Preamble
This privacy notice supplements the privacy policy on our website.
Last Update: 7. April 2026
Table of contents
- Preamble
- Overview of processing operations
- Providers and services used in the course of business
- Cloud Services
- Surveys and Questionnaires
- Management, Organization and Utilities
Overview of processing operations
The following table summarises the types of data processed, the purposes for which they are processed and the concerned data subjects.
Categories of Processed Data
- Inventory data.
- Payment Data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and process data.
- Log data.
Categories of Data Subjects
- Service recipients and clients.
- Employees.
- Prospective customers.
- Communication partner.
- Users.
- Business and contractual partners.
- Education and course participants.
- Participants.
- Persons depicted.
- Third parties.
Purposes of Processing
- Provision of contractual services and fulfillment of contractual obligations.
- Communication.
- Security measures.
- Office and organisational procedures.
- Organisational and Administrative Procedures.
- Feedback.
- Polls and Questionnaires.
- Profiles with user-related information.
- Information technology infrastructure.
- Business processes and management procedures.
Providers and services used in the course of business
As part of our business activities, we use additional services, platforms, interfaces or plug-ins from third-party providers (in short, "services") in compliance with legal requirements. Their use is based on our interests in the proper, legal and economic management of our business operations and internal organization.
- Processed data types: Inventory data (For example, the full name, residential address, contact information, customer number, etc.); Payment Data (e.g. bank details, invoices, payment history); Contact data (e.g. postal and email addresses or phone numbers); Content data (e.g. textual or pictorial messages and contributions, as well as information pertaining to them, such as details of authorship or the time of creation.). Contract data (e.g. contract object, duration, customer category).
- Data subjects: Service recipients and clients; Prospective customers; Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; Office and organisational procedures. Business processes and management procedures.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Retention and Deletion".
- Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Further information on processing methods, procedures and services used:
Cloud Services
We use Internet-accessible software services (so-called "cloud services", also referred to as "Software as a Service") provided on the servers of its providers for the storage and management of content (e.g. document storage and management, exchange of documents, content and information with certain recipients or publication of content and information).
Within this framework, personal data may be processed and stored on the provider's servers insofar as this data is part of communication processes with us or is otherwise processed by us in accordance with this additional privacy information. This data may include in particular master data and contact data of data subjects, data on processes, contracts, other proceedings and their contents. Cloud service providers also process usage data and metadata that they use for security and service optimization purposes.
If we use cloud services to provide documents and content to other users or publicly accessible websites, forms, etc., providers may store cookies on users' devices for web analysis or to remember user settings (e.g. in the case of media control).
- Processed data types: Inventory data (For example, the full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or phone numbers); Content data (e.g. textual or pictorial messages and contributions, as well as information pertaining to them, such as details of authorship or the time of creation.). Usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, types of devices and operating systems used, interactions with content and features).
- Data subjects: Prospective customers; Communication partner (Recipients of e-mails, letters, etc.); Business and contractual partners. Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Office and organisational procedures. Information technology infrastructure (Operation and provision of information systems and technical devices, such as computers, servers, etc.)).
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Retention and Deletion".
- Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Further information on processing methods, procedures and services used:
Surveys and Questionnaires
We conduct surveys and interviews to gather information for the survey purpose communicated in each case. The surveys and questionnaires ("surveys") carried out by us are evaluated anonymously. Personal data is only processed insofar as this is necessary for the provision and technical execution of the survey (e.g. processing the IP address to display the survey in the user's browser or to enable a resumption of the survey with the aid of a cookie).
- Processed data types: Inventory data (For example, the full name, residential address, contact information, customer number, etc.); Contact data (e.g. postal and email addresses or phone numbers); Content data (e.g. textual or pictorial messages and contributions, as well as information pertaining to them, such as details of authorship or the time of creation.); Usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, types of devices and operating systems used, interactions with content and features). Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, involved parties).
- Data subjects: Participants; Employees (e.g. employees, job applicants, temporary workers, and other personnel.); Communication partner (Recipients of e-mails, letters, etc.). Business and contractual partners.
- Purposes of processing and legitimate interests: Feedback (e.g. collecting feedback via online form). Polls and Questionnaires (e.g. surveys with input options, multiple choice questions).
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Retention and Deletion".
- Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR).
Further information on processing methods, procedures and services used:
- Google Forms: Creation and evaluation of online forms, surveys, feedback forms, etc; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR); Website: https://www.google.de/intl/en/forms/about/; Privacy Policy: https://policies.google.com/privacy; Data Processing Agreement: https://cloud.google.com/terms/data-processing-addendum. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://cloud.google.com/terms/eu-model-contract-clause).
- Mentimeter: Erstellung von Präsentationen und Besprechungen mit Echtzeit-Feedback; Service provider: Mentimeter AB, Alströmergatan 22 SE-112 47 Stockholm, Sweden; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR); Website: https://www.mentimeter.com. Privacy Policy: https://www.mentimeter.com/policies.
Management, Organization and Utilities
We use services, platforms and software from other providers (hereinafter referred to as " third-party providers") for the purposes of organizing, administering, planning and providing our services. When selecting third-party providers and their services, we comply with the legal requirements.
Within this context, personal data may be processed and stored on the servers of third-party providers. This may include various data that we process in accordance with this additional privacy information. This data may include in particular master data and contact data of users, data on processes, contracts, other processes and their contents.
If users are referred to the third-party providers or their software or platforms in the context of communication, business or other relationships with us, the third-party provider processing may process usage data and metadata that can be processed by them for security purposes, service optimisation or marketing purposes. We therefore ask you to read the data protection notices of the respective third party providers.
- Processed data types: Content data (e.g. textual or pictorial messages and contributions, as well as information pertaining to them, such as details of authorship or the time of creation.); Usage data (e.g. page views and duration of visit, click paths, intensity and frequency of use, types of devices and operating systems used, interactions with content and features); Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, involved parties). Contact data (e.g. postal and email addresses or phone numbers).
- Data subjects: Communication partner (Recipients of e-mails, letters, etc.). Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfillment of contractual obligations; Office and organisational procedures; Web Analytics (e.g. access statistics, recognition of returning visitors); Provision of our online services and usability. Security measures.
- Retention and deletion: Deletion in accordance with the information provided in the section "General Information on Data Retention and Deletion".
- Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR). Consent (Article 6 (1) (a) GDPR).
Further information on processing methods, procedures and services used:
- Asana: Project management - organization and administration of teams, groups, workflows, projects and processes; Service provider: Asana, Inc, 1550 Bryant Street, Suite 200, San Francisco, CA 94103, USA; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR); Website: https://asana.com/de; Privacy Policy: https://asana.com/terms#privacy-policy; Data Processing Agreement: https://asana.com/de/terms#data-processing. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://asana.com/de/terms#data-processing).
- Canva: Creation and editing of graphic designs, use of pre-made templates, uploading personal images and text, collaboration on projects in real-time, publishing features; Service provider: Canva Pty Ltd, 110 Kippax St, 2010 Surry Hills, Australien; Legal Basis: Consent (Article 6 (1) (a) GDPR); Website: https://www.canva.com/. Privacy Policy: https://www.canva.com/policies/privacy-policy/.
- 1Password: Password Manager; Service provider: AgileBits, Inc., 4711 Yonge St, 10th Floor, Toronto, Ontario, M2N 6K8, Kanada; Legal Basis: Legitimate Interests (Article 6 (1) (f) GDPR); Website: https://1password.com/; Privacy Policy: https://1password.com/legal/privacy/; Data Processing Agreement: https://1password.com/legal-center/; Basis for third-country transfers: Standard Contractual Clauses (Part of the Data Processing Agreement). Further Information: https://1password.com/legal-center/ (Data originating from the European Union is processed on servers within the European Union.).