Privacy Policy

1. Introduction

This website is operated by: Helena Eschner.

It is very important to us to handle our website visitors' data confidentially and to protect it in the best possible way. For this reason, we make every effort to comply with the requirements of the GDPR.

Below we explain how we process your data on our website. We use language that is as clear and transparent as possible so that you really understand what happens to your data.

2. General information

2.1 Processing of personal data and other terms

Data protection applies to the processing of personal data. Personal data means all data with which you can be personally identified. This is, for example, the IP address of the device (PC, laptop, smartphone, etc.) you are currently using. Such data is processed when 'something happens to it'. Here, for example, the IP is transmitted from the browser to our provider and automatically stored there. This is then a processing (according to Art. 4 No. 2 GDPR) of personal data (according to Art. 4 No. 1 GDPR).

These and other legal definitions can be found in Art. 4 GDPR.

2.2 Applicable regulations/laws - GDPR, BDSG and TDDDG

The scope of data protection is regulated by law. In this case, these are the GDPR (General Data Protection Regulation) as a European regulation and the BDSG (Federal Data Protection Act) as a national law.

In addition, the TDDDG supplements the provisions of the GDPR as far as the use of cookies is concerned.

2.3 The person responsible

The controller within the meaning of the GDPR is responsible for data processing on this website. This is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.

You can reach the person responsible at:

Helena Eschner

7 Blocksberg 23812 Wahlstedt Germany

helena.newearthspiritcoach@gmail.com

2.4 How data is generally processed on this website

As we have already established, there is data (e.g. IP address) that is collected automatically. This data is mainly required for the technical provision of the website. If we also use personal data or collect other data, we will inform you of this or ask for your consent.

You consciously provide us with other personal data.

You will find detailed information on this below.

2.5 Your rights

The GDPR provides you with comprehensive rights. These include, for example, free information about the origin, recipient and purpose of your stored personal data. You can also request the rectification, blocking or erasure of this data or lodge a complaint with the competent data protection supervisory authority. You can revoke your consent at any time.

You can find out what these rights look like in detail and how to exercise them in the last section of this Privacy Policy.

2.6 Data protection - Our view

Data protection is more than just a chore for us! Personal data has great value and careful handling of this data should be a matter of course in our digitalized world. As a website visitor, you should also be able to decide for yourself what "happens" to your data, when and by whom. That is why we are committed to complying with all legal regulations, only collect the data that is necessary for us and, of course, treat it confidentially.

2.7 Forwarding and deletion

The transfer and deletion of data are also important and sensitive issues. We would therefore like to briefly inform you in advance about our general approach to this.

Data will only be passed on on the basis of a legal basis and only if this is unavoidable. This may be the case in particular if it is a so-called Data Processor and a Data Processing Agreement has been concluded in accordance with Art. 28 GDPR.

We delete your data when the purpose and legal basis for processing no longer apply and the deletion does not conflict with any other legal obligations. Art. 17 GDPR also provides a 'good' overview of this.

For further information, please refer to this Privacy Policy and contact the controller if you have any specific questions.

2.8 Hosting

WiX

We use the WiX service provided by Wix.com Ltd., 40 Namal Tel Aviv St., Tel Aviv, 6350671, Israel, to host and deliver our website. WiX provides a cloud-based platform with features for website creation, content management, e-commerce, and online bookings. When using the website, personal data such as IP address, email address, browser and device information, website usage data, form data, and order and payment information are processed. Data processing is carried out for the purpose of technically providing the website, managing content, processing orders and payments, and optimizing the user experience. The legal basis for processing is Article 6(1)(b) of the GDPR for (pre-)contractual measures and website use, as well as Article 6(1)(f) of the GDPR based on the legitimate interest in the secure, functional, and cost-effective provision of our online services. WiX uses functional cookies, analytics cookies, and marketing cookies; these are set only with consent, in accordance with Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. Cookies required for technical operation are based on Article 6(1)(f) of the GDPR and Section 25(2) of the TDDDG. Personal data may be transferred to servers in third countries, in particular to Israel and, where applicable, to the United States. An adequacy decision has been issued by the European Commission for Israel. For transfers to other third countries, appropriate safeguards, such as the European Commission’s standard contractual clauses, are used. The stored data will be deleted as soon as it is no longer necessary for the purposes of its processing or if consent is withdrawn, provided that no statutory retention obligations prevent this. Further information is available at https://www.wix.com/about/privacy.

WIX

We use the hosting and construction platform WIX on our website, which offers essential core functions for the administration, provision and publication of websites as well as online stores and booking systems. The service is provided by Wix.com, UAB, Didžioji g. 28, LT-01128, Vilnius, Lithuania. WIX enables the hosting and visual creation of websites and stores, the provision of interactive functions such as bookings, newsletter registration, contact forms and the integration of analytical and marketing-related functions. When using WIX, the following personal data is generally processed: IP address, page views and navigation paths, device type and browser information, rough geolocation (region/country), session behavior (e.g. length of stay, clicks, bounce rate), aggregated demographic information and - depending on the functions used on the website - transmitted content from forms such as name, contact and communication data. Data processing is carried out for the purpose of secure and efficient provision of the website, technical administration, optimization of the offer, fulfillment of contractual obligations (e.g. online store) and - depending on the function used - to enable interactions (e.g. bookings, contacting). The legal basis for the processing is Art. 6 para. 1 lit. b GDPR, insofar as the data is processed to fulfill the contract or carry out pre-contractual measures, otherwise Art. 6 para. 1 lit. f GDPR due to our legitimate interest in a secure and efficient provision of our online offer. If optional functions are used that require consent (e.g. newsletter, analysis functions), the processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR and, if applicable, § 25 para. 1 TDDDG. WIX uses cookies to provide and analyze the services. These are used, among other things, for technical functionality, range measurement and - with the appropriate settings - marketing purposes. Functional and necessary cookies are set on the basis of Art. 6 para. 1 lit. f GDPR and § 25 para. 2 TDDDG. Analysis and marketing cookies are only used with express consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG are used. Personal data may be transferred to third countries, in particular to the USA, as part of technical operations and support services. WIX uses the EU standard contractual clauses as suitable guarantees in accordance with Art. 46 GDPR. Personal data is only stored for as long as is necessary to fulfill the respective purposes or for as long as there are statutory retention obligations. If consent is withdrawn or the purpose of processing ceases to apply, the relevant data will be deleted, provided there are no conflicting legal obligations. Further information can be found in the Privacy Policy of WIX: https://www.wix.com/about/privacy

Wix

This website uses the website builder and hosting system of Wix, a service of Wix.com Luxembourg S.à r.l., 15 Boulevard F.W. Raiffeisen, 2411 Luxembourg, Luxembourg. Wix provides functions for website design, hosting, content management, e-commerce, booking systems, search engine optimization and other modules. When using Wix, personal data such as names, e-mail addresses, telephone numbers and all content entered and transmitted via forms is collected and processed. This data is processed for the purpose of providing and managing the website, enabling functionalities such as contact forms, bookings, e-commerce processes and for analyzing and optimizing the offer. The legal basis for the processing is Art. 6 para. 1 lit. b GDPR, insofar as data is required for the initiation or execution of contractual relationships, as well as Art. 6 para. 1 lit. f GDPR due to the legitimate interest in a professional web presence and website administration. Insofar as Wix uses cookies for function, analysis or marketing purposes, this is done on the basis of any consent given in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. The type and scope of the cookies used can be found in the cookie settings on this website. Personal data is transferred to third countries, in particular to the parent company Wix.com Ltd. in Israel, which is recognized by the European Commission as a safe third country with an adequate level of data protection. Further transfers to third countries, such as the USA, take place on the basis of suitable guarantees such as EU standard contractual clauses. Data is deleted once the purpose of processing no longer applies, consent is withdrawn or statutory retention periods have expired. Further information can be found in Wix's Privacy Policy at https://www.wix.com/manage/privacy.

2.9 Legal basis

The processing of personal data always requires a legal basis. The GDPR provides the following possibilities in Art. 6 para. 1 sentence 1:

a) The data subject has given their consent to the processing of their personal data for one or more specific purposes;

b) Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) The processing is necessary for compliance with a legal obligation to which the controller is subject;

d) Processing is necessary in order to protect the vital interests of the data subject or of another natural person;

e) The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

f) Processing is necessary for the purposes of the legitimate interests pursued by the controller(s) or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

In the following sections, we will provide you with the specific legal basis for the respective processing.

3. What happens on our website

When you visit our website, we process your personal data.

We use SSL or TLS encryption to provide the best possible protection against unauthorized access by third parties. You can recognize this encrypted connection by the https:// or lock symbol in the address bar of your browser.

Below you can find out what data is collected when you visit our website, for what purpose this is done and on what legal basis.

3.1 Data collection when accessing the website

When you visit the website, information is automatically stored in so-called server log files. This is the following information:

Browser type and browser version

Operating system used

Referrer URL

Host name of the accessing computer

Time of the server request

IP address

This data is required temporarily in order to be able to display our website to you permanently and without any problems. In particular, this data is used for the following purposes:

System security of the website

System stability of the website

Troubleshooting on the website

Establishing a connection to the website

Presentation of the website

Data processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR and is based on our legitimate interest in the processing of this data, in particular our interest in the functionality of the website and its security.

Where possible, this data is stored in pseudonymized form and deleted once the respective purpose has been achieved.

If the server log files make it possible to identify the data subject, the data is stored for a maximum period of 14 days. An exception is made if a security-relevant event occurs. In this case, the server log files are stored until the security-relevant event has been resolved and finally clarified.

Otherwise, no merging with other data takes place.

3.2 Data processing through user input

3.2.1 Own data collection

We offer the following service on our website: contact form.

We collect the following data for this purpose:

Name

E-mail address

The legal basis for this data processing is Art. 6 para. 1 lit. b GDPR.

The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

3.2.2 Contact us

a) e-mail

When you contact us by email, we process your email address and any other data contained in the email. This data is stored on the mail server and in some cases on the respective end devices. Depending on the request, the legal basis for this is regularly Art. 6 para. 1 lit. f GDPR or Art. 6 para. 1 lit. b GDPR. The data will be deleted as soon as the respective purpose no longer applies and it is possible in accordance with the legal requirements.

b) Contact form

Wix contact form

Our website includes a contact form from Wix, a platform service for websites and forms from Wix.com Ltd, 40 Namir Road, Tel Aviv-Yafo, 6113402 Israel. The contact form enables the transmission of messages and inquiries as well as the management and processing of contacts by website visitors. The contact details provided in the form, such as name, email address and other information entered by users, are processed, as well as technically required data such as IP address and browser information for form transmission and system security. The data is processed for the purpose of processing and responding to contact requests as well as for the administration and, if necessary, statistical analysis of communication processes. The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as it concerns (pre-)contractual inquiries, otherwise Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in efficient communication and ensuring technical functionality. Wix may use necessary functional cookies for the provision and security of the form; analysis and marketing cookies are used exclusively on the basis of prior consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG are used. Personal data may be transferred to third countries such as Israel; for Israel there is an adequacy decision by the EU Commission pursuant to Art. 45 GDPR. Data will be deleted as soon as the purpose of the processing no longer applies or the statutory retention periods have expired; if consent is withdrawn, the data will be deleted immediately, provided there are no mandatory retention obligations to the contrary. Further information can be found at: https://www.wix.com/about/privacy

3.3 Cookie Consent Tool

Wix (Cookie Consent Tool)

The Cookie Consent Tool is used on our website as part of the Wix services. The controller is Wix.com, UAB, Didžioji g. 28, LT-01128 Vilnius, Lithuania. The tool is used to obtain and manage consent for the use of cookies and similar technologies in accordance with applicable data protection laws such as the GDPR. It provides a banner that is used to control and document the selection of individual cookie categories (e.g. essential, analysis, marketing). In particular, the selected cookie preferences, times of consent or rejection, pages visited, browser and device type, the country in which the page was accessed and - depending on the consent management provider used - possibly also the IP address of the website visitor are recorded. The processing is carried out for the purpose of legally compliant operation of the website and for logging and managing consents granted or refused. The legal basis is Art. 6 para. 1 lit. c GDPR (legal obligation to provide evidence under data protection law) and Art. 6 para. 1 lit. a GDPR in conjunction with. § Section 25 (1) TDDDG, if and insofar as explicit consent is required for non-essential cookies. Essential cookies are set on the basis of our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR, as they are necessary for the display and functionality of the website; analysis and marketing cookies are only used if consent has been given, in which case Art. 6 para. 1 lit. a GDPR in conjunction with Art. 25 para. 1 TDDDG applies. § 25 para. 1 TDDDG is decisive. When using third-party providers as part of consent management, personal data - in particular the IP address - may be transferred to providers outside the EU, in particular to the USA. In these cases, the EU standard contractual clauses pursuant to Art. 46 GDPR are used as suitable guarantees for adequate data protection. The consent data will be stored for as long as is necessary to provide evidence of the consent given or refused or until consent is withdrawn, provided that there are no statutory retention obligations to the contrary. Further information can be found at: https://www.wix.com/about/privacy

3.4 Mailing service

Calendly

We integrate the Calendly service on our website for booking appointments and for automated communication in connection with appointments. Calendly is operated by Calendly LLC, 115 E Main St., Suite A1B, Buford, GA 30518, USA. Calendly enables website visitors to directly select available appointments and make bookings. Confirmation e-mails and reminders are automatically sent to the e-mail addresses entered. Personal data such as name, e-mail address, booked appointments, time stamp and technical information such as IP address and device used are processed. The purpose of data processing is the organization and execution of appointments and the sending of associated e-mail notifications. The legal basis for data processing is Art. 6 para. 1 lit. b GDPR for the implementation of (pre-)contractual measures and Art. 6 para. 1 lit. f GDPR due to our legitimate interest in efficient appointment management and communication. Calendly uses functional cookies to provide the booking function. These are only used insofar as they are technically necessary for the use of the appointment booking function (§ 25 para. 2 no. 2 TDDDG). Other cookies, for example for analysis or marketing purposes, are only used with express consent; the legal basis for this is Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. Personal data is transferred to the USA. Calendly bases this on the Standard Contractual Clauses (SCC) of the EU Commission pursuant to Art. 46 para. 2 lit. c GDPR. The personal data is deleted as soon as it is no longer required to achieve the purpose, statutory retention obligations end or deletion is requested. Further information on data processing by Calendly can be found at: https://calendly.com/privacy.

Gmail

We use the Gmail email service on our website to manage and send emails. Gmail is operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The service enables the sending, receiving, and organization of emails, including the potential integration of automated workflows via interfaces such as the Gmail API or SMTP servers. Typically, the following data is processed: email addresses of senders and recipients, full message content including subject lines and file attachments, and metadata such as timestamps, labels, and information about associated contacts. The processing is carried out for the purposes of communication, organizing support requests, automating business processes, and sending notifications. The legal basis is Article 6(1)(f) of the GDPR based on a legitimate interest in efficient communication, as well as Article 6(1)(b) of the GDPR, provided that the communication is necessary to fulfill contractual obligations. Gmail uses functional cookies within the web application to ensure the technical provision and security of the service. Analytics or marketing cookies are stored only with the users’ explicit consent; The legal basis for this is Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG. To the extent that personal data is transferred to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, the EU Commission’s Standard Contractual Clauses are used as appropriate safeguards within the meaning of Article 46(2)(c) of the GDPR. Data is generally deleted as soon as the purpose of the processing no longer applies, the processing is objected to, or consent has been withdrawn, provided that no statutory retention obligations preclude this. Further information can be found at: https://policies.google.com/privacy?hl=de

3.5 Analysis and tracking tools

Sentry

Our website uses the analysis and error tracking service Sentry, operated by Functional Software, Inc, 45 Fremont Street, San Francisco, CA 94105, United States. Sentry enables the monitoring, detection and analysis of errors and performance problems in real time to ensure the stability and quality of the web application. In particular, the service collects and processes IP addresses, information on the browser used and the browser version, device type, pages visited, data on user interactions (so-called "breadcrumbs"), stack traces, context data on error events, release numbers or commit SHAs and - if provided by the integration - pseudonymized user identifiers such as user IDs or e-mail addresses. This data processing is used to diagnose errors, improve application stability, analyze technical problems and - within the scope of the application - optimize the user experience. The legal basis for the use of Sentry is Art. 6 para. 1 lit. f GDPR. The legitimate interest lies in the secure, error-free and needs-based provision of our online offering. If cookies are used as part of the integration or information is read out in the end device, this is done exclusively on the basis of consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. Sentry may use functional cookies and similar technologies for analysis and monitoring. These are only activated after prior consent via the consent banner. The legal basis for this is Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. Personal data is transferred to third countries, in particular to the USA. Sentry uses the standard contractual clauses of the EU Commission pursuant to Art. 46 para. 2 lit. c GDPR as a suitable guarantee for an adequate level of data protection. The data collected is deleted as soon as it is no longer required to achieve the purpose for which it was collected. Data may be stored beyond this in individual cases if there are statutory retention obligations or consent is revoked. Further information can be found at: https://sentry.io/privacy/

3.6 Social media profiles

In addition to our website, our company is also present on social networks. Here we want to present our company and create the opportunity to get in touch with us.

We also use the opportunity to place advertisements and job advertisements on social media.

In the following, we provide information about which data we and the respective social network process when you visit and interaction with our profile.

Instagram

We operate an Instagram profile. This social media platform is offered by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Interaction with our company profile

When you visit our Instagram profile and interact with us, we process personal data. On the one hand, the data made publicly available on the profile. On the other hand, we also process the personal data contained in posts, comments or direct messages to us. Through interactions such as liking or sharing, we can see the user profile with the public information. The legal basis for this processing is Art. 6 para. 1 lit. f GDPR. It is in our legitimate interest to provide relevant and interesting content and to enable the use and functionality of our Instagram profile. Insofar as a request is related to the performance of a contract or is necessary for the implementation of pre-contractual measures, our processing is based on Art. 6 para. 1 lit. b GDPR.

Insights

As explained in the Meta Privacy Policy under "How do we use your information?" (https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect), Meta also collects and uses information to provide analytics services, known as insights, for site operators. This also applies to our Instagram profile. Insights are summarized statistics that are created based on certain interactions of visitors with pages and the content associated with them and are logged by the Meta servers. This includes the following information: - how many people see and interact with our products, services or content, such as posts, videos, Instagram pages, advertisements, stores and advertisements (if the advertisement is shown on Meta products); - how people interact with our content, websites, apps and services; - which group of people interact with our content or which group of people use our services. Meta provides us with aggregated reports and insights that tell us how well our content, features, products and services are performing. We do not have access to personal data, only to the summarized reports. To evaluate the reach, we can make settings or set appropriate filters with regard to the selection of a time period, the viewing of a specific post and demographic groupings. This data is anonymized. It is not possible for us to draw conclusions about specific individuals. The purpose of processing this data is to analyze our reach and adapt our content and advertisements to user interests so that visitors can derive the greatest possible benefit from them. By evaluating this data, we can recognize how our content, our profile and our advertising are consumed. This enables us to create target-group-specific content and place advertising to better market our company and our services. The processing is based on our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR. When processing personal data in the course of the so-called Insights, the processing is carried out in joint responsibility with Meta in accordance with Art. 26 para. 1 GDPR. We have entered into a corresponding agreement with Meta for this purpose, which can be viewed [here](https://www.facebook.com/legal/terms/page_controller_addendum.). Meta's contact details are as follows: Online contact: https://www.facebook.com/help/contact/1650115808681298 Postal: Meta Platforms Ireland Limited, ATTN: Privacy Operations, Merrion Road, Dublin 4, D04 X2K5, Ireland. For Instagram, you can contact the data protection officer at the following link: https://www.facebook.com/help/contact/540977946302970. Further information about Insights: https://de-de.facebook.com/help/pages/insights. The complete privacy policy of Instagram: https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect

Processing of personal data and cookies by Meta

When an Instagram page is accessed, the IP address assigned to the end device is transmitted to Meta. According to Meta, this IP address is anonymized (for "German" IP addresses). Meta also stores information about the end devices of its users (e.g. as part of the "login notification" function); Meta may thus be able to assign IP addresses to individual users. If you are currently logged in to Instagram as a user, a cookie with the Instagram identifier is stored on the end device. This enables Meta to track who has visited and used this page. Meta buttons integrated into websites enable Meta to record your visits to these websites and assign them to your Instagram profile. This data can be used to offer personalized content or advertising. Further information: https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect

3.7 Third-party content

Calendly

We use the appointment booking service Calendly on our website for automated online appointment scheduling, offered by Calendly LLC, 115 E Main St Ste A1B PMB 123, Buford, GA 30518, USA. Calendly allows visitors to directly select available appointments and synchronize them with their own calendars, which automates appointment suggestions and reminders and eliminates time-consuming email exchanges. Personal data such as name, e-mail address, details of booked appointments, selected event types and - depending on the integration - browser identifiers and, if applicable, campaign information are processed. Data processing is carried out for the purpose of appointment management, automation of booking processes, integration into other systems (e.g. CRM or video conferencing services), as well as for communication and confirmation of booked appointments. The legal basis is Art. 6 para. 1 lit. b GDPR, insofar as bookings are made for (pre-)contractual purposes, and Art. 6 para. 1 lit. f GDPR for our legitimate interest in efficient appointment organization. If analysis or marketing functions are integrated, processing is carried out on the basis of consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG. Calendly can set cookies for functions, analysis and, if necessary, marketing; these are - unless necessary - only activated after consent has been given and can be revoked at any time. When using Calendly, personal data is transferred to the USA. The EU standard contractual clauses are used to protect the transmitted data. Data is generally deleted as soon as the purpose of the processing no longer applies, there are no longer any contractual or statutory retention obligations or consent has been withdrawn. Further information on data processing by Calendly can be found at: https://calendly.com/legal/privacy-notice

3.8 Audio and video conferencing

Zoom

Our website uses the video conferencing and communication service Zoom, provided by Zoom Video Communications, Inc, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA, for European users with services via regional subsidiaries such as ZVC Germany, ZVC Netherlands or ZVC UK. Zoom enables audio and video conferences, webinars, live chats, screen sharing and online meetings to be held directly via the website. In the course of use, IP addresses, account information, session and meeting data, registration information for webinars, engagement data (e.g. recordings, transcripts) and interaction data such as chat messages, shared files or technical usage information are usually processed. The data processing serves the provision and management of online meetings, interactive communication and the implementation and evaluation of digital events. The legal basis for the processing is regularly Art. 6 para. 1 lit. b GDPR (implementation of (pre-)contractual measures), for support or administrative processes as well as analysis purposes Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient communication and IT security). Depending on the integration, Zoom uses functional cookies for session management and, if necessary, analysis or marketing cookies to evaluate usage, whereby analysis and marketing cookies are only used with consent in accordance with Art. 6 Para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG are used. Functional cookies are necessary for operation and are used in accordance with Art. 6 para. 1 lit. f GDPR in conjunction with. § 25 para. 2 TDDDG are used. Personal data is transferred to third countries, in particular to the USA, whereby Zoom uses the EU standard contractual clauses as suitable guarantees in accordance with Art. 46 para. 2 lit. c GDPR. The storage period depends on the respective purpose, i.e. data is deleted or blocked after the purpose of processing ceases to apply, if consent is revoked or objected to, or if statutory retention periods expire. Further information can be found in Zoom's Privacy Policy: https://www.zoom.com/en/trust/privacy/privacy-statement/

3.9 Payment services

Klarna

This website uses the Klarna payment service, which is operated by Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. Klarna enables the processing of payments in the online store and offers functions such as immediate payment, purchase on account, installment purchase and other "buy now, pay later" options. Klarna can also be used to select and integrate corresponding payment methods during checkout. As part of payment processing, personal data such as first and last name, title, date of birth, address, zip code, national identification number, payment data, financial information and, if applicable, information on creditworthiness are processed. In addition, depending on the respective interaction, further information may be collected for identity verification, use of the website and technical data. The purpose of data processing is to process payment transactions, carry out identity and credit checks, ensure fraud prevention and enable contract initiation and fulfillment. The legal basis for data processing is Art. 6 para. 1 lit. b GDPR (implementation of pre-contractual measures and contract fulfillment) and, if necessary for risk assessment and fraud prevention, Art. 6 para. 1 lit. f GDPR. When integrating certain Klarna functions, for example to store payment preferences using cookies or for marketing and analysis purposes, consent is also required in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG. Klarna sets - depending on the selected payment option and functional scope - technically necessary cookies as well as cookies for analysis and marketing purposes with consent. Which cookies are set in individual cases and for what purpose depends on the Klarna component implemented. Personal data may be transferred to third countries if this is necessary for payment processing. Klarna generally uses the EU standard contractual clauses pursuant to Art. 46 para. 2 lit. c GDPR or other suitable guarantees as a guarantee. Personal data will be deleted as soon as they are no longer required for the purposes mentioned, but at the latest after expiry of statutory retention periods. In the event of revocation or objection, data will be deleted promptly, provided that there are no mandatory statutory retention periods to the contrary. Detailed information is available at https://www.klarna.com/international/privacy-policy/.

PayPal

Our platform integrates the PayPal payment service to process online payments. The provider is PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. PayPal enables payments via a PayPal account, credit card, or other available payment methods and handles payment processing during checkout. In particular, the following data is processed: transaction data (e.g., transaction ID, status, amount, fees, refunds), payment and checkout information, details regarding the selected payment method, usage and activity data, as well as technical data such as IP address and log information. The processing is carried out for the purposes of payment processing, fraud prevention, processing refunds, and complying with legal obligations. The legal basis is Article 6(1)(b) of the GDPR for carrying out the payment transaction, Article 6(1)(f) of the GDPR for protection against misuse and fraud, and Article 6(1)(c) of the GDPR for compliance with legal obligations. As part of the payment processing, PayPal uses technically necessary cookies and similar technologies that are absolutely essential for the functionality and security of the payment transaction; the legal basis for this is Section 25(2)(2) of the German Telemedia Act (TDDDG). Analytics or marketing cookies are not set through the payment processing on our platform. If personal data is transferred to third countries outside the European Economic Area, this is done on the basis of the EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR, as well as binding corporate rules (BCRs). The data is stored for as long as necessary for the purposes stated or as required by statutory retention obligations; thereafter, it is deleted. For more information, please see PayPal’s Privacy Policy at: https://www.paypal.com/de/legalhub/privacy-full

SEPA Transfer (Bank Transfer)

We use the SEPA Credit Transfer for payment processing on our website. The SEPA Credit Transfer is a payment service based on the standard set by the European Payments Council (EPC), Rue d'Arlon 73, 1050 Brussels, Belgium, and is processed through the respective bank or payment service provider (PSP). The SEPA Credit Transfer enables standardized and efficient processing of transfers in euros within the SEPA area, such as for online purchases, recurring payments, or direct payments between accounts. In the process, personal data such as the name and IBAN of the payer and payee, the transfer amount, an optional payment reference, and, if applicable, the BIC are typically processed. The purpose of the processing is to execute and settle payments under the SEPA procedure, including legally mandated obligations for fraud prevention and anti-money laundering. The legal basis for data processing is Article 6(1)(b) of the GDPR for the performance of a contract, as well as legal obligations under Article 6(1)(c) of the GDPR. No cookies are used in connection with a SEPA credit transfer. Data is generally transferred within the EU and the EEA. Data is not transferred to third countries unless the recipient bank is based abroad; in this case, the legal requirements for international data transfers under the GDPR apply, and the appropriate safeguards (e.g., EU Standard Contractual Clauses) are utilized. Personal data is stored for the duration of statutory retention periods (e.g., under commercial and tax law) and subsequently deleted, provided there are no further legitimate reasons for retention. Further information on data processing for SEPA transfers can be found in the Privacy Policy of the respective bank or payment service provider.

Stripe

The Stripe payment service is integrated on the website to enable the secure and efficient processing of online payments and subscriptions. Stripe Payments Europe, Limited, 3 Dublin Landings, North Wall Quay, Dublin 1, D01 C4E0, Ireland, is responsible for the service in Europe. Stripe provides various payment functions, such as payment by credit card, direct debit, instant bank transfer or digital wallets, as well as automated invoicing and fraud prevention. In the context of use, Stripe processes personal data such as name, e-mail address, telephone number, billing and delivery address, credit card and account data, IP address, device and browser information, usage and transaction data and, if applicable, documents to confirm identity. The processing is carried out for the purpose of payment processing, contract execution, fraud prevention and compliance with legal requirements. The legal basis is Art. 6 para. 1 lit. b GDPR for contractual or pre-contractual measures, if applicable Art. 6 para. 1 lit. f GDPR due to legitimate interests in secure payment processing and § 25 para. 2 no. 2 TDDDG for technically necessary cookies and technologies. Stripe uses technically necessary cookies as part of the payment process, including authentication and security cookies as well as session IDs for fraud prevention and payment processing. These cookies are absolutely necessary for operation and are processed without consent (Section 25 (2) No. 2 TDDDG). Analytical or marketing cookies, on the other hand, are only used with consent in accordance with Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. Personal data may be transferred to third countries (in particular the USA) as part of payment processing. Stripe uses the standard contractual clauses approved by the EU Commission in accordance with Art. 46 para. 2 lit. c GDPR as suitable guarantees. Personal data is generally deleted as soon as it is no longer required for the purposes for which it was collected and there are no statutory retention obligations. If consent is withdrawn or after expiry of statutory periods, the data will be deleted, provided there are no other statutory retention periods to the contrary. Further information on data processing by Stripe is available at: https://stripe.com/privacy

3.10 Services for processing orders

Wix

Our website uses the Wix service for ordering and booking processes, which is operated by Wix.com, UAB, Didžioji g. 28, LT-01128 Vilnius, Lithuania. Wix enables the processing of orders, bookings and payments via integrated forms as well as the management of customer and order data. In particular, the data provided as part of the ordering and booking process, such as name, e-mail address, order details, payment information, contact details and technical data such as IP address and browser information, are processed. The purpose of data processing is the contractual processing of orders, bookings and customer inquiries as well as the administration of the associated processes. The legal basis is Art. 6 para. 1 lit. b GDPR for the implementation of pre-contractual measures and for the fulfillment of the contract; additional processing (e.g. statistical evaluations, marketing) is carried out on the basis of Art. 6 para. 1 lit. f GDPR or - in the case of technically unnecessary cookies and similar technologies - on the basis of Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. Wix may use technically necessary cookies for individual functions and - insofar as functions for customer analysis or marketing are activated - also analysis and marketing cookies. These are only used with consent; the legal basis in these cases is Art. 6 para. 1 lit. a GDPR in conjunction with. § Section 25 (1) TDDDG. Personal data may be transferred to third countries, in particular to Israel and the USA. In these cases, Wix relies on suitable guarantees, in particular the standard contractual clauses of the EU Commission. The data is generally only stored for as long as is necessary for the stated purposes or until the data subject withdraws their consent or the deletion does not conflict with any statutory retention obligations. Detailed information can be found in Wix's Privacy Policy: https://www.wix.com/about/privacy

3.11 CRM systems

WIX CRM

This website uses WIX CRM from Wix.com Ltd, 5 Yunitsman St., Tel Aviv, 6936025, Israel, for customer relationship management. The service enables the collection, management and organization of contact and prospect data as well as the automation and coordination of communication processes and sales processes via forms, bookings, messages and other interactions integrated into the website. In particular, names, email addresses, contact and communication data such as telephone numbers, content of inquiries and feedback, booking data, payment information (if relevant) and interaction data (e.g. form submissions, chat messages, website actions) are processed. Data processing serves the purpose of managing contacts, optimizing customer interactions, carrying out pre-contractual and contractual communication, sales management and the analysis and improvement of business processes. The legal basis for processing is Art. 6 para. 1 lit. b GDPR for contract initiation or execution and Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in efficient customer management and business processing. As things currently stand, WIX CRM does not use its own functional, analysis or marketing cookies for contact management; should this take place in the future, such integration will only take place on the basis of active consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with § 25 para. 1 TDDDG. Personal data may be transferred to Israel; this third country has an adequate level of data protection pursuant to Art. 45 GDPR in accordance with a decision by the EU Commission. The stored data will generally be deleted as soon as the respective processing purpose no longer applies or upon request, provided that there are no legal retention requirements to the contrary. Detailed information can be found at https://www.wix.com/about/privacy

3.12 Cloud backups

AWS Backup

On our website, we use the AWS Backup service from Amazon Web Services, Inc, 410 Terry Ave North, Seattle, WA 98109-5210, USA, for the automated backup and restoration of data in our cloud infrastructure. The service enables the centralized and automated creation, storage and restoration of backups for various AWS resources such as EC2 instances, EBS volumes, S3 buckets, RDS databases, EFS file systems and DynamoDB tables used for the operation of our website. The data specified in the backup configuration is processed from the aforementioned cloud resources as well as metadata on the backup processes (e.g. timestamps, resource IDs, status messages) and access and administration data (e.g. IAM roles and authorizations). The processing of this data serves the purpose of fail-safety, the recovery of systems in the event of a disaster, compliance with legal and business archiving obligations and the prevention of data loss. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in data security and business continuity, unless a contractual requirement pursuant to Art. 6 para. 1 lit. b GDPR is relevant in individual cases. AWS Backup does not use cookies as part of this functionality, as the service is not integrated into the user interaction on the website, but works exclusively on the server side for backup purposes. Data may be transferred to third countries, in particular to the USA, in certain cases. In this case, Amazon Web Services relies on the EU standard contractual clauses as suitable guarantees in accordance with Art. 46 GDPR. Data will be deleted as soon as the purpose of the backup no longer applies, a retention period expires or at the request of the website operator, provided that there are no legal retention obligations to the contrary. Further information on data protection at Amazon Web Services can be found at: https://aws.amazon.com/privacy/

Google Cloud Platform (GCP)

We use the cloud backup and hosting services of Google Cloud Platform (GCP) on our website, operated by Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. GCP makes it possible to securely store website data and content in distributed cloud storage systems, create automated backups and provide robust hosting and infrastructure services for web applications and services. Depending on the configuration, technical data such as server logs, connection data (e.g. IP address, time stamp), usage and access data and, in the case of transmission processes, content transmitted on the website are typically processed. The data processing is carried out for the purpose of data backup, recovery in the event of loss, operational security of the website and for the effective provision of hosting infrastructure. The legal basis for data processing is Art. 6 para. 1 lit. f GDPR, as there is a legitimate interest in the secure, stable and efficient provision of the website; insofar as backups are legally required, Art. 6 para. 1 lit. c GDPR may also be relevant. In connection with Google Cloud Platform, no cookies are set on users' end devices. Personal data may be transferred to third countries outside the European Union as part of cloud-based hosting. Google uses the European Commission's standard contractual clauses in accordance with Art. 46 GDPR as a suitable guarantee for this. The data will be deleted as soon as the purpose of the backup no longer applies, the website service is discontinued or statutory retention obligations have expired. In the event of a revocation or justified deletion requests, the deletion takes place after examination and within the scope of the technical possibilities. Further information on data processing by Google Cloud Platform can be found at: https://cloud.google.com/terms/cloud-privacy-notice

Fastly

Our website uses the Fastly cloud service to deliver content and back up data. Fastly is operated by Fastly International Technology Limited, Birchin Court, 5th Floor, 19-25 Birchin Lane, London, United Kingdom, EC3V 9DU. The service provides a content delivery network (CDN) platform to optimize the delivery and security of website content. As a result, content is delivered faster and more reliably, while technical protection measures such as DDoS defense and Web Application Firewall (WAF) are supported. During use, personal data such as IP address, geo-location (e.g. country, city), URLs accessed, HTTP headers, user agent, cache and status information are typically processed. Depending on the integration and website configuration, content and communication data can also be processed in Transit for a short time if certain requirements are met. Data processing is used to secure website content, ensure the availability and performance of the website and effectively ward off attacks, as well as for analysis and troubleshooting purposes. The legal basis for processing is Art. 6 para. 1 lit. f GDPR on the basis of the legitimate interest in the secure and efficient provision of digital content and to maintain IT security. If log data or tracking cookies are used for analysis purposes, this is only done on the basis of consent in accordance with Art. 6 para. 1 lit. a GDPR in conjunction with. § 25 para. 1 TDDDG. Fastly may set cookies that are used for technical provision, network security and, if necessary, as anonymized analysis cookies. Functional cookies are required for service operation, analysis cookies are only used if consent has been given. In the context of use, personal data may be transferred to third countries, in particular to the USA and the United Kingdom. The standard contractual clauses of the EU Commission are used as suitable guarantees for these transfers. Personal data is only stored for as long as is necessary to fulfill the purpose or due to statutory retention obligations. Data that is processed on the basis of consent is deleted at the latest after consent is withdrawn, provided that there are no other statutory storage obligations to the contrary. Further information can be found at: https://www.fastly.com/privacy

4. What else is important

Finally, we would like to inform you in detail about your rights and how you will be informed about changes to data protection requirements.

4.1 Your rights in detail

4.1.1 Right to information in accordance with Art. 15 GDPR

You can request information about whether your personal data is being processed. If this is the case, you can request further information on the type and manner of processing. A detailed list can be found in Art. 15 para. 1 lit. a to h GDPR.

4.1.2 Right to rectification in accordance with Art. 16 GDPR

This right includes the correction of incorrect data and the completion of incomplete personal data.

4.1.3 Right to erasure in accordance with Art. 17 GDPR

This so-called 'right to be forgotten' gives you the right, under certain conditions, to request the deletion of your personal data by the controller. This is generally the case if the purpose of the data processing no longer applies, if consent has been withdrawn or the initial processing took place without a legal basis. A detailed list of reasons can be found in Art. 17 para. 1 lit. a to f GDPR. This "right to be forgotten" also corresponds to the controller's obligation under Art. 17 para. 2 GDPR to take reasonable steps to ensure that the data is generally erased.

4.1.4 Right to restriction of processing in accordance with Art. 18 GDPR

This right is subject to the conditions set out in Art. 18 para. 1 lit. a to d.

4.1.5 Right to data portability in accordance with Art. 20 GDPR

This regulates the basic right to receive your own data in a commonly used form and to transfer it to another controller. However, this only applies to data processed on the basis of consent or a contract in accordance with Art. 20 (1) (a) and (b) and insofar as this is technically feasible.

4.1.6 Right to object pursuant to Art. 21 GDPR

In principle, you can object to the processing of your personal data. This applies in particular if your interest in objecting outweighs the legitimate interest of the controller in the processing and if the processing relates to direct marketing and/or profiling.

4.1.7 Right to "individual decision-making" pursuant to Art. 22 GDPR

In principle, you have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. However, this right is also restricted and supplemented by Art. 22 (2) and (4) GDPR.

4.1.8 Further rights

The GDPR contains comprehensive rights to inform third parties about whether or how you have asserted rights under Art. 16, 17, 18 GDPR. However, this only applies insofar as this is possible or feasible with reasonable effort.

We would like to take this opportunity to draw your attention once again to your right to withdraw your consent in accordance with Art. 7 (3) GDPR. However, this does not affect the lawfulness of the processing carried out up to that point.

We would also like to draw your attention to your rights under §§ 32 ff. BDSG, which, however, are largely congruent with the rights just described.

4.1.9 Right to lodge a complaint pursuant to Art. 77 GDPR

You also have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of personal data relating to you infringes this Regulation.

5. What if the GDPR is abolished tomorrow or other changes take place?

This Privacy Policy is current as of August 10, 2026. From time to time, it may be necessary to update the content of this Privacy Policy to reflect factual and legal changes. We therefore reserve the right to amend this Privacy Policy at any time. We will publish the amended version in the same location and recommend that you review the Privacy Policy regularly.

Created with the kind support of Dieter macht den Datenschutz