Privacy Policy
1. Introduction
With the following information, we would like to give you, as the „data subject“, an overview of the processing of your personal data by us and your rights under data protection laws. In principle, our websites can be used without entering any personal data. However, if you wish to use special services of our company via our website, processing of personal data could become necessary. If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain your consent.
The processing of personal data, such as your name, address, or email address, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the country-specific data protection regulations applicable to „hohrising“. By means of this data protection declaration, we would like to inform you about the scope and purpose of the personal data collected, used, and processed by us.
As the data controller, we have implemented numerous technical and organizational measures to ensure the most complete protection possible for personal data processed via this website. Nevertheless, internet-based data transmissions may inherently have security vulnerabilities, meaning that absolute protection cannot be guaranteed. For this reason, you are free to transmit personal data to us via alternative methods, such as by phone or mail.
You too can take simple and easy-to-implement measures to protect yourself against unauthorized third-party access to your data. Therefore, we would like to give you some advice on the secure handling of your data:
- Protect your account (login, user, or customer account) and your IT system (computer, laptop, tablet, or mobile device) with secure passwords.
- Only you should have access to the passwords.
- Make sure you only ever use your passwords for a single account (login, user, or customer account).
- Do not use the same password for different websites, applications, or online services.
- Particularly when using publicly accessible IT systems or those shared with other persons, the following applies: you should always log out again after every login to a website, an application, or an online service.
Passwords should be at least 12 characters long and chosen so that they cannot be easily guessed. Therefore, they should not contain common everyday words, your own name, or the names of relatives, but should include uppercase and lowercase letters, numbers, and special characters.
2. Controller
The controller within the meaning of the GDPR is:
hohrising
2 Im Dorfgraben
55130 Mainz, Germany
Phone: +49 170 61 22 360
Email: hello@hohrising.com
Representative of the data controller: Marius Hohmann
3. Data Protection Officer
We point out that no data protection officer has to be appointed.
The contact person for data protection:
Alexander Feist – External Data Protection Officer TÜV-Süd
Email: datenschutz@hohrising.de
4. Disclosure of Data to Third Parties
Your personal data will not be passed on to third parties for purposes other than those listed below.
We only share your personal data with third parties if:
1. You have given us your explicit consent pursuant to Art. 6 para. 1 lit. a) GDPR,
2. the disclosure pursuant to Art. 6 (1) (f) GDPR is permissible for the safeguarding of our legitimate interests and there is no reason to assume that you have an overriding interest requiring the protection of your data against disclosure,
3. in the event that there is a legal obligation for the disclosure pursuant to Art. 6 (1) (c) GDPR, and
4. this is permitted by law and is necessary, pursuant to Article 6(1)(b) of the GDPR, for the performance of contractual relationships with you.
To protect your data and, if necessary, enable us to transfer data to third countries (outside the EU/EEA), we have concluded data processing agreements based on the European Commission's standard contractual clauses. If the standard contractual clauses are not sufficient to establish an adequate level of security, your consent pursuant to Art. 49 para. 1 lit. a) GDPR may serve as the legal basis for the transfer to third countries. This does not apply, inter alia, to data transfers to third countries for which the European Commission has issued an adequacy decision pursuant to Art. 45 GDPR.
Your personal data will not be passed on to third parties for purposes other than those listed below.
We only share your personal data with third parties if:
1. You have given us your explicit consent pursuant to Art. 6 para. 1 lit. a) GDPR,
2. the disclosure pursuant to Art. 6 (1) (f) GDPR is permissible for the safeguarding of our legitimate interests and there is no reason to assume that you have an overriding interest requiring the protection of your data against disclosure,
3. in the event that there is a legal obligation for the disclosure pursuant to Art. 6 (1) (c) GDPR, and
4. this is permitted by law and is necessary, pursuant to Article 6(1)(b) of the GDPR, for the performance of contractual relationships with you.
As part of the data processing activities described in this Privacy Policy, personal data may be transferred to the United States. Companies in the United States are deemed to provide an adequate level of data protection only if they have obtained certification under the EU-U.S. Data Privacy Framework and the European Commission’s adequacy decision pursuant to Article 45 of the GDPR therefore applies. We have explicitly noted this for the relevant service providers in the Privacy Policy. To protect your data in all other cases, we have entered into data processing agreements based on the European Commission’s Standard Contractual Clauses. If the Standard Contractual Clauses are insufficient to ensure an adequate level of security, your consent pursuant to Article 49(1)(a) of the GDPR may serve as the legal basis for the transfer to third countries. This does not apply, however, to data transfers to third countries for which the European Commission has issued an adequacy decision pursuant to Article 45 of the GDPR.
5. Technology
5.1 SSL/TLS Encryption
This site uses SSL or TLS encryption to ensure the security of data processing and to protect the transmission of confidential information—such as orders, login credentials, or contact requests—that you send to us as the site operator. You can recognize an encrypted connection by the fact that the browser’s address bar displays „https://“ instead of „http://,“ and by the padlock icon in your browser’s address bar.
We use this technology to protect your transmitted data.
5.2 Data collection during visits to the website
When merely using our website for informational purposes, if you do not register or otherwise submit information to us, or if you do not give consent for processing that requires consent, we only collect data that is technically strictly necessary to provide the service. This is regularly data that your browser transmits to our server („in so-called server log files“). Each time a page is accessed by you or an automated system, our website collects a series of general data and information. This general data and information is stored in the server log files. The following may be collected:
1. types and versions of browsers used,
2. the operating system used by the accessing system,
3. the website from which an accessing system reached our website (so-called referrer),
4. the subpages that are accessed via an accessing system on our website,
5. the date and time of access to the website,
an Internet Protocol address (IP address) and,
7. the internet service provider of the accessing system.
When using these general data and information, we do not draw any conclusions about your person. Rather, this information is needed to
1. to deliver the content of our website correctly,
2. to optimize the content of our website and the advertising for it,
to ensure the permanent functionality of our IT systems and the technology of our website, as well as
4. to provide law enforcement authorities with the information necessary for law enforcement in the event of a cyberattack.
Therefore, we evaluate this collected data and information on the one hand statistically and on the other hand with the aim of increasing data protection and data security in our company, in order to ultimately ensure an optimal level of protection for the personal data processed by us. The server log file data is stored separately from any personal data provided by a data subject.
The legal basis for data processing is Art. 6 (1) sentence 1 lit. f) GDPR. Our legitimate interest follows from the purposes for data collection listed above.
5.3 Hosting by Webspace-Verkauf.de ISP e.K.
We host our website with Webspace-Verkauf.de ISP e.K., Lichtenfelser Strasse 17a, 96271 Grub am Forst (hereinafter referred to as Webspace-Verkauf).
When you visit our website, your personal data (e.g., IP addresses in log files) is processed on the servers of Webspace-Verkauf.
The use of web space sales is based on Art. 6 (1) lit. f GDPR. We have a legitimate interest in ensuring the most reliable presentation, provision, and security of our website.
We have concluded a data processing agreement (DPA) pursuant to Art. 28 GDPR with Webspace-Verkauf. This is a legally required agreement under data protection law that ensures Webspace-Verkauf processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
Further information on Webspace-Verkauf's privacy policy can be found at:
https://www.webspace-verkauf.de/datenschutz/
6. Cookies
6.1 General Information about Cookies
Cookies are small files that your browser automatically creates and that are stored on your IT system (laptop, tablet, smartphone, or similar) when you visit our site.
The cookie stores information resulting from the specific end device used in each case. However, this does not mean that we thereby obtain direct knowledge of your identity.
The use of cookies serves to make the use of our services more pleasant for you. For example, we use so-called session cookies to recognize that you have already visited individual pages of our website. These are automatically deleted after you leave our site.
Furthermore, we also use temporary cookies to optimize user-friendliness, which are stored on your device for a specific.
On the other hand, we use cookies to statistically record the use of our website and to evaluate our offerings for the purpose of optimization. These cookies enable us to automatically recognize that you have already visited our website when you visit us again. The cookies set in this way are automatically deleted after a respectively defined period. The respective storage duration of the cookies can be found in the settings of the consent tool used.
6.2 Legal Basis for the Use of Cookies
The data processed by the cookies that is required for the proper functioning of the website is therefore necessary to protect our legitimate interests and those of third parties in accordance with Art. 6 (1) sentence 1 lit. f) GDPR.
For all other cookies, you have given your consent to this via our opt-in cookie banner pursuant to Art. 6 (1) lit. a) GDPR.
6.3 Instructions for avoiding cookies in common browsers
Through the settings of the browser you are using, you have the option at any time to delete cookies, allow only selected cookies, or completely deactivate cookies. You can find further information on the support pages of the respective providers:
- Chrome: https://support.google.com/chrome/answer/95647?tid=311178978.
- Safari: https://support.apple.com/de-at/guide/safari/sfri11471/mac?tid=311178978.
- Firefox https://support.mozilla.org/de/kb/cookies-und-website-daten-in-firefox-loschen?tid=311178978.
- Microsoft Edge https://support.microsoft.com/de-de/microsoft-edge/cookies-in-microsoft-edge-l%C3%B6schen-63947406-40ac-c3b8-57b9-2a946a29ae09
6.4 Borlabs Cookie (Consent Management Tool)
We use the WordPress cookie plugin „Borlabs Cookie“ from Borlabs GmbH, Rübenkamp 32, 22305 Hamburg, Germany. This service enables us to obtain and manage consent for data processing from website users.
Borlabs Cookie uses cookies to collect data generated by end users who use our website. When an end user gives consent, the following data is automatically logged, among other things:
- Cookie lifespan,
- Cookie Version,
- Domain and path of the WordPress site,
- Selection in the cookie banner,
- UID (a randomly generated ID),
The consent status is also stored in the end user's browser so that the website can automatically read and respect the end user's consent on all subsequent page requests and future end-user sessions for up to 12 months. The consent data (consent and withdrawal of consent) is stored for three years. The retention period corresponds to the standard limitation period pursuant to Section 195 of the German Civil Code (BGB). The data will then be deleted immediately.
The functionality of the website cannot be guaranteed without the described processing. There is no right of objection for the user as long as there is a legal obligation to obtain the user's consent for certain data processing operations, Art. 7 (1), Art. 6 (1) sentence 1 lit. c) GDPR.
The collected data will neither be forwarded to Borlabs GmbH, nor will it have access to it.
For more information, please visit: https://de.borlabs.io/borlabs-cookie/.
7. Content of our website
7.1 Contact / Contact form
When contacting us (e.g., via contact form or email), personal data is collected. Which data is collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of answering your request or for contacting you and the associated technical administration. The legal basis for processing the data is our legitimate interest in responding to your request in accordance with Art. 6 (1) lit. f) GDPR. If your contact is aimed at the conclusion of a contract, an additional legal basis for the processing is Art. 6 (1) lit. b) GDPR. Your data will be deleted after your request has been processed, which is the case when it can be inferred from the circumstances that the matter in question has been conclusively clarified and there are no statutory retention obligations to the contrary.
8. Web Analytics
8.1 Google Analytics 4 (GA4)
On our websites, we use Google Analytics 4 (GA4), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland („Google“).
In this context, pseudonymized usage profiles are created and cookies (see section „Cookies“) are used. The information generated by the cookie about your use of this website may include, among other things:
- Temporary collection of the IP address without permanent storage
- Location data
- Browser Type/Version
- operating system used
- Referrer URL (previously visited page)
- Server request time
The pseudonymized data can be transmitted by Google to a server in the USA and stored there.
The information is used to evaluate the use of the website, to compile reports on website activity, and to provide other services associated with the use of the website and the internet for the purposes of market research and tailored design of these internet pages. This information may also be transferred to third parties if this is required by law or if third parties process this data on behalf.
These processing operations are carried out exclusively upon the granting of explicit consent pursuant to Art. 6 (1) lit. a) GDPR.
The retention period for data preset by Google is 14 months. Otherwise, personal data will be stored as long as necessary to fulfill the purpose of processing. The data will be deleted as soon as they are no longer required to achieve the purpose.
The parent company Google LLC, as a US company, is certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that the transfer of personal data may take place even without further guarantees or additional measures.
For more information on data privacy when using GA4, please visit:
https://support.google.com/analytics/answer/12017362?hl=de.
8.2 Google Analytics 4 (GA4) – Additional Information on Google Signals
Google Signals (also known as Google Signals) is a feature in Google Analytics that collects session data from websites and apps where users are logged into their Google account and have personalized advertising enabled. It enables advanced analysis by linking user behavior across different devices and providing additional information such as demographic characteristics and interests. Your consent to the use of Google Analytics (see above) also includes consent to the Google Signals additional feature.
8.3 Google Analytics Remarketing
We have integrated Google Remarketing services on this website. The operating company for the Google Remarketing services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Remarketing is a feature of Google AdWords that allows a company to display advertisements to internet users who have previously visited the company's website. The integration of Google Remarketing consequently enables a company to create user-specific advertising and thus display interest-relevant advertisements to the internet user.
The purpose of Google Remarketing is the display of interest-based advertising. Google Remarketing enables us to show advertisements via the Google advertising network or have them displayed on other internet pages that are tailored to the individual needs and interests of internet users.
Google Remarketing places a cookie on the IT system of the data subject. Setting the cookie enables Google to recognize the visitor of our website when they subsequently visit websites that are also members of the Google advertising network. With each visit to a website into which the Google Remarketing service has been integrated, your internet browser automatically identifies itself to Google. As part of this technical process, Google obtains knowledge of personal data, such as your IP address or surfing behavior, which Google uses, among other things, to display interest-based advertising.
The cookie is used to store personal information, such as the web pages you have visited. Accordingly, personal data, including your IP address, is transmitted to Google in the United States of America every time you visit our web pages. This personal data is stored by Google in the United States of America. Google may disclose this personal data collected via the technical procedure to third parties.
These processing operations are carried out exclusively upon the granting of explicit consent pursuant to Art. 6 (1) lit. a) GDPR.
The parent company Google LLC, as a US company, is certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that the transfer of personal data may take place even without further guarantees or additional measures.
You can view the privacy policy of Google Analytics Remarketing at:
https://www.google.de/intl/de/policies/privacy/ be accessed.
9. Advertising
9.1 Google Ads with conversion tracking
We have integrated Google Ads on this website. The operating company for Google Ads services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ads is an internet advertising service that allows advertisers to place ads both in Google's search engine results and within the Google advertising network. Google Ads enables an advertiser to pre-define specific keywords by means of which an ad is displayed in Google's search engine results exclusively when the user retrieves a keyword-relevant search result with the search engine. Within the Google advertising network, the ads are distributed on topic-relevant websites using an automatic algorithm and in compliance with the previously defined keywords.
The purpose of Google Ads is the promotion of our website through the display of interest-relevant advertising on third-party websites and in the search engine results of the Google search engine, as well as the display of third-party advertising on our website.
If you reach our website via a Google ad, a so-called conversion cookie is placed on your IT system by Google. A conversion cookie loses its validity after thirty days and is not used for your identification. Provided the cookie has not yet expired, the conversion cookie is used to track whether certain subpages—for example, the shopping cart of an online shop system—have been accessed on our website. The conversion cookie enables both us and Google to track whether a user who reached our website via an AdWords ad generated revenue, i.e., completed or abandoned a purchase.
The data and information collected through the use of the conversion cookie are used by Google to compile visit statistics for our website. We in turn use these visit statistics to determine the total number of users who were referred to us via Ads, i.e., to determine the success or failure of the respective Ads campaign and to optimize our Ads for the future. Neither our company nor other Google Ads advertisers receive information from Google that could be used to identify you.
The conversion cookie is used to store personal information, such as the web pages you have visited. Accordingly, with every visit to our web pages, personal data, including the IP address of the internet connection you use, is transmitted to Google in the United States of America. This personal data is stored by Google in the United States of America. Google may disclose this personal data collected via the technical procedure to third parties.
These processing operations are carried out exclusively upon the granting of explicit consent pursuant to Art. 6 (1) lit. a) GDPR.
The parent company Google LLC, as a US company, is certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that the transfer of personal data may take place even without further guarantees or additional measures.
You can view the privacy policy and further information from Google AdSense at:
https://www.google.de/intl/de/policies/privacy/.
10. Plugins and Other Services
10.1 Scheduling with Calendly
To provide a simplified way to book appointments, we use the online appointment calendar „Calendly“, provided by Calendly LLC, 3423 Piedmont Road NE, Atlanta, GA 30305-1754, USA.
When you click the corresponding booking button, you will be automatically connected to our appointment account on Calendly. After selecting your appointment, confirming it, and entering your contact information and request, you will receive an email from Calendly confirming your appointment. The information you provided in the Calendly form, including the data entered there, will be stored by us for the purpose of processing the request and in the event of follow-up questions. This data will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after the appointment has taken place). Mandatory statutory provisions, in particular retention periods, remain unaffected. Calendly will also inevitably gain knowledge of your data. We have concluded a data processing agreement with Calendly.
For each data processing operation, Calendly transmits personal data from the log files (e.g., IP addresses) to the USA, as certain servers for processing the log files are located exclusively in the USA.
The legal basis for data processing is your consent pursuant to Art. 6 (1) (a) GDPR, which you granted us before entering the appointment.
Detailed information about Calendly can be found at: https://calendly.com/privacy.
Alternatively, appointments can also be arranged by email or telephone.
10.2 Google Tag Manager
On this website, we use the Google Tag Manager service. The operating company of Google Tag Manager is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited is part of the Google corporate group with its headquarters at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This tool allows „website tags“ (i.e., keywords embedded in HTML elements) to be implemented and managed via an interface. By using Google Tag Manager, we can automatically track which button, link, or personalized image you have actively clicked, and can subsequently record which content on our website is of particular interest to you.
The tool also triggers other tags, which may in turn collect data. Google Tag Manager does not access this data. If you have opted out at the domain or cookie level, this opt-out remains in effect for all tracking tags implemented with Google Tag Manager.
These processing operations are carried out exclusively upon the issuance of explicit consent pursuant to Article 6 paragraph 1 letter a) of the GDPR.
The parent company Google LLC, as a US company, is certified under the EU-US Data Privacy Framework. An adequacy decision pursuant to Art. 45 GDPR is therefore in place, meaning that the transfer of personal data may take place even without further guarantees or additional measures.
Further information on the Google Tag Manager as well as Google's privacy policy can be viewed at: https://www.google.com/intl/de/policies/privacy/.
10.3 Microsoft Teams
We use the tool „Microsoft Teams“ („MS Teams“) for our communication, both in written form (chat) and in the form of telephone conferences, online meetings, and video conferences. The operating company of the service is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland („Microsoft“).
When using MS Teams, the following personal data is processed:
- Meetings, chats, voicemails, shared files, recordings, and transcriptions.
- Data that has been shared about you. Examples of this include your email address, profile picture, and phone number.
- A detailed history of the phone calls you make.
- Call quality data.
- Support/Feedback data Information related to troubleshooting tickets or feedback sent to Microsoft.
- Diagnostic and service data Diagnostic data related to service usage.
To enable video display and audio playback, the data from your device's microphone and video camera are processed for the duration of the meeting. You can turn off the camera or mute the microphone yourself at any time via the „Microsoft Teams“ applications.
Provided that appropriate consent has been obtained, the processing is carried out exclusively on the basis of Art. 6 (1) lit. a) GDPR. In the context of an employment relationship, such data processing is carried out on the basis of Section 26 BDSG (Federal Data Protection Act). The legal basis for the use of „MS Teams“ within the framework of contractual relationships is Art. 6 (1) lit. b) GDPR. In all other cases, the legal basis for the processing of your personal data is Art. 6 (1) lit. f) GDPR. In this regard, our legitimate interest lies in the effective conduct of online meetings.
If we record online meetings, we will inform you before they begin and, to the extent necessary, ask for your consent to the recording. If you do not wish for this, you can leave the online meeting.
As a cloud-based service, „MS Teams“ processes the aforementioned data as part of the provision of the service. To the extent that „MS Teams“ processes personal data in connection with Microsoft's legitimate business operations, Microsoft is an independent data controller for such use and, as such, is responsible for compliance with applicable laws and a data controller's obligations. To the extent that you access the MS Teams website, Microsoft is responsible for the data processing. Accessing the website is required to download the MS Teams software.
Microsoft generally processes data within the European Union under the so-called EU Data Boundary. To provide and secure the services as well as to fulfill legal obligations, Microsoft Ireland may transfer personal data to affiliated companies of Microsoft Corporation (Redmond, Washington, USA). Intra-group data transfer takes place on the basis of standard contractual clauses pursuant to Art. 46 para. 2 lit. c of the GDPR, as well as supplementary technical and organizational measures, as specified in the Microsoft Data Protection Addendum.
Microsoft Corporation is additionally certified under the EU-US Data Privacy Framework (DPF). As a result, an adequacy decision pursuant to Art. 45 GDPR exists for data transfers to the USA. Transfers of personal data to Microsoft in the USA are therefore permissible even without further guarantees or additional measures.
Detailed information regarding data privacy at Microsoft, in connection with „MS Teams,“ can be found at: https://docs.microsoft.com/de-de/microsoftteams/teams-privacy.
10.4 hCaptcha
We use hCaptcha (hereinafter „hCaptcha“) on this website. The provider is Intuition Machines, Inc., 2211 Selig Drive, Los Angeles, CA 90026, USA (hereinafter „IMI“).
hCaptcha is used to check whether data entry on this website (e.g., in a contact form) is done by a human or by an automated program. To this end, hCaptcha analyzes the behavior of the website visitor based on various characteristics.
This analysis begins automatically as soon as the website visitor enters a website with hCaptcha enabled. For the analysis, hCaptcha evaluates various information (e.g., IP address, length of time the website visitor spends on the website, or mouse movements made by the user). The data collected during the analysis is forwarded to IMI. If hCaptcha is used in „invisible mode,“ the analyses run completely in the background. Website visitors are not notified that an analysis is taking place.
The storage and analysis of the data are based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting its website offerings from abusive automated scraping and from SPAM. If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information on the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
Data processing is based on standard contractual clauses contained in the data processing addendum to IMI's general terms and conditions or the data processing agreements.
Further information on hCaptcha can be found in the privacy policy and terms of use at the following links:
https://www.hcaptcha.com/privacy and https://hcaptcha.com/terms
The company is certified under the EU-US Data Privacy Framework (DPF). The DPF is an agreement between the European Union and the USA designed to ensure compliance with European data protection standards when processing data in the USA. Every company certified under the DPF commits to complying with these data protection standards. You can obtain further information on this from the provider at the following link:
https://www.dataprivacyframework.gov/participant/6388
10.5 Wordfence
We have integrated Wordfence on this website. The provider is Defiant Inc., Defiant, Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA (hereinafter referred to as „Wordfence“).
Wordfence serves to protect our website against unwanted access or malicious cyberattacks. For this purpose, our website establishes a permanent connection to Wordfence's servers so that Wordfence can compare its databases with the access attempts made on our website and block them if necessary.
The use of Wordfence is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in protecting their website as effectively as possible against cyberattacks.
If corresponding consent has been requested, the processing is based exclusively on Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal equipment (e.g., device fingerprinting) within the meaning of the TDDDG. The consent can be revoked at any time.
Data transfer to the USA is based on the EU Commission's standard contractual clauses.
Find details here:
https://www.wordfence.com/help/general-data-protection-regulation/
Data processing agreement
We have concluded a data processing agreement (DPA) for the use of the aforementioned service. This is a legally required contract under data protection law that ensures the service processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
This privacy policy was created with the assistance of data protection software: audatis MANAGER.