Datenschutz
Privacy Policy
Privacy Policy
This Privacy Policy explains the nature, scope, and purpose of the processing of personal data (hereinafter referred to as “data”) within our online offering and the websites, functions, and content associated with it, as well as external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”). With regard to the terminology used, such as “processing” or “controller,” we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Controller
Rosenberg LLC
30 N Gould St STE N
Sheridan, WY 82801
United States
Email: info@rosenbergperformance.com
Website: www.rosenbergperformance.com
Legal Notice: www.rosenbergperformance.com/impressum
Privacy Policy: www.rosenbergperformance.com/datenschutz
Types of Data Processed
- Inventory data (e.g. names, addresses)
- Contact data (e.g. email addresses, telephone numbers)
- Content data (e.g. text entries, photographs, videos)
- Usage data (e.g. visited websites, interest in content, access times)
- Meta/communication data (e.g. device information, IP addresses)
Purpose of Processing
- Provision of the online offering, its functions, and contents
- Responding to contact inquiries and communication with users
- Security measures
- Reach measurement/marketing
Definitions Used
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter “data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data.
“Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Applicable Legal Bases
In accordance with Article 13 GDPR, we inform you of the legal bases of our data processing activities. If the legal basis is not specifically stated in this Privacy Policy, the following applies: the legal basis for obtaining consent is Article 6(1)(a) and Article 7 GDPR; the legal basis for processing for the purpose of fulfilling our services, carrying out contractual measures, and responding to inquiries is Article 6(1)(b) GDPR; the legal basis for processing to fulfill our legal obligations is Article 6(1)(c) GDPR; and the legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) GDPR. In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) GDPR serves as the legal basis.
Security Measures
We ask you to regularly inform yourself about the contents of our Privacy Policy. We adapt the Privacy Policy as soon as changes in the data processing activities carried out by us make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.
Cooperation with Processors and Third Parties
If, in the course of our processing, we disclose data to other persons or companies (processors or third parties), transfer it to them, or otherwise grant them access to the data, this will only take place on the basis of legal permission (e.g. if a transfer of the data to third parties, such as payment service providers, is necessary for contract fulfillment pursuant to Article 6(1)(b) GDPR), if you have consented, if a legal obligation provides for this, or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).
If we commission third parties to process data on the basis of a so-called “data processing agreement,” this is done on the basis of Article 28 GDPR.
Transfers to Third Countries
If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if this takes place in the context of the use of third-party services or disclosure or transfer of data to third parties, this will only take place if it is necessary to fulfill our (pre-)contractual obligations, on the basis of your consent, on the basis of a legal obligation, or on the basis of our legitimate interests. Subject to legal or contractual permissions, we only process or allow data to be processed in a third country if the special requirements of Articles 44 et seq. GDPR are met. This means, for example, that processing is carried out on the basis of special guarantees, such as an officially recognized determination of a data protection level equivalent to that of the EU or compliance with officially recognized specific contractual obligations (so-called “Standard Contractual Clauses”).
Rights of Data Subjects
You have the right to request confirmation as to whether the data in question is being processed and to receive information about this data as well as further information and a copy of the data in accordance with Article 15 GDPR.
In accordance with Article 16 GDPR, you have the right to request completion of data concerning you or correction of inaccurate data concerning you.
In accordance with Article 17 GDPR, you have the right to request that data concerning you be deleted without undue delay, or alternatively, in accordance with Article 18 GDPR, to request restriction of the processing of the data.
You have the right to request to receive the data concerning you which you have provided to us in accordance with Article 20 GDPR and to request its transfer to other controllers.
You also have the right, pursuant to Article 77 GDPR, to lodge a complaint with the competent supervisory authority.
Right to Withdraw Consent
You have the right to withdraw any consent you have given pursuant to Article 7(3) GDPR with effect for the future.
Right to Object
You may object at any time to the future processing of data concerning you in accordance with Article 21 GDPR. In particular, the objection may be made against processing for direct marketing purposes.
Cookies and Right to Object to Direct Marketing
“Cookies” are small files that are stored on users’ computers. Different information can be stored within cookies. A cookie primarily serves to store information about a user (or the device on which the cookie is stored) during or even after their visit within an online offering.
Temporary cookies, also called “session cookies” or “transient cookies,” are cookies that are deleted after a user leaves an online offering and closes their browser. Such a cookie may, for example, store the contents of a shopping cart in an online shop or a login status. “Permanent” or “persistent” cookies remain stored even after the browser is closed. For example, the login status can be stored if users visit the site again after several days. Likewise, such a cookie can store users’ interests, which are used for reach measurement or marketing purposes. “Third-party cookies” are cookies offered by providers other than the controller operating the online offering (otherwise, if they are only the controller’s cookies, these are called “first-party cookies”).
We may use temporary and permanent cookies and provide information about this within the framework of this Privacy Policy.
If users do not want cookies to be stored on their computer, they are asked to deactivate the corresponding option in their browser settings. Stored cookies can be deleted in the browser settings. Excluding cookies may lead to functional limitations of this online offering.
A general objection to the use of cookies used for online marketing purposes can be declared for many services, especially in the case of tracking, via the US site https://www.aboutads.info/choices/ or the EU site https://www.youronlinechoices.com/. Furthermore, the storage of cookies can be prevented by disabling them in the browser settings. Please note that in this case, not all functions of this online offering may be available.
Deletion of Data
The data processed by us is deleted or restricted in its processing in accordance with Articles 17 and 18 GDPR. Unless explicitly stated otherwise within this Privacy Policy, the data stored by us will be deleted as soon as it is no longer necessary for its intended purpose and no statutory retention obligations prevent deletion. If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted. This means the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
According to statutory requirements in Germany, retention is carried out in particular for 10 years in accordance with Sections 147(1) AO, 257(1) nos. 1 and 4, para. 4 HGB (books, records, management reports, booking documents, commercial books, documents relevant for taxation, etc.) and 6 years pursuant to Section 257(1) nos. 2 and 3, para. 4 HGB (commercial letters).
According to statutory requirements in Austria, retention is carried out in particular for 7 years pursuant to Section 132(1) BAO (accounting documents, receipts/invoices, accounts, vouchers, business papers, records of income and expenses, etc.), for 22 years in connection with real estate, and for 10 years for documents relating to electronically supplied services, telecommunications, radio and television services provided to non-business customers in EU member states and for which the Mini-One-Stop-Shop (MOSS) is used.
Hosting
The hosting services we use serve to provide the following services: infrastructure and platform services, computing capacity, storage space and database services, security services, and technical maintenance services that we use for the purpose of operating this online offering.
In doing so, we or our hosting provider process inventory data, contact data, content data, contract data, usage data, meta and communication data of customers, prospective customers, and visitors to this online offering on the basis of our legitimate interests in an efficient and secure provision of this online offering pursuant to Article 6(1)(f) GDPR in conjunction with Article 28 GDPR (conclusion of a data processing agreement).
Collection of Access Data and Log Files
We, or our hosting provider, collect data about every access to the server on which this service is located on the basis of our legitimate interests within the meaning of Article 6(1)(f) GDPR (so-called server log files). Access data includes the name of the website accessed, file, date and time of access, amount of data transferred, notification of successful access, browser type along with version, the user’s operating system, referrer URL (the previously visited page), IP address, and the requesting provider.
Log file information is stored for security reasons (e.g. to investigate misuse or fraud) for a maximum of 7 days and then deleted. Data whose further retention is required for evidentiary purposes is excluded from deletion until the respective incident has been finally clarified.
Agency Services
We process the data of our customers within the scope of our contractual services, which include conceptual and strategic consulting, campaign planning, software and design development/consulting or maintenance, implementation of campaigns and processes/handling, server administration, data analysis/consulting services, and training services.
In doing so, we process inventory data (e.g. customer master data such as names or addresses), contact data (e.g. email, phone numbers), content data (e.g. text entries, photographs, videos), contract data (e.g. contract subject, term), payment data (e.g. bank details, payment history), usage and metadata (e.g. as part of the analysis and measurement of the success of marketing measures). We generally do not process special categories of personal data unless these are components of commissioned processing. Data subjects include our customers, prospective customers, and their customers, users, website visitors or employees, as well as third parties. The purpose of processing is the provision of contractual services, billing, and our customer service. The legal bases of processing result from Article 6(1)(b) GDPR (contractual services), Article 6(1)(f) GDPR (analysis, statistics, optimization, security measures). We process data that is necessary for the establishment and fulfillment of contractual services and point out the necessity of its provision. Disclosure to external parties only takes place if it is required within the scope of an order. When processing data provided to us within the scope of an order, we act in accordance with the instructions of the client and the statutory requirements of order processing pursuant to Article 28 GDPR and do not process the data for any purposes other than those specified in the order.
We delete the data after the expiry of statutory warranty and comparable obligations. The necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, deletion occurs after their expiry (6 years pursuant to Section 257(1) HGB, 10 years pursuant to Section 147(1) AO). In the case of data disclosed to us by the client within the scope of an order, we delete the data in accordance with the specifications of the order, generally after the end of the order.
Administration, Financial Accounting, Office Organization, Contact Management
We process data in the context of administrative tasks as well as organization of our operations, financial accounting, and compliance with legal obligations, such as archiving. In doing so, we process the same data that we process in the context of providing our contractual services. The legal bases for processing are Article 6(1)(c) GDPR and Article 6(1)(f) GDPR. Customers, prospective customers, business partners, and website visitors are affected by the processing. The purpose and our interest in processing lie in administration, financial accounting, office organization, archiving of data, i.e. tasks that serve to maintain our business operations, perform our tasks, and provide our services. The deletion of data with regard to contractual services and contractual communication corresponds to the information provided in these processing activities.
In doing so, we disclose or transfer data to tax authorities, consultants such as tax advisors or auditors, as well as other fee offices and payment service providers.
Furthermore, on the basis of our business management interests, we store information on suppliers, event organizers, and other business partners, e.g. for the purpose of later contact. We generally store this mostly business-related data permanently.
Business Analysis and Market Research
In order to operate our business economically, identify market trends, customer wishes, and user needs, we analyze the data available to us on business transactions, contracts, inquiries, etc. We process inventory data, communication data, contract data, payment data, usage data, and metadata on the basis of Article 6(1)(f) GDPR, whereby the persons concerned include customers, prospective customers, business partners, visitors, and users of the online offering.
The analyses are carried out for the purpose of business evaluations, marketing, and market research. We may consider the profiles of registered users with information such as their purchasing transactions. The analyses serve us to increase user-friendliness, optimize our offering, and improve economic efficiency. The analyses serve only us and are not disclosed externally unless they are anonymous analyses with summarized values.
If these analyses or profiles are personal, they are deleted or anonymized upon termination of the users, otherwise after two years from conclusion of the contract. In addition, the overall business analyses and general trend determinations are created anonymously wherever possible.
Contact
When contacting us (e.g. via contact form, email, telephone, or social media), the user’s details are processed for handling the contact request and its execution in accordance with Article 6(1)(b) GDPR. Users’ details may be stored in a Customer Relationship Management System (“CRM system”) or comparable inquiry organization.
We delete the inquiries if they are no longer required. We review the necessity every two years; furthermore, the statutory archiving obligations apply.
Comments and Contributions
If users leave comments or other contributions, their IP addresses may be stored for 7 days on the basis of our legitimate interests within the meaning of Article 6(1)(f) GDPR. This is done for our security in case someone leaves unlawful content in comments and contributions (insults, prohibited political propaganda, etc.). In this case, we ourselves can be held liable for the comment or contribution and are therefore interested in the identity of the author.
Furthermore, we reserve the right, on the basis of our legitimate interests pursuant to Article 6(1)(f) GDPR, to process users’ information for the purpose of spam detection.
Akismet Anti-Spam Check
Our online offering uses the service “Akismet,” offered by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. Use is based on our legitimate interests within the meaning of Article 6(1)(f) GDPR. With the help of this service, comments from real people are distinguished from spam comments. For this purpose, all comment information is sent to a server in the USA, where it is analyzed and stored for comparison purposes for four days. If a comment is classified as spam, the data is stored beyond this period. This information includes the entered name, email address, IP address, comment content, referrer, information about the browser used and the computer system, and the time of the entry.
Further information on the collection and use of data by Akismet can be found in Automattic’s privacy notices: https://automattic.com/privacy/.
Users are welcome to use pseudonyms or refrain from entering their name or email address. They can completely prevent the transfer of data by not using our comment system. That would be unfortunate, but unfortunately we see no alternatives that work just as effectively.
Retrieval of Profile Pictures via Gravatar
We use the service Gravatar from Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA within our online offering and especially in the blog.
Gravatar is a service where users can register and store profile pictures and their email addresses. If users leave contributions or comments on other online presences (especially in blogs) with the respective email address, their profile pictures can be displayed next to the contributions or comments. For this purpose, the email address provided by the users is transmitted to Gravatar in encrypted form for the purpose of checking whether a profile is stored for it. This is the sole purpose of transmitting the email address and it is not used for other purposes but is deleted afterwards.
The use of Gravatar is based on our legitimate interests within the meaning of Article 6(1)(f) GDPR, as we use Gravatar to offer contribution and comment authors the possibility of personalizing their contributions with a profile picture.
By displaying the images, Gravatar obtains the users’ IP address, as this is necessary for communication between a browser and an online service. More information on the collection and use of data by Gravatar can be found in Automattic’s privacy notices: https://automattic.com/privacy/.
If users do not want an avatar linked to their email address at Gravatar to appear in comments, they should use an email address that is not stored with Gravatar. We also point out that it is possible to use an anonymous or no email address at all if users do not wish their own email address to be transmitted to Gravatar. Users can completely prevent the transfer of data by not using our comment system.
VG Wort / Scalable Central Measurement Procedure
We use the “Scalable Central Measurement Procedure” (SZM) of INFOnline GmbH (INFOnline GmbH, Brühler Str. 9, D-53119 Bonn, Germany) to determine statistical parameters for determining the probability of text copying. Anonymous measurement values are collected in the process. To recognize computer systems, access measurement alternatively uses a session cookie or a signature created from various automatically transmitted information from your browser. IP addresses are only processed in anonymized form. The procedure was developed with data protection in mind. Its sole purpose is to determine the probability of copying individual texts. At no time are individual users identified. Your identity always remains protected. You will not receive advertising through the system.
Many of our pages are equipped with JavaScript calls through which we report access to Verwertungsgesellschaft Wort (VG Wort). This enables our authors to participate in the distributions of VG Wort, which ensure the statutory remuneration for the use of copyrighted works pursuant to Section 53 UrhG.
Usage data and metadata of users are processed, whereby IP addresses are shortened and the measurement procedures are pseudonymous. The shortened IP address is stored for a maximum of 60 days. Usage data in connection with a pseudonymous identifier is stored for a maximum of 6 months.
Users also have the option to opt out of collection for the aforementioned purposes: https://optout.ioam.de. Further information can be found in INFOnline’s privacy policy: https://www.infonline.de/datenschutz/benutzer.
Google Re/Marketing Services
On the basis of our legitimate interests (i.e. interest in the analysis, optimization, and economic operation of our online offering within the meaning of Article 6(1)(f) GDPR), we use the marketing and remarketing services (hereinafter “Google Marketing Services”) of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”).
Google Marketing Services allow us to display advertisements for and on our website in a more targeted way in order to present users only with ads that potentially match their interests. If, for example, a user is shown ads for products they were interested in on other websites, this is referred to as “remarketing.” For these purposes, when our website and other websites on which Google Marketing Services are active are accessed, Google directly executes a code from Google and so-called (re)marketing tags (invisible graphics or code, also referred to as “web beacons”) are integrated into the website. With their help, an individual cookie, i.e. a small file, is stored on the user’s device (comparable technologies may be used instead of cookies). The cookies may be set by various domains, including google.com, doubleclick.net, invitemedia.com, admeld.com, googlesyndication.com, or googleadservices.com. This file records which websites the user visited, what content they are interested in, and which offers they clicked on, as well as technical information about the browser and operating system, referring websites, visit time, and other details regarding the use of the online offering. The IP address of users is also collected, whereby, within the framework of Google Analytics, we inform that the IP address is shortened within member states of the European Union or in other contracting states to the Agreement on the European Economic Area and is only transmitted in full to a Google server in the USA and shortened there in exceptional cases. The IP address is not merged with the user’s data within other Google services. The above information may also be combined by Google with such information from other sources. If the user then visits other websites, they may be shown ads tailored to their interests.
Users’ data is processed pseudonymously within the framework of Google Marketing Services. This means that Google does not store and process users’ names or email addresses, but processes the relevant data cookie-related within pseudonymous user profiles. From Google’s perspective, the ads are therefore not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who that cookie holder is. This does not apply if a user has expressly allowed Google to process the data without this pseudonymization. The information collected by Google Marketing Services about users is transmitted to Google and stored on Google’s servers in the USA.
The Google Marketing Services we use include the online advertising program “Google AdWords.” In the case of Google AdWords, each AdWords customer receives a different “conversion cookie.” Cookies can therefore not be tracked across the websites of AdWords customers. The information obtained using the cookie is used to create conversion statistics for AdWords customers who have opted for conversion tracking. AdWords customers learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that could personally identify users.
We may incorporate third-party advertisements on the basis of the Google Marketing Service “AdSense.” AdSense uses cookies that enable Google and its partner websites to place ads based on users’ visits to this website and/or other websites on the internet.
We may also use “Google Tag Manager” to integrate and manage Google analysis and marketing services on our website.
Further information on Google’s use of data for marketing purposes can be found on the overview page: https://www.google.com/policies/technologies/ads. Google’s privacy policy is available at: https://www.google.com/policies/privacy.
If you wish to object to interest-based advertising by Google Marketing Services, you can use the settings and opt-out options provided by Google: https://www.google.com/ads/preferences.
Facebook Pixel, Custom Audiences and Facebook Conversion
Within our online offering, the so-called “Facebook Pixel” of the social network Facebook is used on the basis of our legitimate interests in analysis, optimization, and economic operation of our online offering and for these purposes. Facebook is operated by Meta Platforms, Inc. and, for users in the EU, by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”).
With the help of the Facebook Pixel, Facebook is able to determine visitors to our online offering as a target group for the display of advertisements (so-called “Facebook Ads”). Accordingly, we use the Facebook Pixel in order to display the Facebook Ads placed by us only to those Facebook users who have also shown an interest in our online offering or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of visited websites) that we transmit to Facebook (so-called “Custom Audiences”). With the help of the Facebook Pixel, we also want to ensure that our Facebook Ads correspond to the potential interests of users and are not annoying. With the help of the Facebook Pixel, we can also track the effectiveness of Facebook advertisements for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook advertisement (so-called “conversion”).
Facebook’s processing of data takes place within the framework of Facebook’s data usage policy. Accordingly, general information on the display of Facebook Ads can be found in Facebook’s data usage policy: https://www.facebook.com/policy.php. Specific information and details about the Facebook Pixel and its functionality can be found in Facebook’s help area: https://www.facebook.com/business/help/651294705016616.
You can object to the collection by the Facebook Pixel and use of your data for the display of Facebook Ads. To set which types of advertisements are displayed to you within Facebook, you can visit the page set up by Facebook and follow the instructions regarding the settings for usage-based advertising: https://www.facebook.com/settings?tab=ads. The settings are platform-independent, i.e. they are applied to all devices, such as desktop computers or mobile devices.
You can also object to the use of cookies that serve reach measurement and advertising purposes via the deactivation page of the Network Advertising Initiative (https://optout.networkadvertising.org/), as well as the US website (https://www.aboutads.info/choices) or the European website (https://www.youronlinechoices.com/uk/your-ad-choices/).
Online Presence in Social Media
We maintain online presences within social networks and platforms in order to communicate with customers, interested parties, and users active there and to inform them about our services there. When accessing the respective networks and platforms, the terms and conditions and the data processing guidelines of their respective operators apply.
Unless otherwise stated within our Privacy Policy, we process users’ data if they communicate with us within the social networks and platforms, e.g. write posts on our online presences or send us messages.
Integration of Third-Party Services and Content
Within our online offering, we use content or service offers from third-party providers on the basis of our legitimate interests (i.e. interest in the analysis, optimization, and economic operation of our online offering within the meaning of Article 6(1)(f) GDPR) in order to integrate their content and services, such as videos or fonts (hereinafter uniformly referred to as “content”).
This always presupposes that the third-party providers of this content perceive the users’ IP address, since they could not send the content to their browser without the IP address. The IP address is therefore required for the display of this content. We endeavor to use only such content whose respective providers use the IP address only to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. Through pixel tags, information such as visitor traffic on the pages of this website can be evaluated. The pseudonymous information may also be stored in cookies on users’ devices and may include technical information on the browser and operating system, referring websites, visit time, and other information on the use of our online offering, and may also be linked to such information from other sources.
Vimeo
We may embed videos from the platform “Vimeo” of the provider Vimeo Inc., Attention: Legal Department, 555 West 18th Street, New York, New York 10011, USA. Privacy Policy: https://vimeo.com/privacy. Please note that Vimeo may use Google Analytics and we refer in this regard to Google’s Privacy Policy (https://www.google.com/policies/privacy), as well as opt-out options for Google Analytics (https://tools.google.com/dlpage/gaoptout?hl=en) or Google’s settings for the use of data for marketing purposes (https://adssettings.google.com/).
YouTube
We embed videos from the platform “YouTube” of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.
Google Fonts
We integrate the fonts (“Google Fonts”) of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.
Google reCAPTCHA
We integrate the function for detecting bots, e.g. for entries in online forms (“reCAPTCHA”) from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.
Google Maps
We integrate maps of the service “Google Maps” from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The processed data may include, in particular, IP addresses and location data of users, which, however, are not collected without their consent (usually as part of the settings of their mobile devices). The data may be processed in the USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.
OpenStreetMap
We integrate maps of the service “OpenStreetMap” (https://www.openstreetmap.org), which are offered by the OpenStreetMap Foundation (OSMF) under the Open Data Commons Open Database License (ODbL). Privacy Policy: https://wiki.openstreetmap.org/wiki/Privacy_Policy.
To the best of our knowledge, OpenStreetMap uses users’ data exclusively for the purposes of displaying map functions and temporarily storing selected settings. This data may include, in particular, IP addresses and location data of users, which, however, are generally not collected without their consent (usually as part of the settings of their mobile devices). The data may be processed in the USA. Further information can be found in OpenStreetMap’s Privacy Policy: https://wiki.openstreetmap.org/wiki/Privacy_Policy.
Use of Facebook Social Plugins
On the basis of our legitimate interests (i.e. interest in the analysis, optimization, and economic operation of our online offering within the meaning of Article 6(1)(f) GDPR), we use social plugins (“plugins”) of the social network facebook.com, operated by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”). The plugins may display interaction elements or content (e.g. videos, graphics, or text contributions) and can be recognized by one of the Facebook logos (white “f” on blue tile, the terms “Like”, “Gefällt mir”, or a “thumbs up” sign) or are marked with the addition “Facebook Social Plugin.” The list and appearance of Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins/.
When a user calls up a function of this online offering that contains such a plugin, their device establishes a direct connection with Facebook’s servers. The content of the plugin is transmitted by Facebook directly to the user’s device and integrated into the online offering by it. In the process, user profiles can be created from the processed data. We therefore have no influence on the extent of the data that Facebook collects with the help of this plugin and inform users accordingly to the best of our knowledge.
Through the integration of the plugins, Facebook receives the information that a user has accessed the corresponding page of the online offering. If the user is logged into Facebook, Facebook can assign the visit to their Facebook account. If users interact with the plugins, for example by pressing the Like button or leaving a comment, the corresponding information is transmitted directly from their device to Facebook and stored there. If a user is not a member of Facebook, it is still possible that Facebook will learn and store their IP address. According to Facebook, only an anonymized IP address is stored in Germany.
Purpose and scope of data collection and the further processing and use of the data by Facebook, as well as the related rights and setting options for protecting the privacy of users, can be found in Facebook’s privacy notices: https://www.facebook.com/about/privacy/.
If a user is a Facebook member and does not want Facebook to collect data about them via this online offering and link it with their member data stored on Facebook, they must log out of Facebook before using our online offering and delete their cookies. Further settings and objections to the use of data for advertising purposes are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US page https://www.aboutads.info/choices/ or the EU page https://www.youronlinechoices.com/. The settings are platform-independent, i.e. they are applied to all devices, such as desktop computers or mobile devices.
Twitter / X
Functions and content of the service Twitter/X, offered by X Corp. or its affiliated providers, may be integrated within our online offering. This may include content such as images, videos, or text and buttons that users can use to express their appreciation regarding the content, subscribe to the authors of the content, or to our posts. If users are members of the platform Twitter/X, Twitter/X may assign the access to the above-mentioned content and functions to the profiles of the users there. Privacy Policy: https://twitter.com/privacy.
Functions and content of the service Instagram, offered by Meta Platforms, may be integrated within our online offering. This may include content such as images, videos, or text and buttons with which users can express their appreciation regarding the content, subscribe to the authors of the content, or to our posts. If users are members of the platform Instagram, Instagram may assign access to the above-mentioned content and functions to the profiles of the users there. Instagram Privacy Policy: https://instagram.com/about/legal/privacy/.
Functions and content of the service Pinterest, offered by Pinterest Inc., 635 High Street, Palo Alto, CA 94301, USA, may be integrated within our online offering. This may include content such as images, videos, or text and buttons with which users can express their appreciation regarding the content, subscribe to the authors of the content, or to our posts. If users are members of the platform Pinterest, Pinterest may assign access to the above-mentioned content and functions to the profiles of the users there. Pinterest Privacy Policy: https://about.pinterest.com/privacy-policy.
Functions and content of the service Xing, offered by New Work SE, Am Strandkai 1, 20457 Hamburg, Germany, may be integrated within our online offering. This may include content such as images, videos, or text and buttons with which users can express their appreciation regarding the content, subscribe to the authors of the content, or to our posts. If users are members of the platform Xing, Xing may assign access to the above-mentioned content and functions to the profiles of the users there. Xing Privacy Policy: https://privacy.xing.com/en/privacy-policy.
Functions and content of the service LinkedIn, offered by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, may be integrated within our online offering. This may include content such as images, videos, or text and buttons with which users can express their appreciation regarding the content, subscribe to the authors of the content, or to our posts. If users are members of the platform LinkedIn, LinkedIn may assign access to the above-mentioned content and functions to the profiles of the users there. LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy. Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
