to the use of cookies or third-party providers at any time. You can do this either through our cookie management tool or via other opt-out features. You can also prevent data collection via cookies by managing, disabling, or deleting cookies in your browser. However, some data within web design elements (mostly related to fonts) cannot be deleted quite so easily. This is the case when data is automatically collected directly upon page view and transmitted to a third-party provider (such as Google). In such cases, please contact the support team of the respective provider. For Google, you can reach support at https://support.google.com/?hl=de.

Legal basis

If you have consented to the use of web design tools, the legal basis for the corresponding data processing is this consent. According to Article 6(1)(a) of the GDPR (Consent), this consent constitutes the legal basis for the processing of personal data, such as that which may occur when data is collected by web design tools. We also have a legitimate interest in improving the web design of our website. After all, this is the only way we can provide you with an attractive and professional website. The corresponding legal basis for this is Article 6(1)(f) of the GDPR (Legitimate Interests). However, we only use web design tools to the extent that you have given your consent. We would like to emphasize this point once again here.

Information about specific web design tools—if available—can be found in the following sections.

Google Fonts Privacy Policy

Google Fonts Privacy Policy Summary

👥 Data subjects: Website visitors

🤝 Purpose: To improve our services

📓 Processed data: Data such as IP addresses and CSS and font requests

You can find more details below in this privacy policy.

📅 Retention period: Font files are stored by Google for one year

⚖️ Legal basis: Art. 6(1)(a) GDPR (Consent), Art. 6(1)(f) GDPR (Legitimate Interests)

What are Google Fonts?

We use Google Fonts on our website. These are the “Google fonts” provided by Google Inc. For the European region, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) is responsible for all Google services.

You do not need to sign in or provide a password to use Google Fonts. Furthermore, no cookies are stored in your browser. The files (CSS, fonts) are requested via the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, requests for CSS and fonts are completely separate from all other Google services. If you have a Google account, you don’t need to worry that your Google account data will be transmitted to Google while using Google Fonts. Google tracks the use of CSS (Cascading Style Sheets) and the fonts used and stores this data securely. We’ll take a closer look at exactly how this data is stored.

Google Fonts (formerly Google Web Fonts) is a directory of over 800 fonts that Google provides to its users free of charge.

Many of these fonts are released under the SIL Open Font License, while others are released under the Apache License. Both are free software licenses.

Why do we use Google Fonts on our website?

With Google Fonts, we can use fonts on our website without having to upload them to our own server. Google Fonts is a key component in maintaining the high quality of our website. All Google fonts are automatically optimized for the web, which saves data and is a major advantage, especially for use on mobile devices. When you visit our site, the small file size ensures fast loading times. Furthermore, Google Fonts are secure web fonts. Differences in rendering systems across various browsers, operating systems, and mobile devices can lead to errors. Such errors can sometimes cause text or entire web pages to appear distorted. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform issues with Google Fonts. Google Fonts supports all major browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod). We use Google Fonts so that we can present our entire online service as beautifully and consistently as possible.

What data does Google store?

When you visit our website, the fonts are loaded via a Google server. This external request transmits data to Google’s servers. This allows Google to recognize that you—or rather, your IP address—are visiting our website. The Google Fonts API was developed to limit the use, storage, and collection of end-user data to what is necessary for the proper delivery of fonts. By the way, API stands for “Application Programming Interface” and serves, among other things, as a data transmitter in the software sector.

Google Fonts securely stores CSS and font requests on Google, ensuring they are protected. By analyzing the collected usage data, Google can determine how well individual fonts are being received. Google publishes the results on internal analytics pages, such as Google Analytics. Google also uses data from its own web crawler to determine which websites use Google Fonts. This data is published in the Google Fonts BigQuery database. Business owners and developers use the Google web service BigQuery to analyze and process large amounts of data.

However, it is important to note that every Google Font request automatically transmits information such as language settings, IP address, browser version, browser screen resolution, and browser name to Google’s servers. It is not clear whether this data is also stored, nor does Google explicitly state this.

How long and where will the data be stored?

Google stores requests for CSS assets on its servers—which are primarily located outside the EU—for one day. This allows us to use the fonts via a Google stylesheet. A stylesheet is a template that makes it easy and quick to change, for example, the design or font of a website.

Google stores font files for one year. Google’s goal is to improve website loading times across the board. When millions of websites reference the same fonts, they are cached after the first visit and appear immediately on all other websites visited later. Google sometimes updates font files to reduce file size, expand language coverage, and improve design.

How can I delete my data or prevent it from being stored?

The data that Google stores for a day or a year cannot simply be deleted. The data is automatically transmitted to Google when you visit a page. To delete this data early, you must contact Google Support at https://support.google.com/?hl=de&tid=313105770 . In this case, you can only prevent data storage by not visiting our site.

Unlike other web fonts, Google gives us unrestricted access to all fonts. This means we can access an unlimited selection of fonts and get the most out of our website. For more information about Google Fonts and to ask further questions, please visit https://developers.google.com/fonts/faq?tid=313105770. While Google addresses privacy-related issues there, the site does not contain truly detailed information about data storage. It is relatively difficult to obtain truly precise information from Google regarding stored data.

Legal basis

If you have consented to the use of Google Fonts, the legal basis for the corresponding data processing is this consent. According to Art. 6(1)(a) GDPR (Consent) constitutes the legal basis for the processing of personal data, as may occur during collection by Google Fonts.

We also have a legitimate interest in using Google Fonts to optimize our online service. The legal basis for this is Art. 6(1)(f) GDPR (Legitimate Interests). However, we only use Google Fonts if you have given your consent.

Google processes your data in the United States, among other places. Google is an active participant in the EU-U.S. Data Privacy Framework, which governs the proper and secure transfer of personal data belonging to EU citizens to the United States. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en.

In addition, Google uses so-called Standard Contractual Clauses (Art. 46(2) and (3) of the GDPR). Standard Contractual Clauses (SCCs) are model templates provided by the European Commission and are intended to ensure that your data complies with European data protection standards even when it is transferred to and stored in third countries (such as the United States). Through the EU-US Data Privacy Framework and the Standard Contractual Clauses, Google commits to adhering to European data protection standards when processing your relevant data, even if the data is stored, processed, and managed in the US. These clauses are based on an implementing decision by the European Commission. You can find the decision and the corresponding Standard Contractual Clauses here, among other places: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de

The Google Ads Data Processing Terms, which refer to the Standard Contractual Clauses, can be found at https://business.safety.google/intl/de/adsprocessorterms/.

You can also find out what data Google generally collects and how it is used at https://www.google.com/intl/de/policies/privacy/ .

Closing Remarks

Congratulations! If you’re reading this, you’ve either really “battled” your way through our entire privacy policy or at least scrolled down to this point. As you can see from the length of our privacy policy, we take the protection of your personal data very seriously.
It is important to us to inform you to the best of our knowledge and belief about the processing of personal data. In doing so, we want to not only tell you what data is processed, but also explain the reasons for using various software programs. Privacy policies usually sound very technical and legal. However, since most of you are not web developers or lawyers, we wanted to take a different approach linguistically and explain the facts in simple and clear language. Of course, this isn’t always possible due to the nature of the subject matter. Therefore, the most important terms are explained in more detail at the end of the privacy policy.
If you have any questions regarding data protection on our website, please do not hesitate to contact us or the responsible authority. We hope you enjoy your visit and look forward to welcoming you back to our website soon.

All texts are protected by copyright.

Source: Privacy Policy Created using the AdSimple Privacy Policy Generator for Germany

Cookie Consent Banner by Real Cookie Banner