Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

A data protection officer has not been appointed, as there is no legal obligation to do so.

2. General information on data processing

Personal data is processed only to the extent necessary for the provision of the website and the app as well as to ensure a secure and functional operation.

3. Data processing when using the website

3.1 Technical provision of the website

When accessing the website, information that the browser automatically transmits is processed for technical reasons. This includes in particular:

  • IP address
  • date and time of access
  • accessed page
  • information about the browser and operating system

The processing is necessary in order to provide the website and to ensure the security and stability of operation.

Legal basis:
Art. 6(1)(f) GDPR
(Legitimate interest in a secure and functional website)

3.2 Use of technical service providers and third-country processing

For the technical provision and security of the website, the following service providers are used:

  • Cloudflare, Inc., USA (network security, content delivery and protection against cyberattacks)
  • Google Cloud Platform (Google Ireland Limited, Ireland; where applicable Google LLC, USA) as infrastructure provider

In this context, personal data (in particular IP addresses) is processed in order to ensure the technical delivery of the website as well as the security and stability of operation.

Due to technical reasons, personal data may be processed on servers within and outside the European Union, including in countries without an adequacy decision by the European Commission.

To safeguard such transfers, appropriate guarantees pursuant to Art. 46 GDPR are used, in particular standard contractual clauses as well as supplementary technical and organizational measures. Where applicable, data transfers are additionally based on adequacy decisions of the European Commission (e.g. the EU–U.S. Data Privacy Framework).

3.3 Cookies

Only technically necessary cookies are used on the website. These are required to ensure basic functions of the website, in particular:

  • secure delivery of content
  • protection against abusive access
  • storage of language settings

No cookies are used for analytics, tracking, or marketing purposes.

Technically necessary cookies can be managed or deleted in the browser settings. The functionality of the website may be restricted as a result.

Legal basis:
Section 25(2) no. 2 TTDSG
Art. 6(1)(f) GDPR

3.4 Storage period

Personal data from technical access processes is processed only for as long as this is necessary for the operation, security, and error analysis of the website and is subsequently deleted or anonymized.

4. Data processing in the app

4.1 Principle of processing

The app processes content provided by the user on the user’s end device. Such content is not processed on the provider’s own servers. The provider does not collect or process any personal data of users as a controller. The provider of the app has no access to the content stored by the user within the app.

4.2 Cloud synchronization

If the user has enabled cloud synchronization (iCloud) in the device settings, the content stored within the app is additionally synchronized via the respective cloud service of the platform provider.

The processing of this data takes place within the responsibility of the respective platform provider. The provider of the app does not process this data for its own purposes and has no access to the synchronized content.

Further information on data processing can be found in the privacy policy of the respective platform provider.

5. Automated decision-making

Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.

6. Rights of data subjects

Data subjects have in particular the following rights:

  • right of access (Art. 15 GDPR)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to object to processing (Art. 21 GDPR)
  • right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
  • right to data portability, insofar as the requirements of Art. 20 GDPR are met

Requests can be submitted at any time to the contact address stated above.

7. Language version

This document is provided in German and English. If there are any differences, the German version applies.