Skip to content

Privacy policy


This privacy policy explains which types of your personal data (also referred to below as “data”) we process, for which purposes and to what extent. It applies to all processing of personal data that we carry out, both in providing our services and, in particular, on our websites, in mobile applications and on external online profiles such as our social media accounts (collectively referred to below as our “online services”).

The terms used are not gender-specific.

Last updated: 11 April 2024

  • Introduction
  • Controller
  • Overview of processing
  • Relevant legal bases
  • Security measures
  • Transfer of personal data
  • Retention and deletion of data
  • Rights of data subjects
  • Business services
  • Providers and services used in our business activities
  • Credit checks
  • Provision of online services and web hosting
  • Contact and enquiry management
  • Communication via messaging services
  • Chatbots and chat functions
  • Video conferences, online meetings, webinars and screen sharing
  • Cloud services
  • Social media profiles
  • Plugins and embedded functions and content
  • Management, organisation and support tools
  • Recruitment procedures
  • Changes and updates to this privacy policy
  • Definitions

Stadtbild Werbegesellschaft mbH
Volbedingstraße 2
04357 Leipzig
Germany

Email address:

info@stadtbild.de

Phone: 0341-9004430

Legal notice: https://www.stadtbild.de/impressum

The following overview summarises the types of data processed and the purposes of processing, and identifies the data subjects concerned.

Types of data processed

  • Master data.
  • Payment data.
  • Location data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Metadata, communication data and procedural data.
  • Applicant data.

Categories of data subjects

  • Customers.
  • Employees.
  • Prospective customers.
  • Communication partners.
  • Users.
  • Applicants.
  • Business and contractual partners.
  • Persons depicted.
  • Third parties.

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations.
  • Contact enquiries and communication.
  • Security measures.
  • Direct marketing.
  • Office and organisational procedures.
  • Conversion measurement.
  • Managing and responding to enquiries.
  • Recruitment procedures.
  • Feedback.
  • Marketing.
  • Provision of our online services and user-friendliness.
  • Assessment of creditworthiness.
  • Information technology infrastructure.

Automated individual decision-making

  • Credit information.

Relevant legal bases under the GDPR: Below is an overview of the GDPR legal bases on which we process personal data. Please note that national data protection provisions in your country or our country of residence or establishment may apply in addition to the GDPR. If more specific legal bases apply in an individual case, we identify them in this privacy policy.

  • Consent (Article 6(1)(a) GDPR) – The data subject has consented to the processing of their personal data for one or more specific purposes.
  • Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR) – Processing is necessary to perform a contract with the data subject or to take steps at their request before entering into a contract.
  • Legal obligation (Article 6(1)(c) GDPR) – Processing is necessary to meet a legal obligation to which the controller is subject.
  • Legitimate interests (Article 6(1)(f) GDPR) – Processing is necessary to protect the legitimate interests of the controller or a third party, provided these are not overridden by the data subject’s interests, fundamental rights and freedoms requiring protection of personal data.
  • Recruitment as a pre-contractual or contractual relationship (Article 6(1)(b) GDPR) – Where special categories of personal data within Article 9(1) GDPR, such as health data including severe disability or ethnic origin, are requested from applicants so that the controller or data subject can exercise rights and meet obligations under employment, social security and social protection law, processing is based on Article 9(2)(b) GDPR. Where processing protects the vital interests of applicants or other persons, Article 9(2)(c) GDPR applies. For preventive or occupational medicine, assessment of an employee’s working capacity, medical diagnosis, health or social care or treatment, or management of health or social care systems and services, Article 9(2)(h) GDPR applies. Where special categories of data are disclosed on the basis of freely given consent, processing is based on Article 9(2)(a) GDPR.

National data protection rules in Germany: German national data protection rules apply alongside the GDPR. These include, in particular, the law protecting against misuse of personal data during data processing, the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). The BDSG includes specific provisions on access, erasure, objections, processing special categories of personal data, processing for other purposes, transfers and automated individual decision-making including profiling. State data protection laws of the individual German federal states may also apply.

Application of the GDPR and Swiss Data Protection Act: This privacy notice provides information under both the Swiss Federal Act on Data Protection (Swiss DPA) and the GDPR. For broader geographical applicability and clarity, we use GDPR terminology. In particular, we use “processing” of “personal data”, “legitimate interest” and “special categories of data” rather than the corresponding Swiss DPA terms for handling personal data, overriding interests and particularly sensitive personal data. Where the Swiss DPA applies, however, the legal meaning of those terms continues to be determined under that Act.

In accordance with legal requirements, and taking into account the state of the art, implementation costs, the nature, scope, circumstances and purposes of processing, and the differing likelihood and severity of risks to individuals’ rights and freedoms, we implement appropriate technical and organisational measures to provide a level of protection appropriate to the risk.

These measures include protecting the confidentiality, integrity and availability of data by controlling physical and electronic access, entry, disclosure, availability and separation of data. We have also established procedures for exercising data subject rights, deleting data and responding to threats to data. We consider personal data protection when developing or selecting hardware, software and procedures, following the principles of data protection by design and by default.

IP address truncation: where we or our service providers and technologies process IP addresses and a full address is not required, the address is truncated, also known as IP masking. The last two digits or the last part after a full stop are removed or replaced with placeholders. Truncation is intended to prevent or substantially hinder identification of a person from their IP address.

Protecting online connections with TLS/SSL encryption (HTTPS): we use TLS/SSL encryption to protect users’ data transmitted through our online services from unauthorised access. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are cornerstones of secure internet data transmission. They encrypt information transmitted between a website or app and the user’s browser, or between two servers, protecting it from unauthorised access. TLS, the more advanced and secure successor to SSL, ensures that data transmissions meet the highest security standards. A website secured by an SSL/TLS certificate shows HTTPS in its URL, indicating to users that their data is transmitted securely and in encrypted form.

When processing personal data, we may transfer or disclose it to other bodies, companies, legally independent organisational units or individuals. Recipients may include providers contracted to perform IT tasks or providers of services and content embedded in a website. We observe legal requirements and, in particular, enter into appropriate contracts or agreements with recipients to protect your data.

We delete processed data in accordance with legal requirements once consent permitting processing is withdrawn or other permissions cease to apply, for example when the purpose of processing no longer exists or the data is no longer required for that purpose. If data is retained for other legally permissible purposes, processing is restricted to those purposes: the data is blocked and not processed for other purposes. This includes data retained for commercial or tax law reasons, to establish, exercise or defend legal claims, or to protect another natural or legal person’s rights. Our privacy notices may provide further retention and deletion information specific to individual processing operations. Where several retention periods or deletion deadlines apply to the same data, the longer period applies. Unless a starting point is specified, periods of at least one year generally begin at the end of the calendar year in which the triggering event occurred. Data retained or archived for legal or other reasons rather than its original collection purpose is processed solely for the purposes requiring its retention or archiving.

Data subject rights under the GDPR: the GDPR provides various rights, particularly under Articles 15 to 21:

  • Right to object: on grounds relating to your particular situation, you may object at any time to processing of your personal data based on Article 6(1)(e) or (f) GDPR, including profiling based on those provisions. Where your personal data is processed for direct marketing, you may object at any time to processing for that purpose, including profiling related to direct marketing.
  • Right to withdraw consent: You may withdraw consent at any time.
  • Right of access: You may request confirmation of whether your data is being processed, access to that data, further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: In accordance with legal requirements, you may request completion of your data or correction of inaccurate data relating to you.
  • Right to erasure and restriction of processing: In accordance with legal requirements, you may request deletion of your data without undue delay or, alternatively, restriction of processing.
  • Right to data portability: In accordance with legal requirements, you may receive data you have provided to us in a structured, commonly used, machine-readable format or request its transfer to another controller.
  • Complaint to a supervisory authority: In accordance with legal requirements and without prejudice to other administrative or judicial remedies, you may lodge a complaint with a data protection supervisory authority, particularly in the Member State of your habitual residence, workplace or the alleged infringement, if you consider that processing of your personal data infringes the GDPR.

We process data from contractual and business partners, including customers and prospective customers (collectively “contractual partners”), within contractual and comparable legal relationships and related measures, and in communication with contractual partners or before a contract, for example when responding to enquiries.

We use this data to fulfil our contractual obligations, including providing agreed services, any update obligations and remedies for warranty claims or other service disruptions. We also use it to protect our rights, perform related administrative tasks and organise our business. We process data on the basis of our legitimate interests in proper, economically sound business management and security measures protecting contractual partners and our operations against misuse and threats to data, confidential information and rights. This may involve telecommunications, transport and other support services, subcontractors, banks, tax and legal advisers, payment service providers or tax authorities. Within applicable law, we disclose contractual partners’ data to third parties only where required for these purposes or legal obligations. This privacy policy informs contractual partners about other processing, such as marketing.

We inform contractual partners which data is required for these purposes before or during collection, for example in online forms, through special markings such as colours or symbols such as asterisks, or in person.

We delete data after statutory warranty and comparable obligations expire, generally after four years, unless it is stored in a customer account or must be retained for statutory archiving, typically ten years for tax purposes. Data disclosed by contractual partners in the course of an assignment is deleted according to requirements and generally when the assignment ends.

  • Types of data processed: Master data (such as full name, residential address, contact information and customer number); payment data (such as bank details, invoices and payment history); contact data (such as postal and email addresses or telephone numbers); contract data (such as subject matter, duration and customer category).
  • Data subjects: Prospective customers; business and contractual partners; customers.
  • Purposes of processing: Provision of contractual services and fulfilment of obligations; contact enquiries and communication; office and organisational procedures; managing and responding to enquiries.
  • Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legal obligation (Article 6(1)(c) GDPR); legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Agency services: We process customer data as part of our contractual services, which may include conceptual and strategic advice, campaign planning, software and design development, advice or maintenance, implementation of campaigns and processes, handling, server administration, data analysis, consultancy and training; Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).
  • Marketing services: We process data from our customers and commissioning clients (collectively “customers”) to provide marketing services such as market research, advertising campaigns, content creation and social media management. Required information is marked when orders are placed and includes data needed to provide services and invoice them, plus contact details for consultation. Where we access information about end customers, employees or other persons, we process it according to legal and contractual requirements; Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), legal obligation (Article 6(1)(c) GDPR), legitimate interests (Article 6(1)(f) GDPR).

In our business activities, we use additional third-party services, platforms, interfaces or plugins (“services”) in accordance with legal requirements. Their use is based on our interests in proper, lawful and economically sound business operations and internal organisation.

  • Types of data processed: Master data (such as full name, residential address, contact information and customer number); payment data (such as bank details, invoices and payment history); contact data (such as postal and email addresses or telephone numbers); content data (such as text or image messages and posts, and related information including authorship or creation time); contract data (such as subject matter, duration and customer category).
  • Data subjects: Customers; prospective customers; users (such as website visitors and online service users); business and contractual partners; employees (including staff, applicants, temporary workers and other personnel).
  • Purposes of processing: Provision of contractual services and fulfilment of obligations; office and organisational procedures.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

Where we provide services in advance or assume comparable economic risks, such as payment on invoice, we reserve the right to obtain identity and credit information from specialist credit reference agencies to assess credit risk using mathematical and statistical methods, in protection of our legitimate interests.

We use information from credit reference agencies about the statistical probability of payment default when making appropriate discretionary decisions on establishing, performing and ending the contractual relationship. If a credit check is negative, we reserve the right to refuse payment on invoice or other advance provision of services.

In accordance with legal requirements, the decision to provide services in advance is based solely on automated individual decision-making by our software using information from the credit reference agency.

Where we obtain express consent from contractual partners, consent is the legal basis for obtaining credit information and transmitting customer data to credit reference agencies. Without consent, credit checks are based on our legitimate interest in protecting payment claims against default.

  • Types of data processed: Master data (such as full name, residential address, contact information and customer number); payment data (such as bank details, invoices and payment history); contact data (such as postal and email addresses or telephone numbers); contract data (such as subject matter, duration and customer category); usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions).
  • Data subjects: Customers; prospective customers; business and contractual partners.
  • Purposes of processing: Assessment of creditworthiness.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR).
  • Automated individual decision-making: Credit information (decision based on a credit check).

Further information on processing operations, procedures and services:

We process users’ data to provide our online services. This includes the user’s IP address, which is necessary to transmit our services’ content and functions to their browser or device.

  • Types of data processed: Usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved).
  • Data subjects: Users (such as website visitors and online service users).
  • Purposes of processing: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment such as computers and servers); security measures.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Provision of online services on our own or dedicated server hardware: We provide our online services using server hardware we operate, together with the associated storage, computing capacity and software; Legal bases: Legitimate interests (Article 6(1)(f) GDPR).
  • Collection of access data and log files: Access to our online services is recorded in server log files. These may contain the addresses and names of pages and files accessed, access dates and times, data volumes transferred, successful retrieval notifications, browser type and version, the user’s operating system, referring URL (the page previously visited), and generally IP addresses and the requesting provider. Log files may be used for security, for example to prevent server overload, particularly from abusive attacks such as DDoS attacks, and to ensure server capacity and stability; Legal bases: Legitimate interests (Article 6(1)(f) GDPR). Deletion of data: Log file information is retained for a maximum of 30 days, then deleted or anonymised. Data needed as evidence is exempt from deletion until the relevant incident has been conclusively resolved.

When people contact us, for example by post, contact form, email, telephone or social media, or within existing user and business relationships, we process their information where necessary to respond to contact enquiries and any requested measures.

  • Types of data processed: Contact data (such as postal and email addresses or telephone numbers); content data (such as text or image messages and posts, and related information including authorship or creation time); usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved).
  • Data subjects: Communication partners; users (such as website visitors and online service users); business and contractual partners.
  • Purposes of processing: Contact enquiries and communication; managing and responding to enquiries; feedback (such as collection through online forms); provision of our online services and user-friendliness; contractual services and obligations; marketing.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR); performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR).

Further information on processing operations, procedures and services:

  • Contact form: When users contact us through our contact form, email or other channels, we process the data they provide to handle their enquiry; Legal bases: Performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR), legitimate interests (Article 6(1)(f) GDPR).
  • 3CX: Chat functions, video and audio conferences; Service provider: 3CX GmbH, Walter-Gieseking-Straße 22, 30519 Hannover, Germany; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://www.3cx.de/. Privacy policy: https://www.3cx.com/company/privacy/.

We use messaging services for communication. Please observe the following information about their functionality, encryption, use of communication metadata and your options for objecting.

You can also contact us through alternatives such as telephone or email. Please use the contact details provided to you or listed within our online services.

Where content is end-to-end encrypted, your messages and attachments, including attached images, are encrypted from one end to the other. Their content cannot be viewed, even by the messaging provider. Always use a current version of the messaging service with encryption enabled to ensure message content is encrypted.

However, messaging providers may still learn that and when communication partners contact us, and may process technical device information and, depending on device settings, location information (metadata), even though they cannot view message content.

Information on legal bases: Where we ask communication partners for permission before using a messaging service, consent is the basis for processing their data. Otherwise, for example when they contact us on their own initiative, we use messaging services with contractual partners and when initiating contracts as a contractual measure. For other prospective customers and communication partners, we rely on our legitimate interests in quick, efficient communication and meeting their preferences for messaging. We do not initially transmit contact data provided to us to messaging services without your consent.

Withdrawal, objection and deletion: You may withdraw consent and object to communication through messaging services at any time. We delete messages in accordance with our general deletion policies, for example after contractual relationships end and subject to archiving requirements, or once we can assume enquiries have been answered, no reference to an earlier conversation is expected and no statutory retention obligations prevent deletion.

Reservation of the right to refer to other communication channels: For your security, we reserve the right not to respond through messaging services, for example where contractual information requires particular confidentiality or a response through messaging would not meet formal requirements. In such cases, we refer you to more appropriate channels.

  • Types of data processed: Contact data (such as postal and email addresses or telephone numbers); usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved).
  • Data subjects: Communication partners.
  • Purposes of processing: Contact enquiries and communication; direct marketing, for example by email or post.
  • Legal bases: Consent (Article 6(1)(a) GDPR); legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

We offer online chats and chatbot functions as communication options (collectively “chat services”). A chat is an online conversation conducted with relatively short delays. A chatbot is software that answers users’ questions or informs them through messages. When you use our chat functions, we may process your personal data.

If you use our chat services within an online platform, your identification number on that platform is also stored. We may collect information about which users interact with our chat services and when. We also store conversation content and log registration and consent processes to demonstrate them as required by law.

The platform provider may learn that and when users communicate with our chat services, and may collect technical device information and, depending on device settings, location information (metadata) for service optimisation and security. Platform providers may also use chat communication metadata, such as who communicated with whom, for marketing or personalised advertising under their own terms, which we refer to for further information.

Users who agree to receive regular messages from a chatbot can unsubscribe at any time. The chatbot explains how and which terms to use to unsubscribe. Once messages are unsubscribed from, user data is deleted from the list of message recipients.

We use this information to operate our chat services, for example to address users personally, answer questions, transmit requested content and improve the services, such as teaching chatbots answers to frequently asked questions or identifying unanswered enquiries.

Information on legal bases: We use chat services on the basis of consent where we previously obtained users’ permission to process their data through those services, for example when a chatbot sends regular messages. Where chat services answer questions about our services or business, they form part of contractual and pre-contractual communication. Otherwise, we use them on the basis of our legitimate interests in optimising chat services, economic efficiency and a positive user experience.

Withdrawal, objection and deletion: You may withdraw consent or object to processing of your data through our chat services at any time.

  • Types of data processed: Contact data (such as postal and email addresses or telephone numbers); content data (such as text or image messages and posts, and related information including authorship or creation time); usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved).
  • Data subjects: Communication partners; users (such as website visitors and online service users); business and contractual partners.
  • Purposes of processing: Contact enquiries and communication; direct marketing, for example by email or post; contractual services and obligations; marketing; provision of our online services and user-friendliness.
  • Legal bases: Consent (Article 6(1)(a) GDPR); performance of a contract and pre-contractual enquiries (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • 3CX: Chat functions, video and audio conferences; Service provider: 3CX GmbH, Walter-Gieseking-Straße 22, 30519 Hannover, Germany; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://www.3cx.de/. Privacy policy: https://www.3cx.com/company/privacy/.

We use other providers’ platforms and applications (“conference platforms”) for video and audio conferences, webinars and other video or audio meetings (collectively “conferences”). We observe legal requirements when selecting platforms and their services.

Data processed by conference platforms: Conference platforms process participants’ personal data as described below. The extent depends on data required for a particular conference, such as access credentials or real names, and optional information participants provide. Besides running the conference, platforms may process participant data for security or service optimisation. Data includes names, email addresses, telephone numbers, access codes or passwords, profile pictures, professional positions or roles, IP addresses, device details, operating systems, browser and technical and language settings, communication information such as chat entries and audio and video data, and use of other functions such as surveys. Communication content is encrypted to the extent technically provided by the platform. Registered users may have further data processed under their agreement with the conference provider.

Logging and recordings: Where text entries, participation results such as surveys, or video or audio are recorded, participants are informed transparently in advance and asked for consent where required.

Participants’ data protection measures: Please consult the conference platforms’ privacy notices for processing details and select the security and privacy settings that suit you best. During video conferences, protect personal data and privacy in the background of your recording, for example by informing housemates, locking doors or using background blurring where available. Do not share conference links or credentials with unauthorised third parties.

Information on legal bases: Where we process user data in addition to conference platforms and ask users for consent to use platforms or particular functions, such as conference recording, consent is the legal basis. Processing may also be necessary to fulfil contractual obligations, for example participant lists or follow-up of discussion results. Otherwise, user data is processed on the basis of our legitimate interests in efficient, secure communication with our communication partners.

  • Types of data processed: Master data (such as full name, residential address, contact information and customer number); contact data (such as postal and email addresses or telephone numbers); content data (such as text or image messages and posts, and related information including authorship or creation time); usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved).
  • Data subjects: Communication partners; users (such as website visitors and online service users); persons depicted; business and contractual partners.
  • Purposes of processing: Contractual services and obligations; contact enquiries and communication; office and organisational procedures; marketing; provision of our online services and user-friendliness.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • 3CX: Chat functions, video and audio conferences; Service provider: 3CX GmbH, Walter-Gieseking-Straße 22, 30519 Hannover, Germany; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://www.3cx.de/. Privacy policy: https://www.3cx.com/company/privacy/.

We use software services accessible through the internet and running on providers’ servers (“cloud services” or “software as a service”) to store and manage content, such as document storage and management, exchange of documents, content and information with particular recipients, or publication of content and information.

Personal data may be processed and stored on providers’ servers where it forms part of communication with us or is otherwise processed as described in this policy. It may include users’ master and contact data, transactions, contracts, other processes and their content. Cloud providers also process usage data and metadata for security and service optimisation.

Where cloud services provide forms, other documents or content to other users or on publicly accessible websites, providers may store cookies on users’ devices for web analytics or to remember settings, such as media controls.

  • Types of data processed: Master data (such as full name, residential address, contact information and customer number); contact data (such as postal and email addresses or telephone numbers); content data (such as text or image messages and posts, and related information including authorship or creation time); usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved).
  • Data subjects: Customers; employees (including staff, applicants, temporary workers and other personnel); prospective customers; communication partners; users (such as website visitors and online service users).
  • Purposes of processing: Office and organisational procedures; IT infrastructure (operation and provision of information systems and technical equipment such as computers and servers); provision of our online services and user-friendliness.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Nextcloud (hosted on our own server): Cloud storage operated on a server we manage, where processed data is stored; Service provider: Nextcloud GmbH, Hauptmannsreute 44a, 70192 Stuttgart, Germany; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://nextcloud.com/de/. Privacy policy: https://nextcloud.com/de/privacy/.
  • Provision of online services on our own or dedicated server hardware: We provide our online services using server hardware we operate, together with the associated storage, computing capacity and software; Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

We maintain profiles on social networks and process user data to communicate with people active there or provide information about us.

User data may be processed outside the European Union. This may create risks, for example making it harder to enforce user rights.

Social networks generally process user data for market research and advertising. Usage behaviour and resulting interests may be used to create profiles, which may then be used to display advertising inside and outside the networks presumed to match users’ interests. Cookies are therefore generally stored on users’ computers to record behaviour and interests. Profiles may also store data independently of the devices users employ, particularly when they are registered members and logged in.

For detailed descriptions of processing and opt-out options, please refer to the relevant networks’ privacy policies and operator information.

Requests for information and other data subject rights are most effectively addressed to providers, as only they have direct access to user data and can take measures or provide information. You may still contact us if you need assistance.

  • Types of data processed: Contact data (such as postal and email addresses or telephone numbers); content data (such as text or image messages and posts, and related information including authorship or creation time); usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved).
  • Data subjects: Users (such as website visitors and online service users).
  • Purposes of processing: Contact enquiries and communication; feedback, such as collection through online forms; marketing.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Instagram: Social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://www.instagram.com; Privacy policy: https://instagram.com/about/legal/privacy. Basis for transfers to third countries: Data Privacy Framework (DPF).
  • Facebook pages: Profiles within the Facebook social network; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/about/privacy; Basis for transfers to third countries: Data Privacy Framework (DPF); Further information: We are jointly responsible with Meta Platforms Ireland Limited for collecting, but not further processing, visitors’ data on our Facebook page (“fan page”). This includes content users view or interact with and actions they take (see the section on things you and others do and provide in Facebook’s data policy: https://www.facebook.com/policy), and information about devices used, such as IP addresses, operating systems, browser types, language settings and cookie data (see device information in Facebook’s data policy: https://www.facebook.com/policy). As explained in the policy’s section on how information is used, Facebook collects and uses information to provide analytics known as Page Insights, helping page operators understand interactions with their pages and related content. We have concluded a special agreement with Facebook on Page Insights (https://www.facebook.com/legal/terms/page_controller_addendum), specifying security measures Facebook must observe and its agreement to fulfil data subject rights, so users can, for example, send access or deletion requests directly to Facebook. Agreements with Facebook do not restrict users’ rights, particularly access, erasure, objection and complaints to the competent supervisory authority. Further information is available in the Page Insights information (https://www.facebook.com/legal/terms/information_about_page_insights_data). Joint responsibility is limited to collection by and transfer to Meta Platforms Ireland Limited, an EU-based company. Further processing is solely Meta Platforms Ireland Limited’s responsibility, including transfers to its US parent company Meta Platforms, Inc.
  • LinkedIn: Social network; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Website: https://www.linkedin.com; Privacy policy: https://www.linkedin.com/legal/privacy-policy; Basis for transfers to third countries: Data Privacy Framework (DPF); Opt-out option: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out. Further information: We are jointly responsible with LinkedIn Ireland Unlimited Company for collecting, but not further processing, visitors’ data used to create Page Insights statistics for our LinkedIn profiles. Data includes content users view or interact with, their actions, device information such as IP addresses, operating systems, browser types, language settings and cookie data, and profile information such as job function, country, industry, seniority, company size and employment status. LinkedIn’s processing is described in its privacy notice: https://www.linkedin.com/legal/privacy-policy We have concluded a special agreement with LinkedIn Ireland, the Page Insights Joint Controller Addendum (https://legal.linkedin.com/pages-joint-controller-addendum), specifying security measures LinkedIn must observe and its agreement to fulfil data subject rights, so users can, for example, send access or deletion requests directly to LinkedIn. Agreements with LinkedIn do not restrict users’ rights, particularly access, erasure, objection and complaints to the competent supervisory authority. Joint responsibility is limited to collection by and transfer to Ireland Unlimited Company, an EU-based company. Further processing is solely Ireland Unlimited Company’s responsibility, including transfers to its US parent company LinkedIn Corporation.

We embed functions and content in our online services that are obtained from the servers of their respective providers (“third-party providers”). These may include graphics, videos or maps (collectively “content”).

Embedding content always requires providers to process users’ IP addresses, as they could not send content to browsers without them. The IP address is therefore necessary to display content or functions. We seek to use only content whose providers use IP addresses solely for delivery. Providers may also use pixel tags, invisible graphics also known as web beacons, for statistics or marketing. These can evaluate information such as traffic on this website. Pseudonymous information may be stored in cookies on users’ devices, including technical browser and operating system information, referring websites, visit times and other usage details, and may be combined with information from other sources.

Information on legal bases: Where we ask users to consent to third-party services, consent is the basis for processing. Otherwise, user data is processed on the basis of our legitimate interests in efficient, economical and recipient-friendly services. Please also see this policy’s information on cookies.

  • Types of data processed: Usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved); location data (geographical positions of devices or persons).
  • Data subjects: Users (such as website visitors and online service users).
  • Purposes of processing: Provision of our online services and user-friendliness.
  • Legal bases: Consent (Article 6(1)(a) GDPR).

Further information on processing operations, procedures and services:

  • Google Maps: We embed maps from Google Maps. Processed data may include users’ IP addresses and location data; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal bases: Consent (Article 6(1)(a) GDPR); Website:  https://mapsplatform.google.com/; Privacy policy: https://policies.google.com/privacy. Basis for transfers to third countries: Data Privacy Framework (DPF).
  • Google Maps APIs and SDKs: Interfaces to Google’s map and location services, enabling functions such as address completion, location detection, distance calculation or supplementary information about sites and other places; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal bases: Consent (Article 6(1)(a) GDPR); Website:  https://mapsplatform.google.com/; Privacy policy: https://policies.google.com/privacy. Basis for transfers to third countries: Data Privacy Framework (DPF).

We use third-party services, platforms and software for organisation, administration, planning and provision of our services. We observe legal requirements when selecting providers and services.

Personal data may be processed and stored on third-party servers. This may involve various data processed under this policy, particularly users’ master and contact data, transactions, contracts, other processes and their content.

Where users are referred to third-party software or platforms during communication, business or other relationships with us, providers may process usage data and metadata for security, service optimisation or marketing. Please consult their respective privacy notices.

  • Types of data processed: Content data (such as text or image messages and posts, and related information including authorship or creation time); usage data (such as page views and visit duration, click paths, frequency and intensity of use, device types and operating systems, and interactions with content and functions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved).
  • Data subjects: Communication partners; users (such as website visitors and online service users); third parties.
  • Purposes of processing: Provision of contractual services and fulfilment of obligations; office and organisational procedures.
  • Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

Recruitment requires applicants to provide data needed for assessment and selection. Required information is set out in the job description or, for online forms, in the form itself.

Required information generally includes personal details such as name, address and contact details, plus evidence of qualifications needed for the position. We are happy to explain which information is required on request.

Where available, applicants can submit applications through an online form. Data is transmitted to us using state-of-the-art encryption. Applications can also be sent by email, but email is generally not encrypted throughout its journey on the internet. Emails are usually encrypted in transit, but not on the servers from which they are sent or received. We therefore cannot assume responsibility for transmission between the sender and receipt on our server.

We may use third-party applicant management or recruitment software, platforms and services to search for applicants, receive applications and select candidates, in compliance with legal requirements.

Applicants are welcome to contact us about submission methods or send applications by post.

Processing special categories of data: Where special categories of personal data under Article 9(1) GDPR, such as health data including severe disability or ethnic origin, are requested or provided during recruitment, they are processed so that the controller or data subject can exercise rights and meet obligations under employment, social security and social protection law; to protect applicants’ or others’ vital interests; or for preventive or occupational medicine, assessment of working capacity, medical diagnosis, health or social care or treatment, or management of health or social care systems and services.

Deletion of data: Following a successful application, we may continue processing applicant data for the employment relationship. Otherwise, data is deleted if an application is unsuccessful or withdrawn, which applicants may do at any time. Subject to a justified withdrawal request, deletion occurs no later than six months afterwards, allowing us to answer follow-up questions and meet evidentiary obligations concerning equal treatment of applicants. Invoices for any travel expense reimbursement are archived under tax requirements.

Inclusion in an applicant pool: Inclusion in an applicant pool, where offered, is based on consent. Applicants are informed that consent is voluntary, does not affect the ongoing application process and may be withdrawn at any time with future effect.

  • Types of data processed: Master data (such as full name, residential address, contact information and customer number); contact data (such as postal and email addresses or telephone numbers); content data (such as text or image messages and posts, authorship and creation time); applicant data (such as personal details, postal and contact addresses, application documents and their information, including cover letters, CVs, certificates and other information on the person or qualifications relevant to a position or provided voluntarily); payment data (such as bank details, invoices and payment history); contract data (such as subject matter, duration and customer category); usage data (such as page views and visit duration, click paths, frequency and intensity of use, devices, operating systems and interactions); metadata, communication and procedural data (such as IP addresses, times, identification numbers and persons involved).
  • Data subjects: Applicants; customers; prospective customers; business and contractual partners.
  • Purposes of processing: Recruitment (establishing, subsequently conducting and potentially ending an employment relationship); contractual services and obligations; conversion measurement (measuring marketing effectiveness); marketing; provision of our online services and user-friendliness.
  • Legal bases: Recruitment as a pre-contractual or contractual relationship (Article 6(1)(b) GDPR); legitimate interests (Article 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

Please review our privacy policy regularly. We update it whenever changes to our processing make this necessary. We notify you if changes require your participation, such as consent, or other individual notification.

Company and organisation addresses and contact details in this policy may change over time. Please check them before making contact.

This section explains terms used in this policy. Where terms are legally defined, their legal definitions apply. The explanations below primarily support understanding.

  • Employees: Employees are persons in an employment relationship, whether as workers, salaried staff or in similar positions. An employment relationship is a legal relationship between employer and employee established by contract or agreement. The employer must pay remuneration while the employee provides work. It includes establishment, when the contract is concluded; performance, when work is carried out; and termination, whether by notice, termination agreement or otherwise. Employee data means information relating to these persons in the context of employment, including personal identification data, identification numbers, salary and bank data, working hours, leave entitlements, health data and performance assessments.
  • Master data: Master data is essential information for identifying and managing contractual partners, user accounts, profiles and similar relationships. It may include personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), birth dates and identifiers such as user IDs. Master data forms the basis of formal interactions between people and services, institutions or systems by enabling clear identification and communication.
  • Credit information: Automated decisions result from automatic data processing without human involvement, such as refusing payment on invoice, online loan applications or online recruitment processes without human intervention. Under Article 22 GDPR, these decisions are permitted only with the data subject’s consent, where necessary to perform a contract or where national law allows them.
  • Content data: Content data is information generated when creating, editing and publishing content of any kind. It may include text, images, video, audio and other multimedia published across platforms and media. It includes not only the content itself but also metadata describing it, such as tags, descriptions, author information and publication dates.
  • Contact data: Contact data is essential information enabling communication with individuals or organisations. It includes telephone numbers, postal and email addresses, social media handles and instant messaging identifiers.
  • Conversion measurement: Conversion measurement evaluates the effectiveness of marketing activity. It generally involves storing a cookie on users’ devices on websites where marketing takes place and retrieving it on the target website. This can show, for example, whether our advertisements on other websites were successful.
  • Metadata, communication and procedural data: These categories describe how data is processed, transmitted and managed. Metadata, or data about data, describes other data’s context, origin and structure, including file size, creation date, author and change history. Communication data records exchanges through channels such as email, calls, social media and chats, including participants, timestamps and transmission routes. Procedural data describes processes within systems or organisations, including workflow documentation, transaction and activity records, and audit logs used to trace and review operations.
  • Usage data: Usage data records how people interact with digital products, services or platforms. It covers how applications are used, preferred functions, time spent on pages and navigation paths. It may include frequency, activity timestamps, IP addresses, device and location information. It is particularly useful for analysing behaviour, improving user experiences, personalising content and enhancing products or services. It also helps identify trends, preferences and possible problems within digital services.
  • Personal data: Personal data means information relating to an identified or identifiable individual (“data subject”). An individual is identifiable when they can be identified directly or indirectly, particularly through a name, identification number, location data, online identifier such as a cookie, or characteristics of their physical, physiological, genetic, mental, economic, cultural or social identity.
  • Location data: Location data arises when a mobile device, or another device capable of locating itself, connects to a cell tower, Wi-Fi network or similar positioning technology. It indicates the device’s geographical position and may be used to display maps or other location-dependent information.
  • Controller: The controller is the individual, legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes and means of processing personal data.
  • Processing: Processing means an operation or series of operations involving personal data, with or without automated means. The term is broad and covers virtually any handling of data, including collection, analysis, storage, transmission and deletion.
  • Contract data: Contract data concerns formalising agreements between two or more parties. It records the terms under which services or products are provided, exchanged or sold. Essential for managing and fulfilling contractual obligations, it includes the parties’ identification and specific terms and conditions: start and end dates, services or products, prices, payment terms, termination rights, renewal options and special clauses. It provides the legal basis for relationships between parties and helps clarify rights and obligations, enforce claims and resolve disputes.
  • Payment data: Payment data includes information needed to process transactions between buyers and sellers. It is essential in e-commerce, online banking and other financial transactions. It includes card numbers, bank details, payment amounts, transaction dates, verification numbers and invoice information, and may include payment status, chargebacks, authorisations and fees.