We process user data in order to be able to provide them with our online services. For this purpose, we process the IP address of the user, which is necessary to transmit the content and functions of our online services to the user's browser or terminal device.
Processed data types: Usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, types of devices and operating systems used, interactions with content and features); Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, involved parties); Log data (e.g. log files concerning logins or data retrieval or access times.). Content data (e.g. textual or pictorial messages and contributions, as well as information pertaining to them, such as details of authorship or the time of creation.).
Data subjects: Users (e.g. website visitors, users of online services). Business and contractual partners.
Purposes of processing: Provision of our online services and usability; Information technology infrastructure (Operation and provision of information systems and technical devices, such as computers, servers, etc.).); Security measures; Content Delivery Network (CDN). Office and organisational procedures.
Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Retention and Deletion". Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Further information on processing methods, procedures and services used:
Provision of online offer on rented hosting space: For the provision of our online services, we use storage space, computing capacity and software that we rent or otherwise obtain from a corresponding server provider (also referred to as a "web hoster"); Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Collection of Access Data and Log Files:
Access to our online service is logged in the form of so-called "server log files". Server log files may include the address and name of the accessed web pages and files, date and time of access, transferred data volumes, notification of successful retrieval, browser type along with version, the user's operating system, referrer URL (the previously visited page), and typically IP addresses and the requesting provider. The server log files can be used for security purposes, e.g., to prevent server overload (especially in the case of abusive attacks, known as DDoS attacks), and to ensure server load management and stability; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR). Retention period: Log file information is stored for a maximum period of 30 days and then deleted or anonymized. Data, the further storage of which is necessary for evidence purposes, are excluded from deletion until the respective incident has been finally clarified.
Content-Delivery-Network:
We use a so-called "Content Delivery Network" (CDN). A CDN is a service with whose help contents of our online services, in particular large media files, such as graphics or scripts, can be delivered faster and more securely with the help of regionally distributed servers connected via the Internet; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Amazon Web Services (AWS):
Servicesin the field of the provision of information technology infrastructure and related services (e.g. storage space and/or computing capacities); Service provider: Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, 1855, Luxembourg;
Legal Basis: Legitimate Interests (Article 6 (1)(f) GDPR);
Website: https://aws.amazon.com/;
Privacy Policy: https://aws.amazon.com/privacy/;
Data Processing Agreement: https://aws.amazon.com/compliance/gdpr-center/.
Basis for third-country transfers: EEA - Data Privacy Framework (DPF), Switzerland - Adequacy decision (Luxembourg).
Webflow:
Creation, management and hosting of websites, online forms and other web elements;
Service provider: Webflow, Inc., 398 11th St., Floor 2, 94103 San Francisco, USA; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR);
Website: https://webflow.com;
Privacy Policy: https://webflow.com/legal/eu-privacy-policy;
Data Processing Agreement: https://webflow.com/legal/dpa.
Basis for third-country transfers: EEA - Data Privacy Framework (DPF), Switzerland - Data Privacy Framework (DPF).
Cloudflare:
Content-Delivery-Network (CDN) - service with whose help contents of our online services, in particular large media files, such as graphics or scripts, can be delivered faster and more securely with the help of regionally distributed servers connected via the Internet; Service provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR);
Website: https://www.cloudflare.com;
Privacy Policy: https://www.cloudflare.com/privacypolicy/;
Data Processing Agreement: https://www.cloudflare.com/cloudflare-customer-dpa/. Basis for third-country transfers: EEA - Data Privacy Framework (DPF), Switzerland - Data Privacy Framework (DPF).
Amazon CloudFront:
Content-Delivery-Network (CDN) - service with whose help contents of our online services, in particular large media files, such as graphics or scripts, can be delivered faster and more securely with the help of regionally distributed servers connected via the Internet; Service provider: Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, 1855, Luxembourg; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR);
Website: https://aws.amazon.com/cloudfront/;
Privacy Policy: https://aws.amazon.com/privacy/;
Data Processing Agreement: https://aws.amazon.com/compliance/gdpr-center/.
Basis for third-country transfers: EEA - Standard Contractual Clauses (Provided by the service provider), Switzerland - Adequacy decision (Luxembourg).
Google Cloud CDN:
Content-Delivery-Network (CDN) - service with whose help contents of our online services, inparticular large media files, such as graphics or scripts, can be delivered faster and more securely with the help of regionally distributed servers connected via the Internet; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR);
Website: https://cloud.google.com/cdn;
Privacy Policy: https://policies.google.com/privacy;
Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum;
Basis for third-country transfers: EEA - Data Privacy Framework (DPF), Switzerland - Adequacy decision (Ireland).
Further Information: https://cloud.google.com/privacy.
JSDelivr:
Content Delivery Network (CDN) that helps deliver media and files quickly and efficiently, especially under heavy load; Service provider: ProspectOne, Królewska 65A/1, 30-081, Kraków, Poland; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR);
Website: https://www.jsdelivr.com; Privacy
Policy: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net.
Basis for third-country transfers: Switzerland - Adequacy decision (Poland).
Supabase:
Provision of backend services including database hosting, authentication, file storage, and server-side functions for web and mobile applications.Service provider: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR)Website:
https://supabase.com/Privacy Policy:
https://supabase.com/privacyData Processing Agreement:
https://supabase.com/dpaBasis for third-country transfers: EEA – Standard Contractual Clauses (SCCs), Switzerland – Adequacy decision (Singapore)