Privacy Policy
This is a courtesy translation. The German version of this document is the legally binding one. In case of any discrepancy, the German text prevails.
View German version ›How do we collect your data?
Your data is collected in part because you provide it to us. This may be data you enter into a contact form, for example.
Other data is collected automatically or with your consent by our IT systems when you visit the website. This is mainly technical data (e.g., internet browser, operating system, or the time the page was accessed). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Part of the data is collected to ensure the website is provided without errors. Other data may be used to analyse your user behaviour. Where contracts can be concluded or initiated via the website, the transmitted data is also processed for contract offers, orders, or other enquiries.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients, and purpose of your stored personal data. You also have a right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this consent at any time with effect for the future. You also have the right, under certain circumstances, to request that the processing of your personal data be restricted. Furthermore, you have a right to lodge a complaint with the competent supervisory authority.
You can contact us at any time regarding this and any other questions about data protection.
Analytics tools and third-party tools
When you visit this website, your browsing behaviour may be analysed statistically. This is done mainly using so-called analytics programs.
Detailed information about these analytics programs can be found in the privacy policy below.
2. Hosting
We host the content of our website with the following provider:
Alfahosting
The provider is Alfahosting GmbH, Ankerstraße 3b, 06108 Halle (Saale) (hereinafter Alfahosting). When you visit our website, Alfahosting records various log files including your IP addresses.
For details, please refer to Alfahosting's privacy policy: https://alfahosting.de/datenschutz/.
Alfahosting is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g., for device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Order processing
We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract required by data protection law, ensuring that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
3. General information and mandatory disclosures
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
When you use this website, various items of personal data are collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the internet (e.g., communication by email) may have security gaps. Complete protection of data against access by third parties is not possible.
Information about the controller
The controller for data processing on this website is:
KAW Kiel Academy für Wirtschaft UG (haftungsbeschränkt)
Von-der-Goltz-Allee 65
24113 Kiel
Phone: 0431 – 79 94 92 08
Email: info@kielacademy.de
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data (e.g., names, email addresses, etc.).
Storage period
Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose for processing it no longer applies. If you assert a justified request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible grounds for storing your personal data (e.g., retention periods under tax or commercial law); in the latter case, deletion takes place once these grounds no longer apply.
General information on the legal bases for data processing on this website
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, where special categories of data pursuant to Art. 9(1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is additionally carried out on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g., via device fingerprinting), data processing is additionally based on Section 25(1) TDDDG. Consent can be withdrawn at any time. If your data is required for the performance of a contract or for pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we process your data where it is necessary for compliance with a legal obligation, on the basis of Art. 6(1)(c) GDPR. Data processing may also be based on our legitimate interest pursuant to Art. 6(1)(f) GDPR. The legal bases relevant in each individual case are set out in the following paragraphs of this privacy policy.
Information on data transfer to third countries that are not secure under data protection law, and on transfers to US companies that are not DPF-certified
Among other things, we use tools from companies based in third countries that are not secure under data protection law, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in these countries. We point out that in third countries that are not secure under data protection law, a level of data protection comparable to that of the EU cannot be guaranteed.
We point out that the USA, as a secure third country, generally offers a level of data protection comparable to that of the EU. A transfer of data to the USA is therefore permissible if the recipient holds a certification under the “EU-US Data Privacy Framework” (DPF) or has suitable additional safeguards in place. Information on transfers to third countries, including the data recipients, can be found in this privacy policy.
Recipients of personal data
In the course of our business activities, we work with various external parties. This sometimes also requires the transfer of personal data to these external parties. We only pass on personal data to external parties where this is necessary for the performance of a contract, where we are legally obliged to do so (e.g., transfer of data to tax authorities), where we have a legitimate interest in the transfer pursuant to Art. 6(1)(f) GDPR, or where another legal basis permits the data transfer. Where processors are used, we pass on our customers' personal data only on the basis of a valid data processing agreement. In the case of joint processing, a joint controllership agreement is concluded.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out up to the point of withdrawal remains unaffected.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE, OR DEFENCE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement. This right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
Information, correction, and deletion
Within the framework of the applicable statutory provisions, you have the right at any time to obtain free information about your stored personal data, its origin and recipients, and the purpose of the data processing, and, where applicable, a right to correction or deletion of this data. You can contact us at any time regarding this and any other questions about personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time to do so. The right to restriction of processing applies in the following cases:
- If you dispute the accuracy of the personal data we hold about you, we generally need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was or is unlawful, you may request the restriction of data processing instead of deletion.
- If we no longer need your personal data but you require it to exercise, defend, or establish legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection pursuant to Art. 21(1) GDPR, a balance must be struck between your interests and ours. As long as it has not been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may — apart from being stored — only be processed with your consent or for the establishment, exercise, or defence of legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us as the site operator, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the browser's address bar changes from “http://” to “https://” and by the padlock symbol in your browser bar.
When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.
Encrypted payment transactions on this website
If, after concluding a contract subject to a charge, there is an obligation to transmit your payment data (e.g., account number for direct debit) to us, this data is required for payment processing.
Payment transactions using common payment methods (Visa/MasterCard, direct debit) are carried out exclusively via an encrypted SSL or TLS connection. You can recognise an encrypted connection by the fact that the browser's address bar changes from “http://” to “https://” and by the padlock symbol in your browser bar.
With encrypted communication, the payment data you transmit to us cannot be read by third parties.
Objection to advertising emails
We hereby object to the use of contact data published as part of our legal notice obligations for the purpose of sending unsolicited advertising and information materials. The operators of these pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam emails.
4. Data collection on this website
Cookies
Our website uses so-called “cookies”. Cookies are small data packages and do no harm to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are deleted automatically at the end of your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.
Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g., cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies may be used to analyse user behaviour or for advertising purposes.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions you have requested (e.g., for the shopping cart function), or to optimise the website (e.g., cookies for measuring the web audience) (necessary cookies) are stored on the basis of Art. 6(1)(f) GDPR, unless another legal basis is stated. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimised provision of its services. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of that consent (Art. 6(1)(a) GDPR and Section 25(1) TDDDG); consent can be withdrawn at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.
You can find out which cookies and services are used on this website in this privacy policy.
Consent management with Usercentrics
This website uses the consent technology of Usercentrics to obtain your consent to the storage of certain cookies on your device or to the use of certain technologies, and to document this in compliance with data protection law. The provider of this technology is Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, website: https://usercentrics.com/de/ (hereinafter “Usercentrics”).
When you enter our website, the following personal data is transmitted to Usercentrics:
- Your consent(s) or the withdrawal of your consent(s)
- Your IP address
- Information about your browser
- Information about your device
- The time of your visit to the website
- Geolocation
Usercentrics also stores a cookie in your browser in order to assign the consents granted or their withdrawal to you. The data collected in this way is stored until you ask us to delete it, until you delete the Usercentrics cookie yourself, or until the purpose for data storage no longer applies. Mandatory statutory retention obligations remain unaffected.
The Usercentrics banner on this website was configured with the help of eRecht24. You can recognise this by the eRecht24 logo appearing in the banner. In order to display the eRecht24 logo in the banner, a connection is established to the eRecht24 image server. The IP address is also transmitted in this process, but is stored in the server logs only in anonymised form. The eRecht24 image server is located in Germany with a German provider. The banner itself is provided exclusively by Usercentrics.
Usercentrics is used in order to obtain the legally required consents for the use of certain technologies. The legal basis for this is Art. 6(1)(c) GDPR.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
This data is not merged with other data sources.
This data is collected on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website — for this purpose, the server log files must be recorded.
Contact form
If you send us enquiries via the contact form, your details from the enquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR, where your enquiry is connected with the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) where this has been requested; consent can be withdrawn at any time.
The data you enter in the contact form remains with us until you ask us to delete it, withdraw your consent to storage, or the purpose for data storage no longer applies (e.g., after your enquiry has been dealt with). Mandatory statutory provisions — in particular retention periods — remain unaffected.
Use of artificial intelligence (AI) to respond to customer enquiries
We use AI-supported software to process and respond to customer enquiries. The AI we use analyses the content of your message in order to generate a suitable response or a suggested response, autonomously or partly autonomously. In this context, our AI processes all contents of your message, including names, email addresses, communication content, or technical information (e.g., IP addresses, device information).
The AI software is used on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in the most efficient customer communication possible using modern technical solutions.
We use the following AI applications:
ChatGPT
We use ChatGPT for our customer communication. The provider is OpenAI, 3180 18th St, San Francisco, CA 94110, USA, https://openai.com. When you contact us, your enquiries including metadata may therefore be transmitted to and processed on ChatGPT's servers in order to generate a suitable response.
We have configured ChatGPT so that the data we forward to ChatGPT is not used to train the ChatGPT algorithm.
You can find further information here: https://openai.com/policies/privacy-policy.
Enquiries by email, telephone, or fax
If you contact us by email, telephone, or fax, your enquiry including all resulting personal data (name, enquiry) will be stored and processed by us for the purpose of handling your request. We do not pass on this data without your consent.
This data is processed on the basis of Art. 6(1)(b) GDPR, where your enquiry is connected with the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) where this has been requested; consent can be withdrawn at any time.
The data you send us via contact enquiries remains with us until you ask us to delete it, withdraw your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been dealt with). Mandatory statutory provisions — in particular statutory retention periods — remain unaffected.
Communication via WhatsApp
Among other things, we use the instant messaging service WhatsApp to communicate with our customers and other third parties. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
Communication takes place via end-to-end encryption (peer-to-peer), which prevents WhatsApp or other third parties from gaining access to the communication content. However, WhatsApp does receive access to metadata generated in the course of the communication process (e.g., sender, recipient, and time). We also point out that, according to its own statement, WhatsApp shares personal data of its users with its US-based parent company Meta. Further details on data processing can be found in WhatsApp's privacy policy at: https://www.whatsapp.com/legal/#privacy-policy.
WhatsApp is used on the basis of our legitimate interest in the fastest and most effective communication possible with customers, prospective customers, and other business and contractual partners (Art. 6(1)(f) GDPR). Where corresponding consent has been requested, data processing is carried out exclusively on the basis of that consent; it can be withdrawn at any time with effect for the future.
The communication content exchanged between you and us on WhatsApp remains with us until you ask us to delete it, withdraw your consent to storage, or the purpose for data storage no longer applies (e.g., after your enquiry has been dealt with). Mandatory statutory provisions — in particular retention periods — remain unaffected.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/7735.
We use WhatsApp in the “WhatsApp Business” variant.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://www.whatsapp.com/legal/business-data-transfer-addendum.
We have configured our WhatsApp accounts so that there is no automatic data synchronisation with the address book on the smartphones in use.
Use of chatbots
We use chatbots to communicate with you. Chatbots are able to respond to your questions and other input without human assistance. To do so, in addition to your input, the chatbots analyse further data in order to give suitable answers (e.g., names, email addresses and other contact data, customer numbers and other identifiers, orders, and chat histories). The chatbot may also record your IP address, log files, location information, and other metadata. This data is stored on the servers of the chatbot provider.
User profiles may be created on the basis of the data collected. The data may also be used to display interest-based advertising, provided the other legal requirements (in particular consent) are met. For this purpose, the chatbots can be linked to analytics and advertising tools.
The data collected may also be used to improve our chatbots and their response behaviour (machine learning).
The data you enter in the course of communication remains with us or the chatbot operator until you ask us to delete it, withdraw your consent to storage, or the purpose for data storage no longer applies (e.g., after your enquiry has been dealt with). Mandatory statutory provisions — in particular retention periods — remain unaffected.
The legal basis for the use of chatbots is Art. 6(1)(b) GDPR, where the chatbot is used to initiate a contract or in the course of performing a contract. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time. In all other cases, use is based on our legitimate interest in the most effective customer communication possible (Art. 6(1)(f) GDPR).
Use of AI applications in chatbot communication
Our chatbots use artificial intelligence (AI) in customer communication. The AI we use analyses the content of your message in order to generate a suitable response autonomously. In this context, the AI processes all contents of your message, including names, email addresses, communication content, or technical information (e.g., IP addresses, device information).
The AI software is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the most efficient customer communication possible using modern technical solutions. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time.
We integrate the following AI applications into our chatbots:
ChatGPT
Our chatbots use ChatGPT for our customer communication. The provider is OpenAI, 3180 18th St, San Francisco, CA 94110, USA, https://openai.com. When you contact us via the chatbot, your enquiries including metadata may therefore be transmitted to and processed on ChatGPT's servers in order to generate a suitable response.
We have configured ChatGPT so that the data we forward to ChatGPT is not used to train the ChatGPT algorithm.
You can find further information here: https://openai.com/policies/privacy-policy.
Google Calendar
On our website you have the option of arranging appointments with us. We use Google Calendar for scheduling. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter “Google”).
For the purpose of booking an appointment, you enter the requested data and your preferred date in the form provided. The data entered is used for planning, conducting, and, where applicable, following up on the appointment. The appointment data is stored for us on Google Calendar's servers; you can view its privacy policy here: https://policies.google.com/privacy.
The data you enter remains with us until you ask us to delete it, withdraw your consent to storage, or the purpose for data storage no longer applies. Mandatory statutory provisions — in particular retention periods — remain unaffected.
The legal basis for data processing is Art. 6(1)(f) GDPR. The website operator has a legitimate interest in arranging appointments with prospective customers and customers as easily as possible. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g., for device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://workspace.google.com/terms/dpa_terms.html and here https://cloud.google.com/terms/sccs.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Registration with Google
Instead of registering directly on this website, you can register with Google. The provider of this service is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
To register with Google, you only need to enter your Google name and your password. Google will identify you and confirm your identity to our website.
When you log in with Google, we may be able to use certain information from your account to complete your profile with us. You decide whether and which information this is within your Google security settings, which you can find here: https://myaccount.google.com/security and https://myaccount.google.com/permissions.
The data processing associated with registration via Google is based on our legitimate interest in enabling the simplest possible registration process for our users (Art. 6(1)(f) GDPR). As use of the registration function is voluntary and users can decide on the respective access options themselves, no overriding rights of data subjects are apparent.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
5. Social media
This website incorporates elements of the social network Facebook. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. According to Facebook, however, the data collected is also transferred to the USA and to other third countries.
You can find an overview of the Facebook social media elements here: https://developers.facebook.com/docs/plugins/?locale=de_DE.
When the social media element is active, a direct connection is established between your device and the Facebook server. Facebook thereby receives the information that you have visited this website with your IP address. If you click the Facebook “Like” button while logged into your Facebook account, you can link the content of this website to your Facebook profile. This allows Facebook to associate your visit to this website with your user account. We point out that, as the provider of these pages, we have no knowledge of the content of the transmitted data or its use by Facebook. Further information on this can be found in Facebook's privacy policy at: https://de-de.facebook.com/privacy/explanation.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). Joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook. The processing carried out by Facebook after the transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. You can find the wording of the agreement at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook tool and for the data-protection-compliant implementation of the tool on our website. Facebook is responsible for the data security of the Facebook products. You can assert data subject rights (e.g., requests for information) regarding the data processed by Facebook directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://de-de.facebook.com/help/566994660333381 and https://www.facebook.com/policy.php.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
This website incorporates functions of the Instagram service. These functions are offered by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your device and the Instagram server. Instagram thereby receives information about your visit to this website.
If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. We point out that, as the provider of these pages, we have no knowledge of the content of the transmitted data or its use by Instagram.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland are jointly responsible for this data processing (Art. 26 GDPR). Joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook or Instagram. The processing carried out by Facebook or Instagram after the transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement. You can find the wording of the agreement at: https://www.facebook.com/legal/controller_addendum. According to this agreement, we are responsible for providing the data protection information when using the Facebook or Instagram tool and for the data-protection-compliant implementation of the tool on our website. Facebook is responsible for the data security of the Facebook and Instagram products. You can assert data subject rights (e.g., requests for information) regarding the data processed by Facebook or Instagram directly with Facebook. If you assert data subject rights with us, we are obliged to forward them to Facebook.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://www.facebook.com/legal/EU_data_transfer_addendum, https://privacycenter.instagram.com/policy/ and https://de-de.facebook.com/help/566994660333381.
Further information on this can be found in Instagram's privacy policy: https://privacycenter.instagram.com/policy/.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452.
This website uses elements of the LinkedIn network. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.
Each time one of this website's pages containing LinkedIn elements is accessed, a connection to LinkedIn servers is established. LinkedIn is informed that you have visited this website with your IP address. If you click LinkedIn's “Recommend” button and are logged into your LinkedIn account, LinkedIn is able to associate your visit to this website with you and your user account. We point out that, as the provider of these pages, we have no knowledge of the content of the transmitted data or its use by LinkedIn.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://www.linkedin.com/help/linkedin/answer/a1343190/datenubertragung-aus-der-eu-dem-ewr-und-der-schweiz?lang=de
Further information on this can be found in LinkedIn's privacy policy at: https://www.linkedin.com/legal/privacy-policy.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/5448.
This website uses elements of the XING network. The provider is New Work SE, Am Strandkai 1, 20457 Hamburg, Germany.
Each time one of our pages containing XING elements is accessed, a connection to XING servers is established. To the best of our knowledge, no personal data is stored in the process. In particular, no IP addresses are stored and no usage behaviour is analysed.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time.
Further information on data protection and the XING share button can be found in XING's privacy policy at: https://privacy.xing.com/de/datenschutzerklaerung.
On this website we use elements of the social network Pinterest, which is operated by Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland.
When you access a page containing such an element, your browser establishes a direct connection to Pinterest's servers. In doing so, this social media element transmits log data to Pinterest's server in the USA. This log data may include your IP address, the address of the websites visited that also contain Pinterest functions, the type and settings of the browser, the date and time of the request, the way you use Pinterest, and cookies.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time.
Further information on the purpose, scope, and further processing and use of the data by Pinterest, as well as your related rights and options for protecting your privacy, can be found in Pinterest's privacy notices: https://policy.pinterest.com/de/privacy-policy.
6. Analytics tools and advertising
Google Tag Manager
We use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Tag Manager is a tool that allows us to integrate tracking or statistics tools and other technologies into our website. Google Tag Manager itself does not create user profiles, does not store cookies, and does not carry out any independent analyses. It merely serves to manage and deliver the tools integrated via it. However, Google Tag Manager does record your IP address, which may also be transferred to Google's parent company in the United States.
Google Tag Manager is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the fast and straightforward integration and management of various tools on its website. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google Ads
The website operator uses Google Ads. Google Ads is an online advertising program of Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads enables us to display advertisements in the Google search engine or on third-party websites when a user enters certain search terms on Google (keyword targeting). Targeted advertisements can also be displayed based on the user data available at Google (e.g., location data and interests) (audience targeting). As the website operator, we can evaluate this data quantitatively, for example by analysing which search terms led to our advertisements being displayed and how many advertisements resulted in corresponding clicks.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time.
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here: https://policies.google.com/privacy/frameworks and https://business.safety.google/controllerterms/.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
Google conversion tracking
This website uses Google conversion tracking. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
With the help of Google conversion tracking, Google and we can recognise whether the user has carried out certain actions. For example, we can evaluate which buttons on our website were clicked how often and which products were viewed or purchased particularly frequently. This information serves to create conversion statistics. We learn the total number of users who clicked on our ads and what actions they took. We do not receive any information that would allow us to identify the user personally. Google itself uses cookies or comparable recognition technologies for identification.
This service is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time.
You can find more information about Google conversion tracking in Google's privacy policy: https://policies.google.com/privacy?hl=de.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
7. Newsletter
Newsletter data
If you would like to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and that you consent to receiving the newsletter. No further data is collected, or only on a voluntary basis. We use this data exclusively to send the requested information and do not pass it on to third parties.
The data entered in the newsletter registration form is processed exclusively on the basis of your consent (Art. 6(1)(a) GDPR). You can withdraw your consent to the storage of the data and the email address, and to their use for sending the newsletter, at any time — for example via the “unsubscribe” link in the newsletter. The lawfulness of the data processing operations already carried out remains unaffected by the withdrawal.
The data you have deposited with us for the purpose of receiving the newsletter is stored by us or the newsletter service provider until you unsubscribe from the newsletter, and is deleted from the newsletter distribution list after you cancel the newsletter or once the purpose no longer applies. We reserve the right to delete or block email addresses from our newsletter distribution list at our own discretion within the scope of our legitimate interest pursuant to Art. 6(1)(f) GDPR.
Data stored with us for other purposes remains unaffected by this.
After you unsubscribe from the newsletter distribution list, your email address may be stored by us or the newsletter service provider on a blacklist, insofar as this is necessary to prevent future mailings. The data from the blacklist is used only for this purpose and is not merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Storage on the blacklist is not limited in time. You may object to the storage if your interests outweigh our legitimate interest.
Sending the newsletter to existing customers
If you order goods or services from us and provide your email address in the process, this email address may subsequently be used by us to send newsletters, provided we inform you of this in advance. In such a case, the newsletter will only be used to send direct advertising for our own similar goods or services. You can cancel the delivery of this newsletter at any time. A corresponding link can be found in every newsletter.
In this case, the legal basis for sending the newsletter is Art. 6(1)(f) GDPR in conjunction with Section 7(3) of the German Act Against Unfair Competition (UWG).
After you unsubscribe from the newsletter distribution list, your email address may be stored by us on a blacklist to prevent future mailings to you. The data from the blacklist is used only for this purpose and is not merged with other data. This serves both your interest and our interest in complying with legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6(1)(f) GDPR). Storage on the blacklist is not limited in time. You may object to the storage if your interests outweigh our legitimate interest.
8. Plugins and tools
Google reCAPTCHA
We use “Google reCAPTCHA” (hereinafter “reCAPTCHA”) on this website. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
The purpose of reCAPTCHA is to check whether data entered on this website (e.g., in a contact form) is being entered by a human or by an automated program. To do this, reCAPTCHA analyses the behaviour of the website visitor on the basis of various characteristics. This analysis begins automatically as soon as the website visitor enters the website. For the analysis, reCAPTCHA evaluates various items of information (e.g., IP address, how long the visitor spends on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to Google.
The reCAPTCHA analyses run entirely in the background. Website visitors are not informed that an analysis is taking place.
The data is stored and analysed on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its web offerings against abusive automated spying and against SPAM. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Further information on Google reCAPTCHA can be found in Google's privacy policy and terms of use at the following links:https://policies.google.com/privacy?hl=de andhttps://policies.google.com/terms?hl=de.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780.
hCaptcha
We use hCaptcha (hereinafter “hCaptcha”) on this website. The provider is Intuition Machines, Inc., 2211 Selig Drive, Los Angeles, CA 90026, USA (hereinafter “IMI”).
The purpose of hCaptcha is to check whether data entered on this website (e.g., in a contact form) is being entered by a human or by an automated program. To do this, hCaptcha analyses the behaviour of the website visitor on the basis of various characteristics.
This analysis begins automatically as soon as the website visitor enters a website with hCaptcha activated. For the analysis, hCaptcha evaluates various items of information (e.g., IP address, how long the visitor spends on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to IMI. If hCaptcha is used in “invisible mode”, the analyses run entirely in the background. Website visitors are not informed that an analysis is taking place.
The data is stored and analysed on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in protecting its web offerings against abusive automated spying and against SPAM. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
Data processing is based on standard contractual clauses contained in the data processing addendum to IMI's general terms and conditions or in the data processing agreements.
Further information on hCaptcha can be found in the privacy policy and terms of use at the following links:https://www.hcaptcha.com/privacy andhttps://hcaptcha.com/terms.
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/6388.
ChatGPT
We use ChatGPT on our website. The provider is OpenAI, 3180 18th St, San Francisco, CA 94110, USA,https://openai.com. We use ChatGPT as follows:
“Business version” of ChatGPT to answer customer enquiries
When you interact with content on our website in which ChatGPT is integrated (e.g., a chatbot), your input including metadata is transmitted to and processed on ChatGPT's servers in order to generate a suitable response.
We have configured ChatGPT so that the personal data entered is not used to train ChatGPT's algorithm.
ChatGPT is used on the basis of Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the most efficient customer communication possible using modern technical solutions. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Consent can be withdrawn at any time.
You can find further information here:https://openai.com/policies/privacy-policy.
9. Online marketing and partner programs
Affiliate programs on this website
We participate in affiliate partner programs. In affiliate partner programs, advertisements of one company are placed on websites or other media of other companies in the affiliate partner network. If you click on one of these affiliate advertisements, you are forwarded to the advertised offer. If you subsequently carry out a particular transaction (conversion), the affiliate and, where applicable, the owner of the medium on which the advertising is placed receive remuneration for this.
In order to calculate this remuneration, the affiliate network operator needs to be able to track which advertisement brought you to the respective offer and where you carried out the predefined transaction. Cookies or comparable recognition technologies (e.g., device fingerprinting) are used for this purpose.
The data is stored and analysed on the basis of Art. 6(1)(f) GDPR. The participants in the affiliate program have a legitimate interest in the correct calculation of affiliate remuneration. Where corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6(1)(a) GDPR and Section 25(1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.
We participate in the following affiliate programs:
Amazon partner program
The provider is Amazon Europe Core S.à.r.l. For details, please refer to Amazon's privacy policy at:https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010
The company holds a certification under the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the USA intended to ensure compliance with European data protection standards for data processing in the USA. Every company certified under the DPF undertakes to comply with these data protection standards. You can obtain further information from the provider at the following link: https://www.dataprivacyframework.gov/participant/5776.
10. eCommerce and payment providers
Processing of customer and contract data
We collect, process, and use personal customer and contract data for the purpose of establishing, structuring, and modifying our contractual relationships. We collect, process, and use personal data about the use of this website (usage data) only insofar as this is necessary to enable the user to use the service or to bill for it. The legal basis for this is Art. 6(1)(b) GDPR.
The customer data collected is deleted once the order has been completed or the business relationship has ended, and after any applicable statutory retention periods have expired. Statutory retention periods remain unaffected.
Data transfer upon conclusion of a contract for online shops, retailers, and shipping of goods
When you order goods from us, we pass on your personal data to the transport company commissioned with the delivery and to the payment service provider commissioned with processing the payment. Only such data is disclosed as the respective service provider needs to perform its task. The legal basis for this is Art. 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures. If you have given corresponding consent pursuant to Art. 6(1)(a) GDPR, we will pass on your email address to the transport company commissioned with the delivery so that it can inform you by email about the shipping status of your order; you can withdraw this consent at any time.
Data transfer upon conclusion of a contract for services and digital content
We transfer personal data to third parties only where this is necessary in the course of contract processing, for example to the credit institution commissioned with processing the payment.
No further transfer of data takes place, or only if you have expressly consented to the transfer. Your data will not be passed on to third parties without express consent, for example for advertising purposes.
The basis for data processing is Art. 6(1)(b) GDPR, which permits the processing of data for the performance of a contract or pre-contractual measures.
Payment services
We integrate payment services from third-party companies on our website. When you make a purchase from us, your payment data (e.g., name, payment amount, account details, credit card number) is processed by the payment service provider for the purpose of payment processing. The respective contractual and data protection provisions of the respective providers apply to these transactions. The payment service providers are used on the basis of Art. 6(1)(b) GDPR (contract processing) and in the interest of a payment process that is as smooth, convenient, and secure as possible (Art. 6(1)(f) GDPR). Insofar as your consent is requested for certain actions, Art. 6(1)(a) GDPR is the legal basis for data processing; consent can be withdrawn at any time with effect for the future.
We use the following payment services / payment service providers on this website:
PayPal
The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”).
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here:https://www.paypal.com/de/webapps/mpp/ua/pocpsa-full
For details, please refer to PayPal's privacy policy:https://www.paypal.com/de/webapps/mpp/ua/privacy-full
Apple Pay
The provider of this payment service is Apple Inc., Infinite Loop, Cupertino, CA 95014, USA. You can find Apple's privacy policy at:https://www.apple.com/legal/privacy/de-ww/
Google Pay
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. You can find Google's privacy policy here:https://policies.google.com/privacy
Stripe
The provider for customers within the EU is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter “Stripe”).
Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here:https://stripe.com/de/privacy andhttps://stripe.com/de/guides/general-data-protection-regulation
You can read details about this in Stripe's privacy policy at the following link:https://stripe.com/de/privacy
Klarna
The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter “Klarna”). Klarna offers various payment options (e.g., instalment purchase). If you choose to pay with Klarna (Klarna checkout solution), Klarna will collect various personal data from you.
Klarna uses cookies to optimise the use of the Klarna checkout solution. You can find details on the use of Klarna cookies at the following link:https://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf
You can read details about this in Klarna's privacy policy at the following link:https://www.klarna.com/de/datenschutz/
Paydirekt
The provider of this payment service is Paydirekt GmbH, Hamburger Allee 26-28, 60486 Frankfurt am Main, Germany (hereinafter “Paydirekt”).
If you make a payment using Paydirekt, Paydirekt collects various transaction data and forwards it to the bank with which you are registered with Paydirekt. In addition to the data required for the payment, Paydirekt may collect further data in the course of processing the transaction, such as the delivery address or individual items in the shopping cart. Paydirekt then authenticates the transaction using the authentication procedure stored for this purpose with the bank. The payment amount is then transferred from your account to our account. Neither we nor third parties have access to your account data.
For details on paying with Paydirekt, please refer to Paydirekt's terms and conditions and privacy provisions at:https://www.paydirekt.de/agb/index.html
Sofortüberweisung
The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter “Sofort GmbH”). With the help of the “Sofortüberweisung” procedure, we receive a payment confirmation from Sofort GmbH in real time and can begin fulfilling our obligations immediately.
If you have chosen the “Sofortüberweisung” payment method, you transmit the PIN and a valid TAN to Sofort GmbH, with which it can log into your online banking account. After logging in, Sofort GmbH automatically checks your account balance and carries out the transfer to us using the TAN you provided. It then immediately sends us a transaction confirmation. After logging in, your transactions, the credit limit of your overdraft facility, and the existence of other accounts and their balances are also checked automatically.
In addition to the PIN and the TAN, the payment data you enter and data about your person are also transmitted to Sofort GmbH. The data about your person consists of your first and last name, address, telephone number(s), email address, IP address, and, where applicable, further data required for payment processing. The transmission of this data is necessary in order to establish your identity beyond doubt and to prevent attempted fraud.
For details on paying with Sofortüberweisung, please refer to the following link:https://www.klarna.com/sofort/
Amazon Pay
The provider of this payment service is Amazon Payments Europe S.C.A., 38 avenue J.F. Kennedy, L-1855 Luxembourg. You can read details on how your data is handled in Amazon Pay's privacy policy at the following link:https://pay.amazon.de/help/201212490?ld=APDELPADirect
giropay
The provider of this payment service is paydirekt GmbH, Stephanstraße 14 – 16, 60313 Frankfurt am Main (hereinafter “giropay”). For details, please refer to giropay's privacy policy:https://www.paydirekt.de/agb/index.html
CopeCart
The provider of this payment service is CopeCart GmbH, Ufnaustraße 10, 10553 Berlin (hereinafter “CopeCart”). For details, please refer to CopeCart's privacy policy:https://www.copecart.com/de/datenschutz
Mastercard
The provider of this payment service is Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium (hereinafter “Mastercard”).
Mastercard may transfer data to its parent company in the USA. Data transfer to the USA is based on Mastercard's Binding Corporate Rules. You can find details here:https://www.mastercard.de/de-de/datenschutz.html andhttps://www.mastercard.us/content/dam/mccom/global/documents/mastercard-bcrs.pdf
VISA
The provider of this payment service is Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, United Kingdom (hereinafter “VISA”).
The United Kingdom is considered a third country that is secure under data protection law. This means that the United Kingdom has a level of data protection that corresponds to the level of data protection in the European Union.
VISA may transfer data to its parent company in the USA. Data transfer to the USA is based on the standard contractual clauses of the EU Commission. You can find details here:https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung/mitteilung-zu-zustandigkeitsfragen-fur-den-ewr.html
Further information can be found in VISA's privacy policy:https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html
Last updated: March 2025. If you have any questions about our privacy policy, please contact info@kielacademy.de.