Privacy policy
Preamble
With the following privacy policy we would like to inform you about which types of your personal data (hereinafter also referred to in short as "data") we process, for which purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: 29 July 2026
Table of contents
- Preamble
- Controller
- Overview of processing operations
- Applicable legal bases
- Security measures
- Handling of government requests for information
- General information on data storage and erasure
- Rights of data subjects
- Business services
- Payment procedures
- Provision of the online offering and web hosting
- Use of cookies
- Registration, login and user account
- Processing within the PostExpert application
- Contact and enquiry management
- Newsletter and electronic notifications
- Promotional communication via email, post, fax or telephone
- Prize draws and competitions
- Web analytics, monitoring and optimisation
- Online marketing
- Provision of an affiliate programme
- Customer reviews and rating procedures
- Presence in social networks (social media)
- Plug-ins and embedded functions and content
- Data protection information for whistleblowers
- Amendment and updating
- Definitions of terms
Controller
Stefan Fischnaller
Sole proprietor
Mentlgasse 5
6020 Innsbruck, Austria
Email address: info@postexpert.de
Legal notice: https://postexpert.de/en/imprint
Note: for the content of the Instagram accounts that our customers connect to the application, we are not the controller but the processor. Further details can be found in the section “Processing within the PostExpert application”.
Overview of processing operations
The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects concerned.
Types of data processed
- Master data.
- Employee data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Event data (Facebook).
- Log data.
Categories of data subjects
- Recipients of services and clients.
- Employees.
- Prospective customers.
- Communication partners.
- Users.
- Participants in prize draws and competitions.
- Business and contractual partners.
- Third parties.
- Whistleblowers.
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Reach measurement.
- Tracking.
- Office and organisational procedures.
- Conversion measurement.
- Audience building.
- Affiliate tracking.
- Organisational and administrative procedures.
- Running prize draws and competitions.
- Feedback.
- Marketing.
- Profiles with user-related information.
- Login procedures.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
- Whistleblower protection.
- Public relations.
- Sales promotion.
- Business processes and commercial management procedures.
Applicable legal bases
Applicable legal bases under the GDPR: below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements in your or our country of residence or establishment may apply. Should more specific legal bases be relevant in an individual case, we will inform you of these in the privacy policy.
- Consent (Art. 6(1)(1)(a) GDPR) - The data subject has given consent to the processing of personal data concerning them for one specific purpose or several specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR) - Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(1)(c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6(1)(1)(f) GDPR) - processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights and freedoms of the data subject which require the protection of personal data do not override them.
National data protection provisions in Austria: in addition to the data protection provisions of the GDPR, national data protection rules apply in Austria. These include in particular the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act – DSG). The Data Protection Act contains, in particular, special provisions on the right of access, the right to rectification or erasure, the processing of special categories of personal data, processing for other purposes, and transfers as well as automated decision-making in individual cases.
Security measures
In accordance with the statutory requirements and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include in particular safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input of, disclosure of, safeguarding the availability of and separation of the data. Furthermore, we have set up procedures that ensure the exercise of data subject rights, the erasure of data and responses to threats to the data. We also take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.
Securing online connections with TLS/SSL encryption technology (HTTPS): in order to protect users’ data transmitted via our online services against unauthorised access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the further developed and more secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by HTTPS being shown in the URL. This serves as an indicator to users that their data is transmitted securely and in encrypted form.
Handling of government requests for information
Public authorities may require us to disclose personal data. We apply a binding internal policy for this purpose. It is intended to prevent us from disclosing data prematurely or to a greater extent than is legally required. The policy provides for the following steps:
- Legality check before every disclosure: for each request we examine whether the requesting authority has jurisdiction, whether there is a sound legal basis and whether the request is formally proper. We do not respond to informal requests without a recognisable legal basis.
- Objection instead of precautionary disclosure: we object to vague, excessive or legally questionable requests, if necessary after obtaining legal advice. We do not disclose data as a precaution merely because an authority asks for it.
- Data minimisation: we disclose only those records that are specifically covered by the request. We do not hand over complete account exports.
- Documentation: we document every request with the date, the requesting authority, the legal basis, the data disclosed, our legal assessment and the people involved.
- Notification: we inform the data subject about the request, insofar as we are legally permitted to do so.
The legal basis for a disclosure is, in the case of a valid official order, Art. 6(1)(c) GDPR (compliance with a legal obligation), and otherwise Art. 6(1)(f) GDPR (legitimate interest in safeguarding and defending our rights). The recipient is solely the requesting authority concerned and, where applicable, the legal counsel we have instructed. We retain the documentation of requests as evidence of our accountability under Art. 5(2) GDPR and delete it once the statutory retention and limitation periods have expired.
General information on data storage and erasure
We erase the personal data we process in accordance with the statutory provisions as soon as the underlying consents are withdrawn or no further legal bases for the processing exist. This concerns cases in which the original purpose of processing ceases to apply or the data are no longer required. Exceptions to this rule exist where statutory obligations or particular interests require longer storage or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy notices contain additional information on the retention and erasure of data that applies specifically to particular processing operations.
Where several indications are given regarding the retention period or erasure deadlines for a data item, the longest period always applies. Data that are no longer retained for the originally intended purpose but on the basis of statutory requirements or other reasons are processed by us exclusively for the reasons that justify their retention.
Retention and erasure of data: under Austrian law, the following general periods apply to the retention and archiving of personal data, insofar as this is necessary to fulfil legal obligations or to safeguard legitimate interests:
- 7 years Personal data processed in connection with tax-relevant business records are retained for seven years pursuant to § 132 BAO and §§ 190–212 UGB. This includes in particular books and records, annual financial statements, inventories, management reports, opening balance sheets, accounting vouchers, invoices as well as commercial or business letters received and sent and other documents relevant for tax assessment. The period begins at the end of the calendar year for which the last entry was made and is extended where applicable for as long as the documents are relevant to pending tax proceedings.
- 3 years Data required to assert, exercise or defend warranty, damage or other contractual claims are stored for the duration of the applicable statutory limitation period. This is generally three years pursuant to § 1489 ABGB, unless longer statutory retention obligations apply.
Period starting at the end of the year: if a period does not expressly begin on a specific date and is at least one year long, it automatically starts at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships under which data are stored, the triggering event is the point at which the termination takes effect or the legal relationship otherwise ends.
Rights of data subjects
Rights of data subjects under the GDPR: as a data subject you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
- Right to object: you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions. Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent: you have the right to withdraw consent that you have given at any time.
- Right of access: you have the right to request confirmation as to whether data concerning you are being processed and to obtain access to those data as well as further information and a copy of the data in accordance with the statutory requirements.
- Right to rectification: in accordance with the statutory requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: in accordance with the statutory requirements, you have the right to request that data concerning you be erased without delay or, alternatively, to request the restriction of the processing of the data in accordance with the statutory requirements.
- Right to data portability: in accordance with the statutory requirements, you have the right to receive data concerning you which you have provided to us in a structured, commonly used and machine-readable format, or to request that they be transmitted to another controller.
- Complaint to a supervisory authority: without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the requirements of the GDPR.
Competent supervisory authority: the Austrian Data Protection Authority is responsible for us. You can reach it at:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna
Austria
Telephone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Irrespective of this, under Art. 77 GDPR you may also contact the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement. You are welcome to contact us first so that we can resolve your concern — but you are not obliged to.
Business services
We process personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers and other cooperation partners (collectively "contractual partners"), for the initiation, performance and administration of contractual relationships and comparable legal relationships. This also includes pre-contractual measures taken upon request as well as communication in connection with the respective contractual relationship.
The processing serves in particular to fulfil our main and ancillary contractual obligations. These include the provision of the agreed services, any update and information obligations, the handling of warranty claims and other performance disruptions, the processing of withdrawals, terminations of continuing obligations, reversals, refunds as well as the handling of other contract-related declarations and enquiries. Both one-off contracts and ongoing contractual relationships are covered.
In particular, we process master data such as name, address and, where applicable, company, contact data such as email address and telephone number, contract and service data such as the subject matter of the contract, contract term, order or transaction number, usage and service data, payment and billing data as well as communication content and histories. Where necessary, we also process data that is disclosed or transmitted to us in the course of carrying out an order.
In addition, we process the data to safeguard our rights and to comply with legal obligations. This includes in particular retention obligations under commercial and tax law, documentation obligations and, where applicable, evidence and accountability obligations. Processing also takes place on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners against misuse, threats to data, trade secrets and other legally protected interests. This may also include involving external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisers or other vicarious agents, insofar as this is necessary for the performance of the contract or to fulfil legal obligations.
Personal data is only disclosed to third parties to the extent necessary for the performance of the contract, for the implementation of pre-contractual measures, to safeguard legitimate interests or to comply with legal obligations. We provide separate information about any processing that goes beyond this, in particular for marketing purposes, within this privacy policy.
We inform contractual partners which data are required in the individual case as part of the data collection, for example in online forms by means of appropriate labelling or in personal contact.
The data are erased as soon as they are no longer required for the aforementioned purposes and no statutory retention obligations conflict with this. Statutory retention periods, in particular under commercial and tax law, may require longer storage. Data transmitted in the context of a specific order are erased by us after completion of the order and expiry of any retention periods, provided that no further legal or contractual storage obligations exist.
The legal basis for the processing is Art. 6(1)(b) GDPR for carrying out pre-contractual measures and for performing the respective contractual relationship, as well as Art. 6(1)(c) GDPR for compliance with legal obligations. Insofar as the processing is based on legitimate interests, it takes place on the basis of Art. 6(1)(f) GDPR. Where the processing is based on Art. 6(1)(f) GDPR, it serves to safeguard our legitimate interests in a proper and efficient business organisation, the internal administration and documentation of business transactions, the enforcement and defence of legal claims, ensuring IT and data security, preventing misuse and fraud as well as the economic management and further development of our business. These interests consist in particular in ensuring secure and legally compliant business operations and in maintaining our entrepreneurial ability to act.
- Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact data (e.g. postal and email addresses or telephone numbers); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: recipients of services and clients; prospective customers. Business and contractual partners.
- Purposes of processing and legitimate interests: provision of contractual services and fulfilment of contractual obligations; security measures; communication; office and organisational procedures; organisational and administrative procedures. Business processes and commercial management procedures.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure".
- Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); legal obligation (Art. 6(1)(1)(c) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Online shop, order forms, e-commerce and fulfilment of services: we process our customers’ data in order to enable them to select, purchase or order the chosen products and goods as well as associated services, and to pay for and receive, have delivered or have them performed. Where necessary to execute an order, we use service providers, in particular postal, freight forwarding and shipping companies, to carry out the delivery or performance for our customers. For processing payment transactions we use the services of banks and payment service providers. The required details are identified as such in the course of the ordering or comparable purchase process and include the details required for delivery or provision and billing as well as contact information so that any queries can be dealt with; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR).
Payment procedures
In the context of contractual and other legal relationships, on the basis of legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, in addition to banks and credit institutions, use further service providers for this purpose (collectively "payment service providers"). Payment transactions are carried out in line with the state of the art exclusively via encrypted connections, so that the data entered are protected against unauthorised access during transmission.
The data processed by the payment service providers include master data such as name and address, bank details such as account numbers or credit card numbers, passwords, TANs and check digits, as well as contract, amount and recipient-related information. This information is required in order to carry out the transactions. However, the data entered are only processed and stored by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information confirming or declining the payment. In some circumstances the data are transmitted by the payment service providers to credit agencies. The purpose of this transmission is to verify identity and creditworthiness. In this regard we refer to the terms and conditions and the privacy notices of the payment service providers.
The terms and conditions and the privacy notices of the respective payment service providers apply to payment transactions and can be accessed within the respective websites or transaction applications. We also refer to these for further information and for asserting rights of withdrawal, access and other data subject rights.
- Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved). Contact data (e.g. postal and email addresses or telephone numbers).
- Data subjects: recipients of services and clients; business and contractual partners. Prospective customers.
- Purposes of processing and legitimate interests: provision of contractual services and fulfilment of contractual obligations. Business processes and commercial management procedures.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure".
- Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Payments are processed exclusively via the payment service provider Stripe. The payment methods listed below are offered within the Stripe checkout; we do not integrate them separately and have no contractual relationship of our own with their providers. Which methods are available in a given case depends on Stripe and on the country selected.
Further information on processing operations, procedures and services:
- Apple Pay: payment services (technical integration of online payment methods); service provider:Apple Inc., Infinite Loop, Cupertino, CA 95014, USA; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); website: https://www.apple.com/de/apple-pay/. Privacy policy: https://www.apple.com/legal/privacy/de-ww/.
- Google Pay: payment services (technical integration of online payment methods); service provider:Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); website: https://pay.google.com/intl/de_de/about/. Privacy policy: https://business.safety.google/privacy/.
- Mastercard: payment services (technical integration of online payment methods); service provider:Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium; legal bases:performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); website:https://www.mastercard.de/de-de.html. Privacy policy:https://www.mastercard.com/de/de/datenschutz.html.
- PayPal: payment services (technical integration of online payment methods) (e.g. PayPal, PayPal Plus, Braintree); service provider: PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); website:https://www.paypal.com/de. Privacy policy: https://www.paypal.com/de/legalhub/paypal/privacy-full.
- Stripe: payment services (technical integration of online payment methods); service provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); website: https://stripe.com; privacy policy:https://stripe.com/de/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
- Visa: payment services (technical integration of online payment methods); service provider: Visa Europe Services Inc., London Branch, 1 Sheldon Square, London W2 6TT, UK; legal bases:performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR); website: https://www.visa.de. Privacy policy: https://www.visa.de/nutzungsbedingungen/visa-globale-datenschutzmitteilung.html.
Provision of the online offering and web hosting
We process users’ data in order to be able to provide them with our online services. For this purpose we process the user’s IP address, which is necessary in order to transmit the content and functions of our online services to the user’s browser or device.
- Types of data processed: usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved); log data (e.g. log files concerning logins or the retrieval of data or access times.). Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or the time of creation).
- Data subjects: users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: provision of our online offering and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)). Security measures.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure".
- Legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Provision of the online offering on rented storage space: to provide our online offering we use storage space, computing capacity and software which we rent or otherwise obtain from a corresponding server provider (also referred to as a "web host"); legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR).
- Collection of access data and log files: access to our online offering is logged in the form of so-called "server log files". Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volumes of data transferred, notification of successful access, browser type and version, the user’s operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. Server log files may be used, on the one hand, for security purposes, e.g. to avoid overloading the servers (in particular in the case of abusive attacks, so-called DDoS attacks) and, on the other hand, to ensure server utilisation and stability; legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR). Erasure of data: log file information is stored for a maximum of 30 days and then erased or anonymised. Data whose further retention is required for evidentiary purposes are exempt from erasure until the respective incident has been finally clarified.
- Email dispatch and hosting: the web hosting services we use also include the sending, receipt and storage of emails. For these purposes, the addresses of the recipients and senders as well as further information concerning the sending of the email (e.g. the providers involved) and the content of the respective emails are processed. The aforementioned data may also be processed for the purposes of detecting SPAM. Please note that emails on the internet are generally not sent in encrypted form. As a rule, emails are encrypted in transit, but (unless a so-called end-to-end encryption method is used) not on the servers from which they are sent and received. We can therefore accept no responsibility for the transmission path of emails between the sender and receipt on our server; legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR).
- Content delivery network: we use a "content delivery network" (CDN). A CDN is a service with the help of which the content of an online offering, in particular large media files such as graphics or program scripts, can be delivered more quickly and securely using regionally distributed servers connected via the internet; legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR).
Use of cookies
The term "cookies" refers to functions that store information on users’ devices and read information from them. Cookies may also be used for a variety of purposes, for example to ensure the functionality, security and convenience of online offerings as well as to create analyses of visitor flows. We use cookies in accordance with the statutory provisions. Where necessary, we obtain users’ consent in advance. Where consent is not required, we rely on our legitimate interests. This applies where the storage and reading of information is essential in order to provide expressly requested content and functions. This includes, for example, storing settings and ensuring the functionality and security of our online offering. Consent can be withdrawn at any time. We provide clear information about its scope and which cookies are used.
Notes on data protection legal bases: whether we process personal data using cookies depends on consent. If consent has been given, it serves as the legal basis. Without consent we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.
Storage period: with regard to the storage period, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): temporary cookies are deleted at the latest after a user has left an online offering and closed their device (e.g. browser or mobile application).
- Permanent cookies: permanent cookies remain stored even after the device has been closed. For example, the login status can be saved and preferred content displayed directly when the user visits a website again. Likewise, the user data collected with the help of cookies can be used for reach measurement. Unless we provide users with explicit information about the type and storage period of cookies (e.g. when obtaining consent), they should assume that these are permanent and that the storage period can be up to two years.
General information on withdrawal and objection (opt-out): users can withdraw the consent they have given at any time and may also object to the processing in accordance with the statutory requirements, including by means of their browser’s privacy settings.
- Types of data processed: meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: users (e.g. website visitors, users of online services).
- Legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR). Consent (Art. 6(1)(1)(a) GDPR).
Further information on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: we use a consent management solution by means of which users’ consent to the use of cookies or to the procedures and providers named within the consent management solution is obtained. This procedure serves to obtain, log, manage and withdraw consent, in particular with regard to the use of cookies and comparable technologies that are used to store, read and process information on users’ devices. Within this procedure, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing operations and providers named in the consent management procedure. Users also have the option of managing and withdrawing their consent. The declarations of consent are stored in order to avoid having to ask again and to be able to provide proof of consent in accordance with the statutory requirements. Storage takes place on the server side and/or in a cookie (a so-called opt-in cookie) or by means of comparable technologies in order to be able to assign the consent to a specific user or their device. Unless specific information about the providers of consent management services is available, the following general information applies: the consent is stored for up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, details of the scope of consent (e.g. the categories of cookies and/or service providers concerned) as well as information about the browser, the system and the device used; legal bases:consent (Art. 6(1)(1)(a) GDPR).
Registration, login and user account
Users can create a user account. As part of the registration process, users are informed of the mandatory information required, which is processed for the purposes of providing the user account on the basis of the fulfilment of contractual obligations. The data processed include in particular the login information (username, password and an email address).
When you use our registration and login functions and the user account, we store the IP address and the time of the respective user action. This storage takes place on the basis of our legitimate interests as well as those of the users in protection against misuse and other unauthorised use. This data is generally not passed on to third parties unless it is necessary to pursue our claims or there is a legal obligation to do so.
Users may be informed by email about matters relevant to their user account, such as technical changes.
There is no login on our website www.postexpert.de. The sign-in buttons lead to our application at app.postexpert.de.
Registration for the application is possible solely with an email address. We do not offer sign-in via third-party accounts, in particular no sign-in via Apple, Facebook, Google or Instagram.
This must be distinguished from connecting an Instagram account within the application. In that case the user signs in to Instagram and grants us permission to act for their account. That is not a login with us but a grant of authorisation. It is described in the section “Processing within the PostExpert application”.
- Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or the time of creation); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Log data (e.g. log files concerning logins or the retrieval of data or access times.).
- Data subjects: users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: provision of contractual services and fulfilment of contractual obligations; security measures; organisational and administrative procedures. Provision of our online offering and user-friendliness.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure". Erasure after termination.
- Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Registration with pseudonyms: users may use pseudonyms as usernames instead of their real names; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR).
- User profiles are not public: users’ profiles are not publicly visible or accessible.
- Erasure of data after termination: when users have terminated their user account, their data relating to the user account are erased, subject to any statutory permission, obligation or users’ consent; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR).
- No obligation to retain data: it is the users’ responsibility to back up their data before the contract ends. After the contract ends we are not obliged to continue holding the data. During the term of the contract we do not delete data without cause. We reserve the right to delete data immediately and irretrievably only if the user breaches our terms and conditions, misuses the application or acts unlawfully; the conditions and the procedure are set out in section 12 of our terms and conditions. Insofar as we process data on behalf of the user, the return and deletion of data are governed by the data processing agreement; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR).
Processing within the PostExpert application
This section describes which data we process within our application at app.postexpert.de. It supplements the preceding sections, which relate to our marketing website www.postexpert.de.
PostExpert is a tool for managing Instagram business accounts. Our customers connect their own Instagram professional account and use it to create, schedule and publish posts, analyse statistics and respond to comments. Content can be generated using artificial intelligence.
This does not refer to our own Instagram presence, which is described in the section “Presence in social networks (social media)”.
Our role: controller and processor
In connection with the application we take on two different roles:
- For the customer relationship we are the controller. This covers registration, the user account, billing, support, the security of our systems and compliance with our legal obligations.
- For the content of the connected Instagram account we process the data on behalf of and on the instructions of our customers. In this respect the customer is the controller and we are the processor within the meaning of Art. 28 GDPR. The basis for this is the data processing agreement set out in section 15 of our terms and conditions; it is concluded together with the usage contract.
The service providers named in this section are therefore our processors where we are the controller ourselves, and sub-processors where we process on behalf of our customers. The processing operations, recipients, retention periods and safeguards described are the same in both cases.
If you have commented on a post from an account managed with PostExpert and have questions about the processing of your data, please contact the operator of the Instagram account concerned first. However, you can also contact us directly at any time. We will then forward your request or answer it ourselves.
Connection with Instagram and data received from Meta
When a customer connects an Instagram account using the “Instagram Business Login” procedure, we receive access to that account from Meta. In doing so we receive and store:
- the app-scoped Instagram account ID and the legacy Instagram user ID
- the Instagram username, the profile name and the profile picture
- a long-lived access token that allows us to act on behalf of the account
- the ID of a linked Facebook page, if one exists
For as long as the connection exists, we also process on an ongoing basis:
- the account’s posts including image and video URLs, caption texts and preview images
- reach, interaction and profile metrics as well as aggregated, non-personal information on the composition of the followers
- comments below the posts, including the username, text and time of the commenting person
The purpose is to provide the contractually agreed service: creating, scheduling and publishing posts, analysing statistics and responding to comments.
The legal basis vis-à-vis our customers is Art. 6(1)(b) GDPR, that is, performance of the usage contract. We process the data of commenting persons on the basis of legitimate interests under Art. 6(1)(f) GDPR. The legitimate interest lies in being able to respond to comments and enquiries directed publicly at the account. Insofar as we process on behalf of a customer, the processing is based on that customer’s legal basis.
Right to object under Art. 21 GDPR: if you have commented on a post, you may object to the processing of your data at any time. An informal message to info@postexpert.de is sufficient. We will then delete the data concerned from our systems, unless compelling legitimate grounds prevent this. Only you or Meta can remove your comment on Instagram itself.
The recipients are the service providers named in the following section.
Retention period: we delete the data listed as soon as the connection to the Instagram account is severed, as soon as the authorisation is revoked directly at Instagram — Meta informs us of this via an automated interface — or as soon as the customer account is deleted. The access token is also deleted in these cases.
Use of artificial intelligence in the application
We use Google’s Vertex AI to generate images, videos and texts and to classify and respond to comments. The data transmitted in this process are processed in the United States.
AI-assisted comment replies: if this function is activated, we transmit the following data to Google:
- the text of the comment
- the Instagram username of the commenting person
- the caption text of the associated post
- the business information stored by the customer
The model classifies the comment and generates a suggested reply. Depending on the setting, this suggestion is submitted to the customer for approval or published immediately.
Please note: this involves processing personal data of people who have no contractual relationship with us — namely the commenting persons — and these data are transferred to a third country. We describe the safeguards that apply and the residual risk that remains in the section “Data transfers to the United States”.
The function can be deactivated at any time. If it is deactivated, we do not transmit any comment data to Google for this purpose.
The purpose is the automated classification of and response to comments as well as the generation of content. The legal basis vis-à-vis our customers is Art. 6(1)(b) GDPR, and with regard to the data of commenting persons Art. 6(1)(f) GDPR. The recipient is Google. Transmission takes place on a case-by-case basis for each request; we delete the comment data in our systems in accordance with the rules stated in the preceding section. For storage by Google itself we refer to its privacy notices.
Processors used by the application
We use the following service providers to operate the application. Data processing agreements under Art. 28 GDPR are in place with all three, in the form of the respective providers’ standard contractual addenda.
- Oracle Corporation (Oracle Cloud Infrastructure): operation of the application servers and the database. All data referred to in this section, including the access tokens, are stored there. Place of processing: Frankfurt am Main, Germany.
- Google Ireland Limited and Google LLC (Google Cloud Platform): Cloud Storage for uploaded and generated media as well as for mirrored preview images of Instagram posts; Vertex AI for generating images, videos and texts and for classifying and responding to comments. Place of processing: United States of America.
- Sendinblue SAS (Brevo): sending transactional and notification emails to our customers. The email address, the self-chosen account name and aggregated metrics are transmitted. Neither access tokens nor personal data of commenting persons are transmitted to Brevo. Places of processing: France, Germany and Belgium.
Oracle and Brevo process these data exclusively within the European Union.
The services used on our marketing website do not receive any data from the connected Instagram accounts. This also applies to payment processing via Stripe. The website’s services are described separately in the preceding sections of this privacy policy and operate independently of the application.
Data transfers to the United States
Processing by the Google Cloud Platform — that is, Cloud Storage and Vertex AI — takes place in the United States. The data concerned therefore leave the European Economic Area.
We base this transfer on two grounds: Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission has found an adequate level of protection. In addition, we have agreed the European Commission’s standard contractual clauses with Google pursuant to Art. 46(2)(c) GDPR.
We would nevertheless like to point out a residual risk openly: under certain conditions, US authorities can access data stored with US companies. Data subjects from the European Union may not have the same legal remedies against such access as they would within the European Union. Legal protection equivalent to that under European law cannot therefore be guaranteed in every case.
These notes concern the application. For the services used on our website, the bases for third-country transfers stated in the respective sections apply.
- Types of data processed: master data (e.g. full name, home address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or pictorial messages and posts as well as information relating to them, such as details of authorship or time of creation); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: service recipients and clients; users (e.g. website visitors, users of online services). Third parties (in particular persons who comment on posts of a connected Instagram account).
- Purposes of processing and legitimate interests: provision of contractual services and fulfilment of contractual obligations; communication; security measures. Information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)).
- Retention and erasure: deletion when the Instagram connection is severed, when the authorisation at Instagram is revoked, and when the customer account is deleted. Otherwise deletion in accordance with the information in the section “General information on data retention and erasure”.
- Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Contact and enquiry management
When you contact us (e.g. by post, contact form, email, telephone or via social media) and in the context of existing user and business relationships, the details of the enquiring persons are processed to the extent necessary to respond to the contact enquiries and any measures requested.
- Types of data processed: contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or the time of creation). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: communication partners.
- Purposes of processing and legitimate interests: communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online offering and user-friendliness.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure".
- Legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR). Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR).
Further information on processing operations, procedures and services:
- Contact form: when you contact us via our contact form, by email or through other communication channels, we process the personal data transmitted to us in order to answer and deal with the respective request. This generally includes information such as name, contact details and, where applicable, further information provided to us that is necessary for appropriate handling. We use this data exclusively for the stated purpose of contact and communication; legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR).
Newsletter and electronic notifications
We send newsletters, emails and other electronic notifications (hereinafter "newsletter") exclusively with the consent of the recipients or on the basis of a legal permission. Where the contents of the newsletter are described when signing up, those contents are decisive for the users’ consent. To subscribe to our newsletter it is normally sufficient to provide your email address. However, in order to be able to offer you a personalised service, we may ask you to provide your name so that you can be addressed personally in the newsletter, or for further information if this is necessary for the purpose of the newsletter.
Erasure and restriction of processing: we may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before erasing them, in order to be able to prove that consent was previously given. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for erasure is possible at any time, provided that the previous existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocking list (a so-called "blocklist").
The sign-up procedure is logged on the basis of our legitimate interests for the purpose of proving that it was carried out properly. Insofar as we commission a service provider to send emails, this takes place on the basis of our legitimate interests in an efficient and secure dispatch system.
To send the newsletter we use Sendinblue SAS (Brevo), 106 boulevard Haussmann, 75008 Paris, France, as a processor pursuant to Art. 28 GDPR. Registration uses the double opt-in procedure: after entering your email address you receive a confirmation message; only by way of the confirmation link it contains are you added to the mailing list. If confirmation does not follow, you are not added to the mailing list. To prove consent, Brevo stores the time of registration and of confirmation as well as the IP address used. The places of processing are France, Germany and Belgium.
Content:
Information about us, our services, promotions and offers.
- Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved). Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: communication partners.
- Purposes of processing and legitimate interests: direct marketing (e.g. by email or post).
- Legal bases: consent (Art. 6(1)(1)(a) GDPR).
- Opt-out option: you can cancel receipt of our newsletter at any time, i.e. withdraw your consent or object to further receipt. You will find a link to cancel the newsletter either at the end of each newsletter or you can otherwise use one of the contact options given above, preferably email.
Further information on processing operations, procedures and services:
- Measurement of open and click rates: the newsletters contain a so-called "web beacon", i.e. a pixel-sized file which is retrieved from our server or that of the dispatch service provider, if we use one, when the newsletter is opened. During this retrieval, technical information such as details about the browser and your system as well as your IP address and the time of retrieval are initially collected. Legal bases: consent (Art. 6(1)(1)(a) GDPR).
Promotional communication via email, post, fax or telephone
We process personal data for the purposes of promotional communication, which may take place via various channels such as email, telephone, post or fax in accordance with the statutory requirements.
Recipients have the right to withdraw consent given at any time or to object to promotional communication at any time free of charge using the contact option stated above.
After withdrawal or objection we store the data required to prove the previous authorisation for contact or dispatch for up to three years after the end of the year of the withdrawal or objection, on the basis of our legitimate interests. The processing of this data is limited to the purpose of possibly defending against claims. On the basis of our legitimate interest in permanently observing users’ withdrawal or objection, we also store the data required to avoid renewed contact (e.g. depending on the communication channel, the email address, telephone number, name).
- Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers). Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or the time of creation).
- Data subjects: communication partners.
- Purposes of processing and legitimate interests: direct marketing (e.g. by email or post); marketing. Sales promotion.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure".
- Legal bases: consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Prize draws and competitions
We decide at our own discretion whether and when we run prize draws or competitions. We may introduce, change, restrict or discontinue them at any time. The following information applies as soon as and to the extent that we offer such a prize draw or competition.
We process personal data of participants in prize draws and competitions only in compliance with the relevant data protection provisions, insofar as the processing is contractually necessary for the provision, running and handling of the prize draw, the participants have consented to the processing, or the processing serves our legitimate interests (e.g. in the security of the prize draw or in protecting our interests against misuse by possibly recording IP addresses when competition entries are submitted).
If entries submitted by participants are published as part of the prize draws (e.g. in the context of a vote or presentation of the competition entries or the winners, or reporting on the prize draw), we point out that participants’ names may also be published in this context. Participants may object to this at any time.
If the prize draw takes place within an online platform or a social network (e.g. Facebook or Instagram, hereinafter referred to as the "online platform"), the terms of use and data protection provisions of the respective platforms additionally apply. In these cases we point out that we are responsible for the information provided by participants in the context of the prize draw and that enquiries regarding the prize draw should be addressed to us.
Participants’ data are erased as soon as the prize draw or competition has ended and the data are no longer required in order to inform the winners or because no further queries regarding the prize draw are to be expected. In principle, participants’ data are erased no later than 6 months after the end of the prize draw. Winners’ data may be retained for longer, e.g. in order to answer queries about the prizes or to be able to fulfil the prize services; in this case the retention period depends on the type of prize and is, for example, up to three years for goods or services in order to be able to handle warranty cases. Furthermore, participants’ data may be stored for longer, e.g. in the form of reporting on the prize draw in online and offline media.
If data were also collected for other purposes in the context of the prize draw, their processing and retention period are governed by the privacy notices relating to that use (e.g. in the case of a newsletter subscription taken out as part of a prize draw).
- Types of data processed: master data (e.g. full name, residential address, contact information, customer number, etc.); contact data (e.g. postal and email addresses or telephone numbers). Content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or the time of creation).
- Data subjects: participants in prize draws and competitions.
- Purposes of processing and legitimate interests: running prize draws and competitions.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure".
- Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Web analytics, monitoring and optimisation
Web analytics (also referred to as "reach measurement") serves to evaluate the visitor flows of our online offering and may include behaviour, interests or demographic information about visitors, such as age or gender, in the form of pseudonymous values. With the help of reach analysis we can, for example, identify at what times our online offering or its functions or content are used most frequently, or invite repeat use. It is likewise possible for us to determine which areas require optimisation.
In addition to web analytics, we may also use testing procedures, for example to test and optimise different versions of our online offering or its components.
Unless stated otherwise below, profiles — i.e. data aggregated for a usage process — may be created for these purposes, and information may be stored in a browser or on a device and then read out. The information collected includes in particular websites visited and elements used there, as well as technical information such as the browser used, the computer system used and details of usage times. Where users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.
In addition, users’ IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation by truncating the IP address) to protect users. In general, no clear data of users (such as email addresses or names) are stored in the context of web analytics, A/B testing and optimisation, but rather pseudonyms. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.
Notes on legal bases: where we ask users for their consent to the use of third-party providers, the legal basis for the data processing is consent. Otherwise, users’ data are processed on the basis of our legitimate interests (i.e. our interest in efficient, economical and recipient-friendly services). In this context we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of data processed: usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: reach measurement (e.g. access statistics, recognition of returning visitors); profiles with user-related information (creation of user profiles). Provision of our online offering and user-friendliness.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure". Storage of cookies for up to 2 years (unless stated otherwise, cookies and similar storage methods may be stored on users’ devices for a period of two years.).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal bases: consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Google Analytics: we use Google Analytics to measure and analyse the use of our online offering on the basis of a pseudonymous user identification number. This identification number does not contain any unique data such as names or email addresses. It serves to assign analysis information to a device in order to identify which content users have accessed within one or several usage processes, which search terms they used, whether they accessed them again or interacted with our online offering. The time of use and its duration are also stored, as well as the sources of users referring to our online offering and technical aspects of their devices and browsers. In doing so, pseudonymous profiles of users are created with information from the use of different devices, whereby cookies may be used. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides coarse geographic location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based counterparts). For EU traffic, IP address data is used exclusively for this derivation of geolocation data before being deleted immediately. It is not logged, is not accessible and is not used for any further purposes. When Google Analytics collects measurement data, all IP queries are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6(1)(1)(a) GDPR); website: https://marketingplatform.google.com/intl/de/about/analytics/; security measures: IP masking (pseudonymisation of the IP address); privacy policy: https://business.safety.google/privacy/; data processing agreement: https://business.safety.google/adsprocessorterms/; basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms); opt-out option: opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://myadcenter.google.com/personalizationoff. Further information:https://business.safety.google/adsservices/ (types of processing and of the data processed).
- Google Tag Manager: we use Google Tag Manager, a software from Google which enables us to manage so-called website tags centrally via a user interface. Tags are small code elements on our website which serve to record and analyse visitor activities. This technology helps us to improve our website and the content offered on it. Google Tag Manager itself does not create user profiles, does not store cookies with user profiles and does not carry out any independent analyses. Its function is limited to simplifying and making more efficient the integration and management of tools and services that we use on our website. Nevertheless, when Google Tag Manager is used, users’ IP addresses are transmitted to Google, which is necessary for technical reasons in order to implement the services we use. Cookies may also be set in the process. However, this data processing only takes place if services are integrated via the Tag Manager. For more detailed information on these services and their data processing we refer to the following sections of this privacy policy; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6(1)(1)(a) GDPR); website:https://marketingplatform.google.com; privacy policy: https://business.safety.google/privacy/; data processing agreement: https://business.safety.google/adsprocessorterms. Basis for third-country transfers: Data Privacy Framework (DPF), standard contractual clauses (https://business.safety.google/adsprocessorterms).
- Ahrefs Web Analytics: We use Ahrefs Web Analytics, a cookieless audience-measurement service. The service sets no cookies and stores no identifiers on users’ devices; it is therefore loaded without a consent prompt. It records aggregated access data such as pages viewed, referring page (referrer), approximate origin (country), browser and device type; no user-related profiles are created. Service provider: Ahrefs Pte. Ltd., 16 Raffles Quay, #33-03 Hong Leong Building, Singapore 048581; legal bases: legitimate interests (Art. 6(1)(f) GDPR); website: https://analytics.ahrefs.com; privacy policy: https://ahrefs.com/privacy-policy.
Online marketing
We process personal data for the purposes of online marketing, which may include in particular the marketing of advertising space or the display of advertising and other content (collectively referred to as "content") based on users’ potential interests, as well as measuring their effectiveness.
For these purposes, so-called user profiles are created and stored in a file (the so-called "cookie"), or similar procedures are used by means of which the information about the user relevant for the display of the aforementioned content is stored. This may include, for example, content viewed, websites visited, online networks used, but also communication partners and technical information such as the browser used, the computer system used and information about usage times and functions used. Where users have consented to the collection of their location data, this may also be processed.
In addition, users’ IP addresses are stored. However, we use the available IP masking procedures (i.e. pseudonymisation by truncating the IP address) to protect users. In general, no clear data of users (such as email addresses or names) are stored in the context of the online marketing procedure, but rather pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.
The information contained in the profiles is generally stored in cookies or by means of similar procedures. These cookies can later generally also be read on other websites that use the same online marketing procedure, analysed for the purpose of displaying content, supplemented with further data and stored on the server of the online marketing procedure provider.
In exceptional cases it is possible to assign clear data to the profiles, primarily where users are, for example, members of a social network whose online marketing procedure we use and the network links the user profiles with the aforementioned information. Please note that users may make additional arrangements with the providers, for example by giving consent during registration.
In principle we only have access to aggregated information about the success of our advertisements. However, within the scope of so-called conversion measurement we can check which of our online marketing procedures have led to a so-called conversion, i.e. for example to the conclusion of a contract with us. Conversion measurement is used solely to analyse the success of our marketing activities.
Unless stated otherwise, please assume that the cookies used are stored for a period of two years.
Notes on legal bases: where we ask users for their consent to the use of third-party providers, the legal basis for the data processing is the permission. Otherwise, users’ data are processed on the basis of our legitimate interests (i.e. our interest in efficient, economical and recipient-friendly services). In this context we would also like to draw your attention to the information on the use of cookies in this privacy policy.
Notes on withdrawal and objection:
We refer to the privacy notices of the respective providers and the opt-out options stated for those providers (so-called "opt-out"). If no explicit opt-out option has been stated, you have the option of disabling cookies in your browser settings. However, this may restrict functions of our online offering. We therefore additionally recommend the following opt-out options, which are offered in summary form for the respective regions:
a) Europe: https://youronlinechoices.eu/.
b) Canada: https://youradchoices.ca/.
c) USA: https://optout.aboutads.info/.
d) Cross-regional: https://optout.aboutads.info.
- Types of data processed: usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: reach measurement (e.g. access statistics, recognition of returning visitors); tracking (e.g. interest/behaviour-based profiling, use of cookies); audience building; marketing; profiles with user-related information (creation of user profiles). Conversion measurement (measuring the effectiveness of marketing activities).
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure". Storage of cookies for up to 2 years (unless stated otherwise, cookies and similar storage methods may be stored on users’ devices for a period of two years.).
- Security measures: IP masking (pseudonymisation of the IP address).
- Legal bases: consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Google Ads and conversion measurement: online marketing procedure for the purpose of placing content and advertisements within the service provider’s advertising network (e.g. in search results, in videos, on websites, etc.) so that they are displayed to users who have a presumed interest in the advertisements. In addition, we measure the conversion of the advertisements, i.e. whether users took them as an occasion to interact with the advertisements and to use the advertised offers (so-called conversions). However, we only receive anonymous information and no personal information about individual users; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: consent (Art. 6(1)(1)(a) GDPR), legitimate interests (Art. 6(1)(1)(f) GDPR); website:https://marketingplatform.google.com; privacy policy: https://business.safety.google/privacy/; basis for third-country transfers: Data Privacy Framework (DPF); further information: types of processing and of the data processed: https://business.safety.google/adsservices/. Data processing terms between controllers and standard contractual clauses for third-country data transfers: https://business.safety.google/adscontrollerterms.
Provision of an affiliate programme
We decide at our own discretion whether and when we offer an affiliate programme. We may introduce, change, restrict or discontinue it at any time. The following information applies as soon as and to the extent that we provide such a programme.
We offer an affiliate programme, i.e. commissions or other benefits (collectively referred to as "commission") for users (referred to as "affiliates") who refer others to our offers and services. The referral takes place by means of a link assigned to the respective affiliate or other methods (e.g. discount codes) which allow us to recognise that the use of our services was based on the referral (collectively referred to as "affiliate links").
- Purposes of processing and legitimate interests: provision of contractual services and fulfilment of contractual obligations. Affiliate tracking.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure".
- Legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR).
Customer reviews and rating procedures
We decide at our own discretion whether and through which providers we use review and rating procedures. At present we do not embed any rating widget or third-party seal in our online offering. The following information applies as soon as and to the extent that we use such a procedure; we will then name the specific provider at this point.
We take part in review and rating procedures in order to evaluate, optimise and promote our services. If users rate us via the participating rating platforms or procedures or otherwise provide feedback, the general terms and conditions or terms of use and the privacy notices of the providers additionally apply. As a rule, rating also requires registration with the respective providers.
In order to ensure that the persons submitting a review have actually used our services, we transmit the data required for this purpose regarding the customer and the service used to the respective rating platform with the customer’s consent (including name, email address and order number or item number). This data is used solely to verify the authenticity of the user.
- Types of data processed: contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: recipients of services and clients. Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: feedback (e.g. collecting feedback via an online form). Marketing.
- Legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR). Consent (Art. 6(1)(1)(a) GDPR).
Presence in social networks (social media)
We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about us.
We point out that user data may be processed outside the area of the European Union in this context. This may give rise to risks for users because, for example, the enforcement of users’ rights could be made more difficult.
Furthermore, users’ data within social networks are generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of usage behaviour and the resulting interests of users. The latter may in turn be used, for example, to place advertisements inside and outside the networks that presumably correspond to users’ interests. For this reason, cookies are generally stored on users’ computers in which usage behaviour and users’ interests are stored. In addition, data may also be stored in the usage profiles irrespective of the devices used by the users (in particular if they are members of the respective platforms and are logged in there).
For a detailed description of the respective forms of processing and the opt-out options, we refer to the privacy policies and information provided by the operators of the respective networks.
Also in the case of requests for information and the assertion of data subject rights, we point out that these can be asserted most effectively with the providers. Only the latter have access to the user data in each case and can take appropriate measures and provide information directly. Should you nevertheless require assistance, you can contact us.
- Types of data processed: contact data (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and contributions as well as the information relating to them, such as details of authorship or the time of creation). Usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions).
- Data subjects: users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: communication; feedback (e.g. collecting feedback via an online form). Public relations.
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure".
- Legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Instagram: social network, enables the sharing of photos and videos, commenting on and favouriting posts, sending messages, subscribing to profiles and pages; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR); website: https://www.instagram.com; privacy policy:https://privacycenter.instagram.com/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
Plug-ins and embedded functions and content
We integrate functional and content elements into our online offering which are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These may be, for example, graphics, videos or city maps (hereinafter uniformly referred to as "content").
Integration always presupposes that the third-party providers of this content process users’ IP addresses, since without the IP address they would not be able to send the content to their browser. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only content whose respective providers use the IP address solely for delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as "web beacons") for statistical or marketing purposes. Pixel tags can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may contain, among other things, technical information about the browser and the operating system, referring websites, time of visit and further details about the use of our online offering, but may also be combined with such information from other sources.
Notes on legal bases: where we ask users for their consent to the use of third-party providers, the legal basis for the data processing is the permission. Otherwise, users’ data are processed on the basis of our legitimate interests (i.e. our interest in efficient, economical and recipient-friendly services). In this context we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of data processed: usage data (e.g. page views and time spent, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved). Event data (Facebook) ("Event data" is information that is sent to the provider Meta, for example via Meta pixels (whether via apps or other channels), and relates to persons or their actions. This data includes, for example, details of website visits, interactions with content and functions, app installations and product purchases. Event data is processed with the aim of creating target groups for content and advertising messages (custom audiences). It is important to note that event data does not include any actual content such as comments written, any login information or any contact information such as names, email addresses or telephone numbers. "Event data" is deleted by Meta after a maximum of two years, and the target groups formed from it disappear when our Meta user accounts are deleted.).
- Data subjects: users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: provision of our online offering and user-friendliness; marketing. Profiles with user-related information (creation of user profiles).
- Retention and erasure: erasure in accordance with the information provided in the section "General information on data storage and erasure". Storage of cookies for up to 2 years (unless stated otherwise, cookies and similar storage methods may be stored on users’ devices for a period of two years.).
- Legal bases: consent (Art. 6(1)(1)(a) GDPR). Legitimate interests (Art. 6(1)(1)(f) GDPR).
Further information on processing operations, procedures and services:
- Facebook plugins and content: Facebook social plugins and content - These may include, for example, content such as images, videos or texts and buttons with which users can share content of this online offering within Facebook. The list and appearance of the Facebook social plugins can be viewed here: https://developers.facebook.com/docs/plugins/ - We are jointly responsible withMeta Platforms Ireland Limited for the collection or receipt in the course of a transmission (but not the further processing) of "event data" that Facebook collects by means of the Facebook social plugins (and content embedding functions) executed on our online offering, or receives in the course of a transmission, for the following purposes: a) display of content and advertising information that corresponds to the presumed interests of users; b) delivery of commercial and transaction-related messages (e.g. contacting users via Facebook Messenger); c) improvement of ad delivery and personalisation of functions and content (e.g. improving the recognition of which content or advertising information presumably corresponds to users’ interests). We have concluded a special agreement with Facebook ("Controller Addendum", https://www.facebook.com/legal/controller_addendum), which in particular governs which security measures Facebook must observe (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to fulfil data subject rights (i.e. users can, for example, address requests for information or erasure directly to Facebook). Note: if Facebook provides us with metrics, analyses and reports (which are aggregated, i.e. do not contain any information about individual users and are anonymous for us), this processing does not take place within the scope of the joint controllership but on the basis of a data processing agreement ("Data Processing Terms ", https://www.facebook.com/legal/terms/dataprocessing) , the "Data Security Terms" (https://www.facebook.com/legal/terms/data_security_terms) and, with regard to processing in the USA, on the basis of standard contractual clauses ("Facebook EU Data Transfer Addendum, https://www.facebook.com/legal/EU_data_transfer_addendum). Users’ rights (in particular to information, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook.; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: consent (Art. 6(1)(1)(a) GDPR); website: https://www.facebook.com; privacy policy: https://www.facebook.com/privacy/policy/. Basis for third-country transfers: Data Privacy Framework (DPF).
- Instagram plugins and content: Instagram plugins and content - These may include, for example, content such as images, videos or texts and buttons with which users can share content of this online offering within Instagram. - We are jointly responsible with Meta Platforms Ireland Limited for the collection or receipt in the course of a transmission (but not the further processing) of "event data" that Facebook collects by means of Instagram functions (e.g. content embedding functions) executed on our online offering, or receives in the course of a transmission, for the following purposes: a) display of content and advertising information that corresponds to the presumed interests of users; b) delivery of commercial and transaction-related messages (e.g. contacting users via Facebook Messenger); c) improvement of ad delivery and personalisation of functions and content (e.g. improving the recognition of which content or advertising information presumably corresponds to users’ interests). We have concluded a special agreement with Facebook ("Controller Addendum", https://www.facebook.com/legal/controller_addendum), which in particular governs which security measures Facebook must observe (https://www.facebook.com/legal/terms/data_security_terms) and in which Facebook has agreed to fulfil data subject rights (i.e. users can, for example, address requests for information or erasure directly to Facebook). Note: if Facebook provides us with metrics, analyses and reports (which are aggregated, i.e. do not contain any information about individual users and are anonymous for us), this processing does not take place within the scope of the joint controllership but on the basis of a data processing agreement ("Data Processing Terms ", https://www.facebook.com/legal/terms/dataprocessing) , the "Data Security Terms" (https://www.facebook.com/legal/terms/data_security_terms) and, with regard to processing in the USA, on the basis of standard contractual clauses ("Facebook EU Data Transfer Addendum, https://www.facebook.com/legal/EU_data_transfer_addendum). Users’ rights (in particular to information, erasure, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook.; service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; legal bases: legitimate interests (Art. 6(1)(1)(f) GDPR); website:https://www.instagram.com. Privacy policy: https://privacycenter.instagram.com/policy/.
Data protection information for whistleblowers
In this section you will find information about how we handle data of persons who report information (whistleblowers) as well as of affected and involved parties within the scope of our whistleblowing procedure.
Legal bases (Austria): insofar as we process data to fulfil our legal obligations in accordance with the Austrian Whistleblower Protection Act (HinweisgeberInnenschutzgesetz – HSchG), the legal basis for the processing is Article 6(1)(1)(c) GDPR and, in the case of special categories of personal data, Art. 9(2)(g) GDPR, in each case in conjunction with § 8 HSchG.
Types of data processed: within the scope of receiving and handling reports and in the subsequent whistleblowing procedure, we may collect various data. These include in particular the data provided by a whistleblower, such as:name, contact details and place of residence of the person making the report, names and data of possible witnesses or persons affected by the report, names and data of the persons against whom the report is directed, data about the alleged misconduct as well as further relevant details.
Use of our online forms: please note that it is possible to submit reports anonymously. In order to ensure the security of your data when using our online forms, we recommend accessing them in your browser’s so-called 'incognito mode'. You can open an incognito window as follows: a) On a Windows PC: open your browser and press Ctrl+Shift+N; b) On a Mac: open your browser and press Command+Shift+N; c) On mobile devices: switch to private mode via the tab menu.
Providing your name: you have the option of submitting reports anonymously. However, insofar as this is not prohibited by national legislation, we recommend providing your name and contact details. This enables us to follow up the report more effectively and, where appropriate, to contact you directly.
Provision of data to third parties: data connected with the reports submitted are only passed on by us to third parties under certain circumstances. This occurs either a) if you have given us your express consent to do so, or b) if there is a legal obligation to disclose the data. Possible third parties include public authorities, governmental, regulatory or tax authorities, if disclosure is necessary to fulfil a legal or regulatory obligation. In addition, within the framework of statutory provisions, we may instruct lawyers and other specialist advisers. These are entitled to examine suspected misconduct and to take the necessary measures following an investigation, such as initiating disciplinary or court proceedings. Furthermore, carefully selected and monitored service providers may receive data for these purposes (for example operators of a web-based reporting system). However, these service providers are contractually obliged, within the framework of processing on behalf of a controller, to comply with the applicable data protection provisions.
Data retention and erasure: personal data are only processed for as long as is necessary to fulfil the processing purposes described above. If these data are no longer necessary for the stated purposes, they are erased.
Technical and organisational measures: we have implemented the necessary contractual, technical and organisational measures to ensure the security of all data processed by us. These data are processed exclusively for the specified purposes.
Amendment and updating
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or any other individual notification.
Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that the addresses may change over time and we ask you to verify the details before making contact.
Definitions of terms
In this section you will find an overview of the terms used in this privacy policy. Insofar as the terms are defined by law, their statutory definitions apply. The following explanations, on the other hand, are intended primarily to aid understanding.
- Affiliate tracking: within the scope of affiliate tracking, links by means of which the linking websites refer users to websites with product or other offers are logged. The operators of the respective linking websites can receive a commission if users follow these so-called affiliate links and subsequently take up the offers (e.g. buy goods or use services). For this it is necessary that the providers can track whether users who are interested in certain offers subsequently take them up as a result of the affiliate links. It is therefore necessary for the functionality of affiliate links that they are supplemented with certain values which become part of the link or are stored in another way, e.g. in a cookie. These values include in particular the originating website (referrer), the time, an online identifier of the operators of the website on which the affiliate link was located, an online identifier of the respective offer, an online identifier of the user as well as tracking-specific values such as advertising medium ID, partner ID and categorisations
- Employees: employees are persons who are in an employment relationship, whether as staff, salaried employees or in similar positions. An employment relationship is a legal relationship between an employer and an employee which is established by an employment contract or an agreement. It entails the employer’s obligation to pay the employee remuneration while the employee performs their work. The employment relationship comprises various phases, including its establishment, in which the employment contract is concluded, its performance, in which the employee carries out their work, and its termination, when the employment relationship ends, whether by notice, a termination agreement or otherwise. Employee data are all information relating to these persons and connected with the context of their employment. This includes aspects such as personal identification data, identification numbers, salary and bank details, working hours, holiday entitlements, health data and performance appraisals.
- Master data: master data comprise essential information that is necessary for the identification and administration of contractual partners, user accounts, profiles and similar assignments. This data may include, among other things, personal and demographic details such as names, contact information (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data form the basis for any formal interaction between persons and services, institutions or systems by enabling unambiguous assignment and communication.
- Content data: content data comprise information generated in the course of creating, editing and publishing content of all kinds. This category of data may include texts, images, videos, audio files and other multimedia content published on various platforms and media. Content data are not limited to the actual content but also include metadata that provide information about the content itself, such as tags, descriptions, author information and publication dates
- Contact data: contact data are essential information that enables communication with persons or organisations. They include, among other things, telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
- Conversion measurement: conversion measurement (also referred to as "visit action evaluation") is a procedure by which the effectiveness of marketing activities can be determined. For this purpose a cookie is generally stored on users’ devices within the websites on which the marketing activities take place and is then retrieved again on the target website. In this way we can, for example, determine whether the advertisements we have placed on other websites have been successful.
- Meta, communication and procedural data: meta, communication and procedural data are categories that contain information about the manner in which data are processed, transmitted and managed. Metadata, also known as data about data, comprise information describing the context, origin and structure of other data. They may include details of file size, creation date, the author of a document and change histories. Communication data record the exchange of information between users via various channels, such as email traffic, call logs, messages in social networks and chat histories, including the persons involved, time stamps and transmission paths. Procedural data describe the processes and workflows within systems or organisations, including workflow documentation, logs of transactions and activities as well as audit logs used to trace and review operations.
- Usage data: usage data refer to information that records how users interact with digital products, services or platforms. This data comprises a broad range of information showing how users use applications, which functions they prefer, how long they stay on particular pages and which paths they take to navigate through an application. Usage data may also include the frequency of use, time stamps of activities, IP addresses, device information and location data. They are particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. In addition, usage data play a decisive role in identifying trends, preferences and possible problem areas within digital offerings
- Personal data: "personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. cookie) or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Profiles with user-related information: the processing of "profiles with user-related information", or "profiles" for short, comprises any form of automated processing of personal data consisting of the use of such personal data to analyse or evaluate certain personal aspects relating to a natural person (depending on the type of profiling, this may include various information concerning demographics, behaviour and interests, such as interaction with websites and their content, etc.) or to predict them (e.g. interest in certain content or products, click behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
- Log data: log data are information about events or activities that have been logged in a system or network. This data typically contains information such as time stamps, IP addresses, user actions, error messages and other details about the use or operation of a system. Log data are often used to analyse system problems, for security monitoring or to produce performance reports.
- Reach measurement: reach measurement (also referred to as web analytics) serves to evaluate the visitor flows of an online offering and may include the behaviour or interests of visitors in certain information, such as the content of websites. With the help of reach analysis, operators of online offerings can, for example, identify at what times users visit their websites and which content they are interested in. This enables them, for example, to better adapt the content of the websites to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are frequently used in order to recognise returning visitors and thus obtain more precise analyses of the use of an online offering.
- Tracking: "tracking" refers to the ability to trace users’ behaviour across several online offerings. As a rule, behavioural and interest information relating to the online offerings used is stored in cookies or on the servers of the providers of the tracking technologies (so-called profiling). This information can subsequently be used, for example, to display advertisements to users that are likely to correspond to their interests.
- Controller: "controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, whether collection, analysis, storage, transmission or erasure.
- Contract data: contract data are specific information relating to the formalisation of an agreement between two or more parties. They document the conditions under which services or products are provided, exchanged or sold. This category of data is essential for the administration and fulfilment of contractual obligations and includes both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include the start and end dates of the contract, the type of services or products agreed, pricing arrangements, payment terms, termination rights, renewal options and special conditions or clauses. They serve as the legal basis for the relationship between the parties and are decisive for clarifying rights and obligations, enforcing claims and resolving disputes.
- Payment data: payment data comprise all information required to process payment transactions between buyers and sellers. This data is of decisive importance for electronic commerce, online banking and any other form of financial transaction. It includes details such as credit card numbers, bank details, payment amounts, transaction data, verification numbers and invoice information. Payment data may also contain information about payment status, chargebacks, authorisations and fees.
- Audience building: audience building (in English "custom audiences") refers to the determination of target groups for advertising purposes, e.g. the display of advertisements. For example, on the basis of a user’s interest in certain products or topics on the internet it can be concluded that this user is interested in advertisements for similar products or for the online shop in which they viewed the products. "Lookalike audiences" (or similar target groups), on the other hand, refers to content assessed as suitable being displayed to users whose profiles or interests presumably correspond to those of the users for whom the profiles were created. Cookies and web beacons are generally used for the purposes of creating custom audiences and lookalike audiences.
Created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke