The following privacy policy is a translated version of the original German text and intended for informational purposes only. For legal validity, please refer to the German version.

Privacy Policy

1) Introduction and contact details of the responsible person

 

 1.1 We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when you use our website. Personal data refers to all data that can be used to identify you personally.

 

 1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Alexandra Vysotskaya, nderUm, Hölderlinstr. 30, 75181 Pforzheim, Germany, Tel.:  4915157824368, Email: alexandra.vysotskaya@nderum.de. The controller responsible for the processing of personal data is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.

 

2) Data collection when visiting our website

 

 2.1 If you use our website for informational purposes only, i.e., if you do not register or otherwise provide us with information, we only collect data that your browser transmits to the website server (so-called "server log files"). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:

 

  • Our visited website
  • Date and time of access
  • Amount of data sent in bytes
  • Source/reference from which you came to the page
  • Browser used
  • Operating system used
  • IP address used (if applicable: in anonymized form)

 

Processing is carried out in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be shared or used for any other purpose. However, we reserve the right to subsequently review the server log files if there are concrete indications of illegal use.

 

 2.2 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries to us), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the character string "https://" and the lock symbol in your browser bar.

 

3) Hosting & Content-Delivery-Network

 

For the hosting of our website and the display of the page content, we use a provider who provides its services either itself or through selected subcontractors exclusively on servers within the European Union.

 

All data collected on our website is processed on these servers.

 

We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

 

4) Cookies

 

To make visiting our website more attractive and enable the use of certain functions, we use cookies, i.e., small text files stored on your device. Some of these cookies are automatically deleted after closing your browser (so-called "session cookies"); others remain on your device for a longer period and allow you to save page settings (so-called "persistent cookies"). In the latter case, you can find out how long cookies are stored in your web browser's cookie settings overview.

 

If personal data is also processed by individual cookies used by us, the processing is carried out in accordance with Art. 6 (1) (b) GDPR either to execute the contract, in accordance with Art. 6 (1) (a) GDPR in the event of consent being given, or in accordance with Art. 6 (1) (f) GDPR to protect our legitimate interests in the best possible functionality of the website and a customer-friendly and effective design of the site visit.

 

You can set your browser so that you are informed about the setting of cookies and can decide individually whether to accept them or to exclude the acceptance of cookies in certain cases or in general.

 

Please note that if you do not accept cookies, the functionality of our website may be limited.

 

5) Contact

 

When you contact us (e.g., via contact form or email), personal data is collected. The data collected when you use a contact form is stated in the respective contact form. This data is stored and used exclusively for the purpose of responding to your inquiry or for the contact and associated technical administration.

 

The legal basis for processing this data is our legitimate interest in responding to your request in accordance with Art. 6 (1) (f) GDPR. If your contact is aimed at concluding a contract, an additional legal basis for processing is Art. 6 (1) (b) GDPR. Your data will be deleted after your request has been processed. This is the case if it can be inferred from the circumstances that the matter in question has been conclusively clarified and provided there are no statutory retention periods to the contrary.

 

6) Web analysis services

 

1&1 IONOS WebAnalytics

 

This website uses the web analysis service of the following provider: 1&1 IONOS Internet SE, Elgendorfer Str. 57, 56410 Montabaur, Germany.

 

Using cookies and/or similar technologies (tracking pixels, web beacons, algorithms for reading device and browser information), the service collects and stores pseudonymized visitor data, including information about the device used, such as the IP address and browser information, in order to evaluate it for statistical analyses of user behavior on our website and to create pseudonymized user profiles. Among other things, this makes it possible to evaluate movement patterns (so-called heat maps), which show the duration of page visits and interactions with page content (e.g., text input, scrolling, clicks, and mouse-overs). Pseudonymization fundamentally excludes direct personal reference. It will not be combined with clear personal data collected in other ways.

 

All processing described above, in particular the reading or storage of information on the device used, will only be carried out if you have given us your express consent in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect by deactivating this service using the "Cookie Consent Tool" provided on the website.

 

We have concluded a data processing agreement with the provider, which ensures the protection of the data of our website visitors and prohibits unauthorized disclosure to third parties.

 

7) Page functionalities

 

 7.1  Google Maps

 

This website uses an online map service from the following provider: Google Maps (API) from Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”).

 

Google Maps is a web service for displaying interactive maps and geographical information visually. Using this service, you will be shown our location and it will be easier for you to find us.

 

As soon as you access the sub-pages in which the Google Maps map is integrated, information about your use of our website (such as your IP address) is transmitted to Google servers and stored there. This may also involve transmission to the servers of Google LLC in the USA. This happens regardless of whether Google provides a user account through which you are logged in or whether a user account already exists. If you are logged in to Google, your data is assigned directly to your account. If you do not wish to be assigned to your Google profile, you must log out before activating the button. Google stores your data (even for users who are not logged in) as usage profiles and evaluates them.

 

The collection, storage, and evaluation are carried out in accordance with Art. 6 (1) (f) GDPR on the basis of Google's legitimate interest in displaying personalized advertising, market research, and/or tailoring Google websites to meet your needs. You have the right to object to the creation of these user profiles; you must contact Google to exercise this right. If you do not agree to the future transmission of your data to Google when using Google Maps, you also have the option of completely deactivating the Google Maps web service by disabling JavaScript in your browser. Google Maps, and thus also the map display on this website, can then no longer be used.

 

To the extent legally required, we have obtained your consent to process your data as described above in accordance with Art. 6 (1) (a) GDPR. You can revoke your consent at any time with future effect. To exercise your consent, please follow the objection option described above.

 

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision of the European Commission.

 

Further information on Google's data protection can be found here: https://business.safety.google/intl/de/privacy/

 

 7.2 Jitsi Meet

 

For online meetings, video conferences and/or webinars, we use this provider: 8×8, Inc., 675 Creekside Way, Campbell, California 95008, USA

 

The provider processes various types of data, with the extent of the data processed depending on what data you provide before or during participation in an online meeting, video conference, or webinar. Your data as a communication participant is processed and stored on the provider's servers. This may include, in particular, your login data (name, email address, telephone number (optional), and password) and session data (subject, participant IP address, device information, description (optional)).

 

In addition, image and sound contributions from participants as well as voice inputs in chats can be processed. Art. 6 (1) (b) GDPR serves as the legal basis for the processing of personal data that is necessary to fulfill a contract with you (this also applies to processing operations that are necessary to carry out pre-contractual measures). If you have given us your consent to process your data, the processing will be carried out on the basis of Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future. Furthermore, the legal basis for data processing when conducting online meetings, video conferences or webinars is our legitimate interest pursuant to Art. 6 (1) (f) GDPR in the effective conduct of the online meeting, webinar or video conference.

 

We have concluded a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorized disclosure to third parties.

 

For data transfers to the USA, the provider has joined the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision of the European Commission.

 

8) Tools and Other

 

Cookie-Consent-Tool

 

This website uses a so-called "cookie consent tool" to obtain effective user consent for cookies and cookie-based applications that require consent. The "cookie consent tool" is displayed when you visit the page in the form of an interactive user interface, where you can grant consent for specific cookies and/or cookie-based applications by checking the appropriate boxes. By using the tool, all cookies/services that require consent will only be loaded if you grant the corresponding consent by checking the appropriate boxes. This ensures that such cookies are only placed on your device if you have granted your consent.

 

The tool uses technically necessary cookies to save your cookie preferences. Personal user data is generally not processed.

 

If, in individual cases, personal data (such as the IP address) is processed for the purpose of storing, assigning or logging cookie settings, this is done in accordance with Art. 6 (1) (f) GDPR on the basis of our legitimate interest in legally compliant, user-specific and user-friendly consent management for cookies and thus in a legally compliant design of our website.

 

A further legal basis for processing is Art. 6 (1) (c) GDPR. As the controller, we are legally obliged to make the use of technically unnecessary cookies dependent on the respective user's consent.

 

Where necessary, we have concluded a data processing agreement with the provider, which ensures the protection of the data of our site visitors and prohibits unauthorized disclosure to third parties.

 

Further information about the operator and the setting options of the cookie consent tool can be found directly in the corresponding user interface on our website.

 

9) Rights of the data subject

 

 9.1 The applicable data protection law grants you the following data subject rights (rights to information and intervention) vis-à-vis us as the controller with regard to the processing of your personal data, whereby reference is made to the legal basis stated for the respective conditions for exercising these rights:

 

  • Right to information pursuant to Art. 15 GDPR;
  • Right to rectification pursuant to Art. 16 GDPR;
  • Right to erasure pursuant to Art. 17 GDPR;
  • Right to restriction of processing pursuant to Art. 18 GDPR;
  • Right to information pursuant to Art. 19 GDPR;
  • Right to data portability pursuant to Art. 20 GDPR;
  • Right to revoke consent given in accordance with Art. 7 (3) GDPR;
  • Right to lodge a complaint pursuant to Art. 77 GDPR.

 

 9.2 RIGHT OF OBJECTION

 

IF WE PROCESS YOUR PERSONAL DATA BASED ON OUR OVERRIDING LEGITIMATE INTEREST AS PART OF A BALANCE OF INTERESTS, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME WITH FUTURE EFFECT FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION.

 

If you exercise your right to object, we will stop processing the data in question. However, we reserve the right to continue processing if we can demonstrate compelling legitimate grounds for the processing that override your interests, fundamental rights, and freedoms, or if the processing serves to assert, exercise, or defend legal claims.

 

If we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing purposes. You can exercise your right of objection as described above.

 

IF YOU EXERCISE YOUR RIGHT OF OBJECTION, WE WILL STOP PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.

 

10) Duration of storage of personal data

 

The duration of storage of personal data is determined based on the respective legal basis, the purpose of the processing and – where applicable – also on the respective statutory retention period (e.g. retention periods under commercial and tax law).

 

When processing personal data on the basis of an express consent in accordance with Art. 6 (1) (a) GDPR, the data concerned will be stored until you revoke your consent.

 

If there are statutory retention periods for data that are processed within the framework of legal transactions or quasi-legal obligations on the basis of Art. 6 (1) (b) GDPR, these data will be routinely deleted after the retention periods have expired, provided that they are no longer required for the fulfilment or initiation of a contract and/or we no longer have a legitimate interest in continuing to store them.

 

When processing personal data on the basis of Art. 6 (1) (f) GDPR, these data will be stored until you exercise your right of objection in accordance with Art. 21 (1) GDPR, unless we can demonstrate compelling legitimate grounds for the processing which outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

 

When processing personal data for the purpose of direct marketing on the basis of Art. 6 (1) (f) GDPR, these data will be stored until you exercise your right of objection in accordance with Art. 21 (2) GDPR.

 

Unless otherwise stated in the other information in this declaration on specific processing situations, stored personal data will be deleted when they are no longer necessary for the purposes for which they were collected or otherwise processed.

 

Status: October 6, 2025, 1:40:05 PM