Privacy Policy

Preamble

With the following privacy policy, we would like to inform you about the types of personal data (hereinafter also referred to simply as "data") we process, for what purposes, and to what extent. The privacy policy applies to all processing of personal data carried out by us, both within the scope of providing our services and, in particular, on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offer").

The terms used are not gender-specific.

Status: June 2, 2026

Table of Contents

Controller

nox cargo GmbH & Co. KG
Papenreye 53
22453 Hamburg
Germany

Authorized Representatives: Tim Schulz

Email address: germany@noxcargo.com

Overview of Processing

The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects.

Types of Data Processed

  • Inventory data.
  • Employee data.
  • Location data.
  • Contact data.
  • Content data.
  • Usage data.
  • Meta, communication, and procedural data.
  • Log data.

Categories of Data Subjects

  • Employees.
  • Communication partners.
  • Users.
  • Third parties.
  • Whistleblowers.

Purposes of Processing

  • Communication.
  • Security measures.
  • Reach measurement.
  • Tracking.
  • Target group formation.
  • Organizational and administrative procedures.
  • Feedback.
  • Marketing.
  • Profiles with user-related information.
  • Provision of our online offer and user-friendliness.
  • Information technology infrastructure.
  • Whistleblower protection.

Relevant Legal Bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR upon which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your or our country of residence or domicile. Furthermore, should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.

  • Consent (Art. 6(1)(a) GDPR) - The data subject has given consent to the processing of his or her personal data for one or more specific purposes.
  • Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6(1)(c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1)(f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

National data protection regulations in Germany: In addition to the data protection regulations of the GDPR, national regulations on data protection apply in Germany. This includes, in particular, the Act to Protect against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains specific rules on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission, as well as automated individual decision-making including profiling. Furthermore, state data protection laws of the individual federal states may apply.

Notice on the applicability of the GDPR and the Swiss FADP: This privacy policy serves to provide information under both the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR). For this reason, we ask you to note that, due to the broader spatial application and comprehensibility, the terms of the GDPR are used. In particular, instead of the terms used in the Swiss FADP, such as "processing" of "personal data", "overriding interest", and "sensitive personal data", the terms used in the GDPR, "processing" of "personal data" as well as "legitimate interest" and "special categories of data", are used. However, the legal meaning of the terms will continue to be determined according to the Swiss FADP within the scope of the applicability of the Swiss FADP.

Applicability of data protection regulations in the country of domicile: In the country where the controller is domiciled, national data protection regulations apply in addition to the General Data Protection Regulation (GDPR).

Security Measures

We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access, input, disclosure, safeguarding availability, and their separation. Furthermore, we have established procedures to ensure the exercise of data subjects' rights, the deletion of data, and responses to data endangerment. Moreover, we take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.

Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorized access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is signaled by displaying HTTPS in the URL. This serves as an indicator to users that their data is being transmitted securely and encrypted.

Transmission of Personal Data

In the context of our processing of personal data, it may happen that this data is transmitted or disclosed to other bodies, companies, legally independent organizational units, or persons. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude appropriate contracts or agreements with the recipients of your data that serve to protect your data.

International Data Transfers

Data processing in third countries: If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs in the context of using third-party services or disclosing or transmitting data to other persons, bodies, or companies (which can be recognized by the respective provider's postal address or if the privacy policy expressly refers to data transfers to third countries), this will only occur in compliance with legal requirements.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized by an adequacy decision of the EU Commission on July 10, 2023, as a secure legal framework. Additionally, we have concluded standard contractual clauses with the respective providers that correspond to the specifications of the EU Commission and establish contractual obligations to protect your data.

This dual safeguard ensures comprehensive protection of your data: The DPF forms the primary level of protection, while the standard contractual clauses serve as additional security. Should any changes occur within the framework of the DPF, the standard contractual clauses act as a reliable fallback option. In this way, we ensure that your data always remains adequately protected, even in the event of political or legal changes.

For individual service providers, we will inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the US Department of Commerce website at https://www.dataprivacyframework.gov/.

For data transfers to other third countries, appropriate security measures apply, in particular standard contractual clauses, explicit consent, or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the EU Commission's information offering: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en.

General Information on Data Retention and Deletion

We delete personal data that we process in accordance with legal provisions as soon as the underlying consents are revoked or no further legal bases for processing exist. This applies to cases in which the original processing purpose ceases to apply or the data is no longer required. Exceptions to this rule exist if legal obligations or special interests require a longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax reasons, or whose storage is necessary for the establishment, exercise, or defense of legal claims or to protect the rights of other natural or legal persons, must be archived accordingly.

Our privacy notices contain additional information on the retention and deletion of data that applies specifically to certain processing operations.

If there are multiple specifications for the retention period or deletion periods of data, the longest period is always authoritative. We process data that is no longer required for the originally intended purpose, but is retained due to legal requirements or other reasons, exclusively for the reasons that justify its retention.

Start of period at the end of the year: If a period does not explicitly start on a specific date and is at least one year, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships within which data is stored, the event triggering the period is the time the termination becomes effective or any other termination of the legal relationship.

Rights of Data Subjects

Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:

  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions. Where personal data concerning you is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent given at any time.
  • Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to receive information about this data as well as further information and a copy of the data in accordance with legal requirements.
  • Right to rectification: In accordance with legal requirements, you have the right to request the completion of data concerning you or the rectification of incorrect data concerning you.
  • Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to request that data concerning you be deleted without undue delay, or alternatively, in accordance with legal requirements, to request a restriction of the processing of the data.
  • Right to data portability: You have the right to receive data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format in accordance with legal requirements, or to request its transmission to another controller.
  • Complaint to supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR.

Provision of the Online Offer and Web Hosting

We process users' data in order to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the contents and functions of our online services to the user's browser or device.

  • Types of data processed: Usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, persons involved). Log data (e.g., log files regarding logins or the retrieval of data or access times).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online offer and user-friendliness; Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
  • Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Further notes on processing operations, procedures, and services:

  • Provision of online offer on rented storage space: To provide our online offer, we use storage space, computing capacity, and software that we rent or otherwise obtain from an appropriate server provider (also called "web host"); Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
  • Collection of access data and log files: Access to our online offer is logged in the form of so-called "server log files". The server log files may include the address and name of the accessed web pages and files, date and time of access, transferred data volumes, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page), and generally IP addresses and the requesting provider. Server log files can be used for security purposes, e.g., to avoid server overload (especially in the case of abusive attacks, so-called DDoS attacks), and secondly, to ensure the utilization of the servers and their stability; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymized. Data whose further retention is required for evidentiary purposes is excluded from deletion until the final clarification of the respective incident.

Use of Cookies

The term "cookies" refers to functions that store information on end devices of users and read information from them. Cookies can also be used for various purposes, such as ensuring the functionality, security, and comfort of online offers, as well as creating analyses of visitor flows. We use cookies in accordance with legal regulations. For this, we obtain the prior consent of the users if necessary. If consent is not necessary, we rely on our legitimate interests. This applies when the storage and reading of information is essential to be able to explicitly provide requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online offer. Consent can be revoked at any time. We clearly provide information about their scope and which cookies are used.

Notes on legal bases under data protection law: Whether we process personal data using cookies depends on a consent. If consent is given, it serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.

Storage duration: With regard to storage duration, the following types of cookies are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offer and closed their end device (e.g., browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after closing the end device. For example, the login status can be saved, and preferred content can be displayed directly when the user visits a website again. The user data collected with the help of cookies can also be used for reach measurement. Unless we provide users with explicit information on the type and storage duration of cookies (e.g., within the scope of obtaining consent), they should assume that these are permanent and that the storage duration can be up to two years.

General notes on revocation and objection (opt-out): Users can revoke the consent they have given at any time and also declare an objection to the processing in accordance with the legal requirements, including by means of their browser's privacy settings.

  • Types of data processed: Meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, persons involved).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Consent (Art. 6(1)(a) GDPR).

Further notes on processing operations, procedures, and services:

  • Processing of cookie data based on consent: We use a consent management solution where the consent of users to the use of cookies or to the procedures and providers mentioned within the consent management solution is obtained. This procedure is used to obtain, log, manage, and revoke consent, in particular with regard to the use of cookies and comparable technologies used to store, read, and process information on users' devices. Within the framework of this procedure, users' consent to the use of cookies and the associated processing of information, including the specific processing and providers mentioned in the consent management procedure, is obtained. Users also have the option to manage and revoke their consent. Consent declarations are stored to avoid repeated queries and to be able to provide evidence of consent according to legal requirements. Storage takes place on the server side and/or in a cookie (so-called opt-in cookie) or using comparable technologies to assign the consent to a specific user or their device. Unless specific information on the providers of consent management services is available, the following general information applies: The duration of the storage of consent is up to two years. A pseudonymous user identifier is created and stored together with the time of consent, information on the scope of consent (e.g., respective categories of cookies and/or service providers), and information about the browser, system, and device used; Legal bases: Consent (Art. 6(1)(a) GDPR).

Blogs and Publication Media

We use blogs or comparable means of online communication and publication (hereinafter "publication medium"). Readers' data is processed for the purposes of the publication medium only to the extent necessary for its presentation and communication between authors and readers or for security reasons. For the rest, we refer to the information on processing the visitors of our publication medium within the scope of this privacy policy.

  • Types of data processed: Inventory data (e.g., full name, residential address, contact information, customer number, etc.); Contact data (e.g., postal and email addresses or phone numbers); Content data (e.g., textual or visual messages and posts as well as information relating to them, such as details of authorship or time of creation); Usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, persons involved).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing and legitimate interests: Feedback (e.g., collecting feedback via online form); Provision of our online offer and user-friendliness; Security measures. Organizational and administrative procedures.
  • Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Further notes on processing operations, procedures, and services:

  • Comments and posts: When users leave comments or other posts, their IP addresses may be stored on the basis of our legitimate interests. This is for our security if someone leaves illegal content in comments and posts (insults, prohibited political propaganda, etc.). In this case, we can be prosecuted for the comment or post ourselves and are therefore interested in the author's identity.

    Furthermore, we reserve the right, on the basis of our legitimate interests, to process user information for the purpose of spam detection.

    On the same legal basis, we reserve the right to store the IP addresses of users for the duration of surveys and to use cookies to avoid multiple votes.

    Personal information provided in the context of comments and posts, any contact and website information, as well as the content information, will be stored permanently by us until the user objects; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).

Contact and Inquiry Management

When contacting us (e.g., by post, contact form, email, telephone, or via social media) as well as within the framework of existing user and business relationships, the details of the inquiring persons are processed insofar as this is necessary to answer the contact inquiries and any requested measures.

  • Types of data processed: Contact data (e.g., postal and email addresses or phone numbers); Content data (e.g., textual or visual messages and posts as well as information relating to them, such as details of authorship or time of creation). Meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, persons involved).
  • Data subjects: Communication partners.
  • Purposes of processing and legitimate interests: Communication; Organizational and administrative procedures; Feedback (e.g., collecting feedback via online form). Provision of our online offer and user-friendliness.
  • Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion".
  • Legal bases: Legitimate interests (Art. 6(1)(f) GDPR). Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR).

Further notes on processing operations, procedures, and services:

  • Contact form: When contacting us via our contact form, by email, or other communication channels, we process the personal data transmitted to us to answer and handle the respective request. This usually includes details such as name, contact information, and any other information provided to us that is necessary for appropriate processing. We use this data exclusively for the stated purpose of contact and communication; Legal bases: Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).

Web Analysis, Monitoring, and Optimization

Web analysis (also known as "reach measurement") is used to evaluate the visitor flows to our online offer and may include behavior, interests, or demographic information about visitors, such as age or gender, as pseudonymous values. Using reach analysis, we can identify, for example, at what times our online offer or its functions or content are most frequently used, or invite reuse. It also enables us to understand which areas need optimization.

In addition to web analysis, we may also use testing procedures to test and optimize different versions of our online offer or its components, for example.

Unless stated otherwise below, profiles (i.e., data combined for a usage process) can be created for these purposes, and information can be stored in a browser or on an end device and then read. The information collected includes, in particular, visited websites and the elements used there, as well as technical information, such as the browser used, the computer system used, and information on usage times. If users have consented to the collection of their location data by us or the providers of the services we use, processing of location data is also possible.

Furthermore, users' IP addresses are stored. However, we use an IP masking procedure (i.e., pseudonymization by truncating the IP address) to protect users. Generally, no plain data of users (such as email addresses or names) is stored in the context of web analysis, A/B testing, and optimization, but pseudonyms. This means that both we and the providers of the software used do not know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.

Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data will be processed on the basis of our legitimate interests (i.e., interest in efficient, economic, and recipient-friendly services). In this context, we also refer you to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, persons involved).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing and legitimate interests: Reach measurement (e.g., access statistics, detection of returning visitors); Profiles with user-related information (creating user profiles). Provision of our online offer and user-friendliness.
  • Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion". Storage of cookies for up to 2 years (Unless stated otherwise, cookies and similar storage methods may be stored on users' devices for a period of two years).
  • Security measures: IP masking (pseudonymization of the IP address).
  • Legal bases: Consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Further notes on processing operations, procedures, and services:

  • Google Analytics: We use Google Analytics to measure and analyze the use of our online offer based on a pseudonymous user identification number. This identification number does not contain any unique data such as names or email addresses. It serves to assign analytical information to a device to detect what content users have accessed within one or various usage processes, what search terms they used, whether they revisited or interacted with our online offer. The time of use and its duration are also stored, as well as the sources of users referring to our online offer and technical aspects of their devices and browsers.
    Pseudonymous user profiles are created with information from the use of various devices, and cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides rough geographic location data by deriving the following metadata from IP addresses: City (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, IP address data is strictly used for this derivation of geolocation data before being immediately discarded. They are not logged, are not accessible, and are not used for any additional purposes. When Google Analytics collects measurement data, all IP lookups are performed on EU-based servers before traffic is routed to Analytics servers for processing; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://marketingplatform.google.com/intl/en/about/analytics/; Security measures: IP masking (pseudonymization of the IP address); Privacy Policy: https://business.safety.google/privacy/; Data Processing Agreement: https://business.safety.google/adsprocessorterms/; Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms); Opt-out possibility: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=en, Settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (Types of processing and processed data).

Plug-ins and Embedded Functions as well as Content

We integrate functional and content elements into our online offer that are sourced from the servers of their respective providers (hereinafter referred to as "third-party providers"). This can include, for example, graphics, videos, or city maps (hereinafter uniformly referred to as "content").

The integration always requires that the third-party providers of this content process the users' IP address, as they could not send the content to their browsers without the IP address. The IP address is therefore required for displaying these contents or functions. We strive to use only those contents whose respective providers use the IP address exclusively for delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. The "pixel tags" allow information to be evaluated, such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information regarding the browser and operating system, referring websites, visit times, and other details regarding the use of our online offer, but it may also be linked to such information from other sources.

Notes on legal bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is permission. Otherwise, user data will be processed on the basis of our legitimate interests (i.e., interest in efficient, economic, and recipient-friendly services). In this context, we also refer you to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g., page views and duration of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); Meta, communication, and procedural data (e.g., IP addresses, time information, identification numbers, persons involved). Location data (information on the geographical position of a device or a person).
  • Data subjects: Users (e.g., website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online offer and user-friendliness; Reach measurement (e.g., access statistics, detection of returning visitors); Tracking (e.g., interest/behavior-based profiling, use of cookies); Target group formation. Marketing.
  • Retention and deletion: Deletion in accordance with the information in the section "General Information on Data Retention and Deletion". Storage of cookies for up to 2 years (Unless stated otherwise, cookies and similar storage methods may be stored on users' devices for a period of two years).
  • Legal bases: Consent (Art. 6(1)(a) GDPR). Legitimate interests (Art. 6(1)(f) GDPR).

Further notes on processing operations, procedures, and services:

  • Google Fonts (sourced from Google Server): Sourcing fonts (and symbols) for the purpose of technically safe, maintenance-free, and efficient use of fonts and symbols with regard to up-to-dateness and loading times, their uniform presentation, and consideration of possible licensing restrictions. The IP address of the user is communicated to the provider of the fonts so that the fonts can be made available in the user's browser. In addition, technical data (language settings, screen resolution, operating system, hardware used) is transmitted, which is necessary to provide the fonts depending on the devices and the technical environment used. This data may be processed on a server of the font provider in the USA - When visiting our online offer, users' browsers send their HTTP browser requests to the Google Fonts Web API (i.e., a software interface for retrieving the fonts). The Google Fonts Web API provides users with the Cascading Style Sheets (CSS) of Google Fonts and subsequently the fonts specified in the CCS. These HTTP requests include (1) the IP address used by the respective user to access the Internet, (2) the requested URL on the Google server, and (3) the HTTP headers, including the User Agent describing the website visitor's browser and operating system versions, as well as the referral URL (i.e., the web page where the Google font is to be displayed). IP addresses are not logged or stored on Google servers and they are not analyzed. The Google Fonts Web API logs details of the HTTP requests (requested URL, User Agent, and referral URL). Access to this data is restricted and strictly controlled. The requested URL identifies the font families for which the user wants to load fonts. This data is logged so Google can determine how often a particular font family is requested. For the Google Fonts Web API, the User Agent must match the font generated for that specific browser type. The User Agent is primarily logged for debugging and used to generate aggregate usage statistics measuring the popularity of font families. These aggregated usage statistics are published on the Google Fonts "Analytics" page. Finally, the referral URL is logged so the data can be used for production maintenance and an aggregated report on top integrations can be generated based on the number of font requests. Google states that it does not use any of the information collected by Google Fonts to create end-user profiles or serve targeted ads; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://fonts.google.com/; Privacy Policy: https://business.safety.google/privacy/; Basis for third-country transfers: Data Privacy Framework (DPF). Further information: https://developers.google.com/fonts/faq/privacy?hl=en.
  • Google Maps: We integrate the maps of the "Google Maps" service provided by Google. The processed data may include, in particular, IP addresses and location data of users; Service Provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://mapsplatform.google.com/; Privacy Policy: https://business.safety.google/privacy/. Basis for third-country transfers: Data Privacy Framework (DPF).
  • YouTube Videos: Video content; Service Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal bases: Consent (Art. 6(1)(a) GDPR); Website: https://www.youtube.com; Privacy Policy: https://business.safety.google/privacy/; Basis for third-country transfers: Data Privacy Framework (DPF). Opt-out possibility: Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=en, Settings for the display of advertisements: https://myadcenter.google.com/personalizationoff.

Data Protection Information for Whistleblowers

In this section, you will find information on how we handle data from persons who provide tips (whistleblowers) as well as data from affected and involved parties as part of our whistleblowing procedure. Our goal is to provide a secure, uncomplicated, and confidential way to report violations without fear of reprisal.

Legal bases: Insofar as we process data to fulfill our legal obligations in accordance with the German Whistleblower Protection Act (HinSchG), the legal basis for processing is Article 6(1)(c) GDPR and, in the case of special categories of personal data, Article 9(2)(g) GDPR in conjunction with Section 10 HinSchG. This refers to the obligation to establish and operate an internal reporting channel, the fulfillment of statutory tasks, and the implementation of necessary follow-up actions and investigations.

Types of data processed: We may collect various data as part of receiving and processing reports. These include, in particular: Name, contact details, and location of the reporting person (if provided voluntarily); names and data of potential witnesses or persons affected by the report; data regarding the alleged misconduct; and any further relevant details provided to us during the investigation.

Special categories of personal data: It may occur that we collect special categories of personal data, in particular when these are communicated by a whistleblower (e.g., health-related data or data revealing racial or ethnic origin), provided this is strictly necessary to investigate the specific report.

Anonymity and Confidentiality: You have the option to submit reports anonymously. To ensure the security of your data when using online forms, we recommend accessing them in your browser's private or 'Incognito' mode. If you choose to provide your name and contact details, your identity will be kept strictly confidential and will only be disclosed to the internal individuals explicitly responsible for receiving and processing the reports.

Providing data to third parties: Data related to the submitted reports will only be forwarded to third parties if there is a strict legal obligation to do so (e.g., to public authorities, government, regulatory, or tax authorities). We may also engage external lawyers or specialized professional advisors to investigate suspected misconduct and take necessary actions. These parties are contractually bound to strict confidentiality and data protection regulations.

Data retention and deletion: Personal data is processed only as long as necessary to fulfill the processing purposes described above. According to legal requirements, documentation of reports is generally kept for up to three years after the conclusion of the procedure. If the data is no longer necessary for these purposes or for initiating legal steps, it is deleted immediately.

  • Types of data processed: Inventory data, employee data, contact data, content data, and usage data.
  • Data subjects: Employees, third parties, and whistleblowers.
  • Purposes of processing and legitimate interests: Whistleblower protection and compliance with legal obligations.
  • Retention and deletion: Deletion in accordance with legal retention periods (usually up to 3 years after case closure).
  • Legal bases: Legal obligation (Art. 6(1)(c) GDPR); Consent (Art. 6(1)(a) GDPR); Legitimate interests (Art. 6(1)(f) GDPR).

Changes and Updates

We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g., consent) or other individual notification.

If we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time and we ask you to verify the details before contacting them.

Definitions of Terms

In this section, you will find an overview of the terms used in this privacy policy. Insofar as the terms are defined by law, their legal definitions apply. The following explanations are primarily intended to aid understanding.

  • Employees: Employees are persons who are in an employment relationship, whether as staff, salaried employees, or in similar positions. An employment relationship is a legal relationship between an employer and an employee, established by an employment contract or agreement. It involves the employer's obligation to pay the employee remuneration while the employee performs their work. The employment relationship includes several phases, including its inception when the employment contract is concluded, execution when the employee performs their work duties, and termination when the employment relationship ends, whether through dismissal, termination agreement, or otherwise. Employee data is all information relating to these persons and placed in the context of their employment. This includes aspects such as personal identification data, identification numbers, salary and bank details, working hours, leave entitlements, health data, and performance appraisals.
  • Inventory data: Inventory data comprises essential information necessary for the identification and management of contract partners, user accounts, profiles, and similar assignments. This data can include personal and demographic details such as names, contact information (addresses, phone numbers, email addresses), dates of birth, and specific identifiers (user IDs). Inventory data forms the basis for any formal interaction between individuals and services, facilities, or systems by enabling clear assignment and communication.
  • Content data: Content data encompasses information generated in the course of creating, editing, and publishing content of all kinds. This category of data can include texts, images, videos, audio files, and other multimedia content published on various platforms and media. Content data is not limited to the actual content but also includes metadata that provides information about the content itself, such as tags, descriptions, author information, and publication dates.
  • Contact data: Contact data is essential information that enables communication with individuals or organizations. It includes, among other things, phone numbers, postal addresses, and email addresses, as well as means of communication like social media handles and instant messaging identifiers.
  • Meta, communication, and procedural data: Meta, communication, and procedural data are categories that contain information about how data is processed, transmitted, and managed. Metadata, also known as data about data, includes information that describes the context, origin, and structure of other data. It can contain details such as file size, creation date, the author of a document, and version histories. Communication data records the exchange of information between users across various channels, such as email traffic, call logs, social network messages, and chat histories, including the people involved, timestamps, and transmission paths. Procedural data describes the processes and workflows within systems or organizations, including workflow documentation, transaction and activity logs, as well as audit logs used to track and verify operations.
  • Usage data: Usage data refers to information that captures how users interact with digital products, services, or platforms. This data covers a wide range of information indicating how users utilize applications, which features they prefer, how long they stay on certain pages, and the paths they take to navigate through an application. Usage data can also include the frequency of use, timestamps of activities, IP addresses, device information, and location data. It is particularly valuable for analyzing user behavior, optimizing user experiences, personalizing content, and improving products or services. In addition, usage data plays a crucial role in identifying trends, preferences, and potential problem areas within digital offerings.
  • Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles with user-related information: The processing of "profiles with user-related information", or simply "profiles", encompasses any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person (depending on the type of profiling, this can include analyzing or predicting various information regarding demographics, behavior, and interests, such as interaction with websites and their contents, etc.) (e.g., interests in certain contents or products, click behavior on a website, or location). Cookies and web beacons are frequently used for profiling purposes.
  • Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages, and other details about the use or operation of a system. Log data is often used for analyzing system problems, security monitoring, or generating performance reports.
  • Reach measurement: Reach measurement (also known as web analytics) is used to evaluate visitor flows to an online offer and can cover the behavior or interests of visitors in certain information, such as website content. Using reach analysis, operators of online offers can identify, for example, at what time users visit their websites and what content they are interested in. This enables them to better adapt website content to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are frequently used to recognize returning visitors and thus obtain more accurate analyses of the use of an online offer.
  • Location data: Location data is created when a mobile device (or another device with the technical requirements for location determination) connects to a radio cell, a WLAN, or similar technical means and functions of location determination. Location data is used to indicate the geographically determinable position on earth where the respective device is located. Location data can be used, for example, to display map functions or other location-dependent information.
  • Tracking: "Tracking" refers to the ability to trace user behavior across multiple online offers. Generally, concerning the online offers used, behavioral and interest information is stored in cookies or on the servers of the providers of tracking technologies (so-called profiling). This information can then be used, for example, to show users advertisements that are likely to correspond to their interests.
  • Controller: "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: "Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means. The term is broad and covers practically any handling of data, be it collection, evaluation, storage, transmission, or deletion.
  • Target group formation: Target group formation (or "Custom Audiences") refers to determining target groups for advertising purposes, e.g., displaying ads. For example, based on a user's interest in certain products or topics on the Internet, it can be concluded that this user is interested in ads for similar products or the online shop where they viewed the products. "Lookalike Audiences" (or similar target groups) refers to content deemed suitable being shown to users whose profiles or interests presumably match those of the users for whom the profiles were created. Cookies and web beacons are typically used for creating Custom Audiences and Lookalike Audiences.

Created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke