Waste to Energy
Privacy Policy
This privacy policy explains the nature, scope and purpose of the processing of personal data (hereinafter referred to as “data”) within our online service and the associated websites, functions and content, as well as external online presences, such as our social media profiles. (hereinafter collectively referred to as the “online service”). With regard to the terms used, such as “processing” or “controller”, we refer to the definitions in Article 4 of the General Data Protection Regulation (GDPR).
Accountable
yes or no Media GmbH
Vor dem Lauch 4
70567 Stuttgart
Fon: +49 (0)711 75 85 89 – 00
redaktion@yes-or-no.de
Management: Claudia Wörner | Brigitte Lehner
Types of data processed:
– Personal information (e.g., names, addresses).
– Contact information (e.g., email addresses, phone numbers).
– Content data (e.g., text entries, photographs, videos).
– Usage data (e.g., websites visited, content interests, access times).
– Meta/communication data (e.g., device information, IP addresses).
Purpose of the processing
– Provision of the online service, its features, and content.
– Responding to contact requests and communicating with users.
– Safety measures.
– Reach Measurement/Marketing.
Terminology Used
“Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., a cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
“Processing” means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and encompasses virtually any interaction with data.
The term “controller” refers to the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.
Relevant legal basis
In accordance with Article 13 of the GDPR, we are providing you with the legal bases for our data processing activities. Unless the legal basis is specified in the privacy policy, the following applies: The legal basis for obtaining consent is Article 6(1)(a) and Article 7 of the GDPR; the legal basis for processing to fulfill our services, carry out contractual measures, and respond to inquiries is Article 6(1)(b) of the GDPR; the legal basis for processing to fulfill our legal obligations is Article 6(1)(c) of the GDPR, and the legal basis for processing to safeguard our legitimate interests is Article 6(1)(f) of the GDPR. In the event that the vital interests of the data subject or another natural person require the processing of personal data, Article 6(1)(d) of the GDPR serves as the legal basis.
Safety measures
We ask that you review the content of our Privacy Policy on a regular basis. We will update the Privacy Policy as soon as changes to our data processing practices make it necessary to do so. We will notify you as soon as the changes require action on your part (e.g., consent) or any other individual notification.
Cooperation with Data Processors and Third Parties
If, in the course of our data processing activities, we disclose data to other individuals or companies (processors or third parties), transfer it to them, or otherwise grant them access to the data, we do so only on the basis of a legal authorization (e.g., if the transfer of data to third parties, such as payment service providers, is necessary for the performance of a contract pursuant to Article 6(1)(b) of the GDPR), you have consented, a legal obligation requires it, or on the basis of our legitimate interests (e.g., when using agents, web hosts, etc.).
If we engage third parties to process data on the basis of a so-called “data processing agreement,” this is done in accordance with Article 28 of the DSGVO.
Transfers to third countries
If we process data in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in connection with the use of third-party services or the disclosure or transfer of data to third parties, we do so only if it is necessary to fulfill our (pre-)contractual obligations, based on your consent, due to a legal obligation, or based on our legitimate interests. Subject to statutory or contractual permissions, we process or have the data processed in a third country only if the specific requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of specific safeguards, such as the officially recognized determination of a level of data protection equivalent to that of the EU (e.g., for the U.S. through the “Privacy Shield”) or compliance with officially recognized specific contractual obligations (so-called “standard contractual clauses”).
Rights of data subjects
You have the right to request confirmation as to whether the relevant data is being processed, as well as access to that data, further information, and a copy of the data in accordance with Article 15 of the DSGVO.
Pursuant to Article 16 of the GDPR, you have the right to request that the data concerning you be completed or that any inaccurate data concerning you be corrected.
Pursuant to Article 17 of the GDPR, you have the right to request that the relevant data be erased without delay; alternatively, pursuant to Article 18 of the GDPR, you have the right to request that the processing of the data be restricted.
You have the right to request that the personal data you have provided to us be made available to you in accordance with Article 20 of the GDPR and to request that it be transferred to other data controllers.
You also have the right, pursuant to Article 77 of the GDPR, to lodge a complaint with the competent supervisory authority.
Right of Withdrawal
You have the right to withdraw any consent you have given in accordance with Article 7(3) of the GDPR with future effect.
Right to object
You may object at any time to the future processing of your personal data in accordance with Article 21 of the GDPR. In particular, you may object to the processing of your data for direct marketing purposes.
Cookies and the Right to Object to Direct Marketing
“Cookies” are small files that are stored on users' computers. Various types of information can be stored in cookies. A cookie is primarily used to store information about a user (or the device on which the cookie is stored) during or after their visit to a website. Temporary cookies, also known as “session cookies” or “transient cookies,” are cookies that are deleted after a user leaves an online service and closes their browser. Such a cookie can, for example, store the contents of a shopping cart in an online store or a login status. Cookies that remain stored even after the browser is closed are referred to as “permanent” or “persistent.” For example, the login status can be stored so that users can access it again after several days. Similarly, such a cookie can store the user’s interests, which are used for audience measurement or marketing purposes. “Third-party cookies” are cookies provided by providers other than the controller operating the online service (otherwise, if only the controller’s own cookies are used, they are referred to as “first-party cookies”).
We may use both temporary and permanent cookies, and we provide further information about this in our Privacy Policy.
If users do not wish to have cookies stored on their computer, they are asked to disable the corresponding option in their browser's settings. Stored cookies can be deleted in the browser's settings. Disabling cookies may result in limited functionality of this website.
A general objection to the use of cookies for online marketing purposes can be submitted for a wide range of services—particularly in the case of tracking—via the U.S. website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. Furthermore, you can prevent cookies from being stored by disabling them in your browser settings. Please note that this may prevent you from using all features of this website.
Deletion of Data
The data we process will be deleted or its processing restricted in accordance with Articles 17 and 18 of the GDPR. Unless expressly stated in this Privacy Policy, the data we store will be deleted as soon as it is no longer necessary for the purpose for which it was collected and there are no legal retention obligations preventing its deletion. If the data is not deleted because it is required for other legally permissible purposes, its processing will be restricted. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.
In accordance with German law, records must be retained for 6 years pursuant to Section 257(1) of the German Commercial Code (HGB) (commercial ledgers, inventories, opening balance sheets, annual financial statements, business correspondence, accounting documents, etc.) and for 10 years pursuant to Section 147(1) of the German Fiscal Code (AO) (books, records, management reports, accounting documents, business correspondence, documents relevant for taxation, etc.).
In accordance with Austrian law, records must be retained for 7 years pursuant to Section 132(1) of the Federal Tax Code (BAO) (accounting records, receipts/invoices, accounts, supporting documents, business papers, statements of income and expenses, etc.), for 22 years in connection with real estate, and for 10 years for documents related to electronically supplied services, telecommunications, radio, and television services provided to non-business customers in EU member states for which the Mini One-Stop Shop (MOSS) is utilized.
Business-related processing
In addition, we process
– Contract details (e.g., subject matter of the contract, term, customer category).
– Payment information (e.g., bank account details, payment history)
From our customers, prospective customers, and business partners for the purpose of providing contractual services, customer support, marketing, advertising, and market research.
Hosting
The hosting services we use are intended to provide the following: infrastructure and platform services, computing capacity, storage space, and database services, as well as security and technical maintenance services, which we utilize for the purpose of operating this online service.
In this context, we—or our hosting provider—process personal data, contact information, content data, contractual data, usage data, metadata, and communication data from customers, prospective customers, and visitors to this online service based on our legitimate interest in providing this online service efficiently and securely, in accordance with Article 6(1)(f) of the GDPR in conjunction with Article 28 of the GDPR (conclusion of a data processing agreement).
Collection of access data and log files
We, or rather our hosting provider, collect data regarding every access to the server on which this service is located (so-called server log files) based on our legitimate interests within the meaning of Article 6(1)(f) of the GDPR. The access data includes the name of the accessed webpage, the file, the date and time of access, the amount of data transferred, a notification of successful access, the browser type and version, the user’s operating system, the referrer URL (the previously visited page), the IP address, and the requesting provider.
For security reasons (e.g., to investigate cases of misuse or fraud), log file information is stored for a maximum of 7 days and then deleted. Data that must be retained for evidentiary purposes is exempt from deletion until the incident in question has been fully resolved.
Agency Services
We process our customers' data as part of our contractual services, which include conceptual and strategic consulting, campaign planning, software and design development/consulting or maintenance, campaign and process implementation/management, server administration, data analysis/consulting services, and training services.
In doing so, we process master data (e.g., customer master data such as names or addresses), contact data (e.g., email, phone numbers), content data (e.g., text entries, photographs, videos), contract data (e.g., subject matter of the contract, term), payment data (e.g., bank details, payment history), usage and metadata (e.g., in the context of evaluating and measuring the success of marketing measures). We generally do not process special categories of personal data, unless they are part of commissioned processing. Data subjects include our customers, prospective customers, and their customers, users, website visitors, or employees, as well as third parties. The purpose of the processing is to provide contractual services, handle billing, and provide customer service. The legal basis for the processing is Article 6(1)(b) of the GDPR (contractual services) and Article 6(1)(f) of the GDPR (analysis, statistics, optimization, and security measures). We process data necessary for the establishment and fulfillment of contractual services and indicate that providing such data is required. Disclosure to third parties occurs only if required within the scope of a contract. When processing data entrusted to us within the scope of a contract, we act in accordance with the client’s instructions and the legal requirements for data processing on behalf of a client pursuant to Article 28 of the GDPR, and we process the data for no other purposes than those specified in the contract.
We delete the data once statutory warranty obligations and similar obligations have expired. The necessity of retaining the data is reviewed every three years; in the case of statutory archiving obligations, the data is deleted upon their expiration (6 years, pursuant to Section 257(1) of the German Commercial Code (HGB); 10 years, pursuant to Section 147(1) of the German Fiscal Code (AO)). In the case of data disclosed to us by the client in connection with an order, we delete the data in accordance with the terms of the order, generally upon completion of the order.
Administration, Financial Accounting, Office Organization, Contact Management
We process data in connection with administrative tasks, the organization of our operations, financial accounting, and compliance with legal obligations, such as archiving. In doing so, we process the same data that we process in connection with the provision of our contractual services. The legal bases for processing are Article 6(1)(c) of the GDPR and Article 6(1)(f) of the GDPR. This processing affects customers, prospective customers, business partners, and website visitors. The purpose and our interest in the processing lie in administration, financial accounting, office organization, and data archiving—that is, tasks that serve to maintain our business operations, fulfill our responsibilities, and provide our services. The deletion of data related to contractual services and contractual communication corresponds to the information provided regarding these processing activities.
In this context, we disclose or transfer data to tax authorities, advisors (such as tax advisors or auditors), as well as other billing agencies and payment service providers.
In addition, based on our business interests, we store information about suppliers, event organizers, and other business partners, for example, to enable us to contact them at a later date. We generally store this data, which is primarily company-related, on a permanent basis.
Business Analysis and Market Research
In order to operate our business efficiently and identify market trends as well as customer and user preferences, we analyze the data we have on business transactions, contracts, inquiries, etc. In doing so, we process inventory data, communication data, contract data, payment data, usage data, and metadata on the basis of Article 6(1)(f) of the GDPR, whereby the data subjects include customers, prospective customers, business partners, visitors, and users of the online offering.
The analyses are conducted for the purposes of business evaluation, marketing, and market research. In doing so, we may take into account the profiles of registered users, including information such as their purchase history. The analyses help us improve user-friendliness, optimize our offerings, and enhance operational efficiency. The analyses are used solely by us and are not disclosed externally, unless they consist of anonymous analyses with aggregated data.
If these analyses or profiles contain personal data, they will be deleted or anonymized upon termination of the user’s account; otherwise, they will be deleted or anonymized two years after the contract is concluded. In all other cases, overall business analyses and general trend assessments are prepared anonymously whenever possible.
Privacy Notice for the Application Process
We process applicant data solely for the purpose of and within the scope of the application process, in accordance with legal requirements. The processing of applicant data is carried out to fulfill our (pre)contractual obligations within the scope of the application process pursuant to Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR, provided that data processing becomes necessary for us, e.g., in the context of legal proceedings (in Germany, § 26 BDSG also applies).
The application process requires applicants to provide us with their application information. The required application information is marked as such; if we provide an online form, it is otherwise specified in the job descriptions. Generally, this includes personal details, mailing and contact addresses, and the documents required for the application, such as a cover letter, resume, and certificates. In addition, applicants may voluntarily provide us with additional information.
By submitting their application to us, applicants consent to the processing of their data for the purposes of the application process in accordance with the manner and scope described in this Privacy Policy.
To the extent that special categories of personal data within the meaning of Article 9(1) of the GDPR are voluntarily provided as part of the application process, their processing is additionally carried out in accordance with Article 9(2)(b) of the GDPR (e.g., health data, such as severe disability status or ethnic origin). To the extent that special categories of personal data within the meaning of Article 9(1) of the GDPR are requested from applicants as part of the application process, their processing is additionally carried out in accordance with Article 9(2)(a) of the GDPR (e.g., health data, if such data is necessary for the performance of the job).
If available, applicants can submit their applications to us using an online form on our website. The data is transmitted to us using state-of-the-art encryption technology.
Applicants may also submit their applications to us via email. However, please note that emails are generally not sent in encrypted form, and applicants must ensure encryption themselves. We therefore cannot assume any responsibility for the transmission of the application between the sender and our server, and we therefore recommend using an online form or sending the application by mail. In addition to applying via the online form and email, applicants still have the option of sending their application to us by mail.
The data provided by applicants may be further processed by us for the purposes of the employment relationship in the event of a successful application. Otherwise, if the application for a job opening is unsuccessful, the applicants’ data will be deleted. Applicants’ data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time.
Subject to a valid revocation by the applicant, the data will be deleted after a period of six months has elapsed, so that we can answer any follow-up questions regarding the application and fulfill our reporting obligations under the Equal Treatment Act. Invoices for any travel expense reimbursements will be archived in accordance with tax regulations.
Talent-Pool
As part of the application process, we offer applicants the opportunity to be included in our “talent pool” for a period of two years, subject to their consent in accordance with Article 6(1)(b) and Article 7 of the GDPR.
The application documents in the talent pool will be processed solely for the purpose of future job postings and recruitment efforts and will be destroyed no later than the expiration of the application deadline. Applicants are informed that their consent to be included in the talent pool is voluntary, has no impact on the current application process, and that they may revoke this consent at any time for the future and object in accordance with Article 21 of the GDPR.
Contact Us
When you contact us (e.g., via the contact form, email, phone, or social media), your information will be processed in accordance with Article 6(1)(b) of the GDPR for the purpose of handling your inquiry and processing it. Your information may be stored in a customer relationship management system (“CRM system”) or a similar inquiry management system.
We delete the requests once they are no longer necessary. We review their necessity every two years; in addition, statutory retention requirements apply.
VG Wort / Scalable Centralized Measurement Method
We use the “Scalable Central Measurement Method” (SZM) provided by INFOnline GmbH (INFOnline GmbH, Brühler Str. 9, D-53119 Bonn) to determine statistical parameters for assessing the likelihood of text copying. This process involves the collection of anonymous data. To recognize computer systems, the traffic measurement uses either a session cookie or a signature generated from various pieces of information automatically transmitted by your browser. IP addresses are processed only in anonymized form. The method was developed in compliance with data protection regulations. The sole purpose of the method is to determine the likelihood of individual texts being copied. Individual users are never identified at any time. Your identity remains protected at all times. You will not receive any advertising through the system.
Many of our pages include JavaScript calls that we use to report page views to the collecting society VG Wort. This allows our authors to receive a share of VG Wort’s distributions, which ensure the statutory remuneration for the use of copyrighted works in accordance with Section 53 of the German Copyright Act (UrhG).
In this process, user usage data and metadata are processed; IP addresses are truncated, and the measurement methods are pseudonymous. The truncated IP address is stored for a maximum of 60 days. The usage data, in conjunction with a pseudonymous identifier, is stored for a maximum of 6 months.
Users also have the option to opt out of data collection for the aforementioned purposes: https://optout.ioam.de. For more information, please refer to INFOnline’s privacy policy at https://www.infonline.de/datenschutz/benutzer.
Newsletter
The following information explains the content of our newsletter, as well as our subscription, distribution, and statistical analysis procedures, and your rights to object. By subscribing to our newsletter, you agree to receive it and to the procedures described herein.
Newsletter Content: We send newsletters, emails, and other electronic communications containing promotional information (hereinafter “newsletters”) only with the recipients’ consent or when permitted by law. If the content of the newsletter is specifically described during the subscription process, that description is decisive for the user’s consent. In addition, our newsletters contain information about our services and our company.
Double opt-in and logging: Signing up for our newsletter is done via a so-called double opt-in process. This means that after signing up, you will receive an email asking you to confirm your subscription. This confirmation is necessary to ensure that no one can sign up using someone else’s email address. Newsletter subscriptions are logged to provide proof of the registration process in accordance with legal requirements. This includes storing the time of registration and confirmation, as well as the IP address. Changes to your data stored with the mailing service provider are also logged.
Subscription information: To subscribe to the newsletter, simply enter your email address. Optionally, you may also provide your name so that we can address you personally in the newsletter.
Germany: The distribution of the newsletter and the associated performance measurement are based on the recipients’ consent pursuant to Article 6(1)(a) and Article 7 of the GDPR in conjunction with Section 7(2)(3) of the German Unfair Competition Act (UWG), or on the basis of the statutory authorization pursuant to Section 7(3) of the UWG.
The registration process is logged based on our legitimate interests pursuant to Article 6(1)(f) of the GDPR. Our interest lies in using a user-friendly and secure newsletter system that serves both our business interests and meets users’ expectations, and also allows us to document consent.
Unsubscribe/Withdrawal – You can unsubscribe from our newsletter at any time, i.e., withdraw your consent. A link to unsubscribe from the newsletter can be found at the bottom of every newsletter. We may store unsubscribed email addresses for up to three years based on our legitimate interests before deleting them, in order to be able to prove that consent was previously given. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for deletion is possible at any time, provided that the prior existence of consent is confirmed at the same time.
Newsletter – Mailing Service Provider
The newsletter is sent via the mailing service provider Newsletter2Go, Köpenicker Str. 126, 10179 Berlin, Germany. You can view the mailing service provider’s privacy policy here: https://www.newsletter2go.de/datenschutz-uebersicht/. The mailing service provider is engaged on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR and a data processing agreement pursuant to Art. 28(3)(1) GDPR.
The mailing service provider may use recipients' data in pseudonymous form—that is, without linking it to a specific user—to optimize or improve its own services, such as for technical improvements to the delivery and presentation of newsletters or for statistical purposes. However, the mailing service provider does not use the data of our newsletter recipients to contact them directly or to share the data with third parties.
Newsletter – Measuring Success
The newsletters contain a so-called “web beacon,” which is a pixel-sized file that is retrieved from our server—or, if we use a mailing service provider, from their server—when you open the newsletter. When this file is retrieved, technical information—such as details about your browser and operating system—as well as your IP address and the time of retrieval are collected.
This information is used to improve our services technically based on technical data, or to analyze target groups and their reading behavior based on their location (which can be determined using their IP address) or access times. Statistical analyses also include determining whether newsletters are opened, when they are opened, and which links are clicked. For technical reasons, this information can be traced back to individual newsletter recipients. However, it is neither our intention, nor—if used—that of the mailing service provider, to monitor individual users. Rather, the analyses serve to help us identify our users’ reading habits and adapt our content accordingly, or to send different content based on our users’ interests.
Jetpack (WordPress Stats)
Based on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR), we use the Jetpack plugin (specifically the “WordPress Stats” sub-feature), which integrates a tool for the statistical analysis of visitor traffic and is provided by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA. Jetpack uses so-called “cookies,” text files that are stored on your computer and enable an analysis of your use of the website.
Automattic is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection laws (https://www.privacyshield.gov/participant?id=a2zt0000000CbqcAAC&status=Active).
The information generated by the cookie regarding your use of this website is stored on a server in the United States. User profiles may be created from the processed data, but these are used solely for analytical purposes and not for advertising. For more information, please refer to Automattic’s privacy policy: https://automattic.com/privacy/ and information about Jetpack cookies: https://jetpack.com/support/cookies/.
Google Analytics
We use Google Analytics, a web analytics service provided by Google LLC (“Google”), based on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic viability of our online offering within the meaning of Article 6(1)(f) of the GDPR). Google uses cookies. The information generated by the cookie regarding users’ use of the online service is generally transmitted to a Google server in the United States and stored there.
Google is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection laws (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
Google will use this information on our behalf to evaluate how users interact with our website, to compile reports on activity within the website, and to provide us with other services related to the use of the website and internet usage. In doing so, pseudonymous user profiles may be created from the processed data.
We use Google Analytics only with IP anonymization enabled. This means that Google truncates users’ IP addresses within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transmitted to a Google server in the United States and truncated there.
The IP address transmitted by the user's browser is not combined with other data held by Google. Users can prevent the storage of cookies by adjusting their browser settings accordingly; users can also prevent the collection of data generated by the cookie and related to their use of the online service by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available at the following link: http://tools.google.com/dlpage/gaoptout?hl=de.
For more information about Google’s use of data, as well as options for adjusting settings and opting out, please refer to Google’s Privacy Policy (https://policies.google.com/technologies/ads) and the settings for Google ads (https://adssettings.google.com/authenticated).
Users' personal data is deleted or anonymized after 14 months.
Social media presence
We maintain online presences on social networks and platforms to communicate with customers, prospective customers, and users who are active there and to inform them about our services. When accessing these networks and platforms, the terms and conditions and data processing policies of their respective operators apply.
Unless otherwise specified in our Privacy Policy, we process users’ data when they communicate with us on social networks and platforms, such as by posting comments on our online presence or sending us messages.
Integration of third-party services and content
Within our online offering, we use third-party content and service providers based on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic viability of our online offering within the meaning of Article 6(1)(f) of the GDPR) to integrate content or services from third-party providers, such as videos or fonts (hereinafter collectively referred to as “Content”).
This always requires that the third-party providers of this content collect the user’s IP address, as they would be unable to send the content to the user’s browser without it. The IP address is therefore necessary for the display of this content. We strive to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as “web beacons”) for statistical or marketing purposes. Pixel tags allow information such as visitor traffic on the pages of this website to be analyzed. The pseudonymous information may also be stored in cookies on the user’s device and may include, among other things, technical information about the browser and operating system, referring websites, visit duration, and other details regarding the use of our online service, as well as being linked to such information from other sources.
Vimeo
We may embed videos from the “Vimeo” platform provided by Vimeo Inc., Attention: Legal Department, 555 West 18th Street, New York, New York 10011, USA. Privacy Policy: https://vimeo.com/privacy. Please note that Vimeo may use Google Analytics; for more information, please refer to the privacy policy (https://www.google.com/policies/privacy) as well as the opt-out options for Google Analytics (http://tools.google.com/dlpage/gaoptout?hl=de) or Google’s settings for data usage for marketing purposes (https://adssettings.google.com/).
YouTube
We embed videos from the “YouTube” platform provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy Policy: https://www.google.com/policies/privacy/, Opt-out: https://adssettings.google.com/authenticated.
Google Maps
We integrate maps from the “Google Maps” service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The data processed may include, in particular, users’ IP addresses and location data; however, this data is not collected without their consent (which is typically provided through the settings on their mobile devices). The data may be processed in the United States. Privacy Policy: https://www.google.com/policies/privacy/, Opt-Out: https://adssettings.google.com/authenticated.
Use of Facebook Social Plugins
Based on our legitimate interests (i.e., our interest in analyzing, optimizing, and ensuring the economic operation of our online offering within the meaning of Article 6(1)(f) of the GDPR), we use social plugins (“plugins”) from the social network facebook.com, which is operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”). The plugins may display interactive elements or content (e.g., videos, graphics, or text posts) and are recognizable by one of the Facebook logos (a white “f” on a blue tile, the terms “Like,” “Gefällt mir,” or a “thumbs-up” icon) or are labeled with the addition “Facebook Social Plugin.” The list and appearance of the Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins/.
Facebook is certified under the Privacy Shield Framework and thereby guarantees compliance with European data protection laws (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active).
When a user accesses a feature of this website that contains such a plugin, their device establishes a direct connection to Facebook’s servers. The content of the plugin is transmitted directly from Facebook to the user’s device and integrated into the website. In the process, user profiles may be created based on the processed data. We therefore have no influence over the scope of the data that Facebook collects using this plugin and are therefore informing users in accordance with our current knowledge.
When the plugins are integrated, Facebook receives information that a user has accessed the corresponding page of the website. If the user is logged into Facebook, Facebook can associate the visit with their Facebook account. When users interact with the plugins—for example, by clicking the “Like” button or posting a comment—the corresponding information is transmitted directly from your device to Facebook and stored there. Even if a user is not a member of Facebook, there is still a possibility that Facebook may obtain and store their IP address. According to Facebook, only an anonymized IP address is stored in Germany.
Users can find information regarding the purpose and scope of data collection, as well as the further processing and use of data by Facebook, along with their rights and privacy settings, in Facebook’s Privacy Policy: https://www.facebook.com/about/privacy/.
If a user is a Facebook member and does not want Facebook to collect data about them through this website and link it to their Facebook account information, they must log out of Facebook and delete their cookies before using our website. Additional settings and opt-outs regarding the use of data for advertising purposes are available in the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the U.S. site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/. These settings are platform-independent, meaning they apply to all devices, such as desktop computers or mobile devices.
Twitter / X
Our website may incorporate features and content from Twitter, a service provided by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. This may include, for example, content such as images, videos, or text, as well as buttons that allow users to express their appreciation for the content, follow the authors of the content, or subscribe to our posts. If users are members of the Twitter platform, Twitter may associate the access to the aforementioned content and features with the users’ profiles on that platform. Twitter is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAO&status=Active). Privacy Policy: https://twitter.com/de/privacy, Opt-Out: https://twitter.com/personalization.
Instagram
Our website may incorporate features and content from the Instagram service, provided by Instagram Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. This may include, for example, content such as images, videos, or text, as well as buttons that allow users to like the content, follow the content creators, or subscribe to our posts. If users are members of the Instagram platform, Instagram may associate the access to the aforementioned content and features with the users’ profiles on that platform. Instagram’s Privacy Policy: http://instagram.com/about/legal/privacy/.
Pinterest
Our website may incorporate features and content from the Pinterest service, provided by Pinterest Inc., 635 High Street, Palo Alto, CA 94301, USA. This may include, for example, content such as images, videos, or text, as well as buttons that allow users to express their liking for the content, follow the content creators, or subscribe to our posts. If users are members of the Pinterest platform, Pinterest may associate the access to the aforementioned content and features with the users’ profiles on that platform. Pinterest’s Privacy Policy: https://about.pinterest.com/de/privacy-policy.
Xing
Our website may incorporate features and content from the Xing service, provided by XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany. This may include, for example, content such as images, videos, or text, as well as buttons that allow users to express their appreciation for the content, contact the authors of the content, or subscribe to our posts. If users are members of the Xing platform, Xing may associate the access to the aforementioned content and features with the users’ profiles on that platform. Xing’s Privacy Policy: https://www.xing.com/app/share?op=data_protection.
LinkedIn
Our website may incorporate features and content from LinkedIn, a service provided by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. This may include, for example, content such as images, videos, or text, as well as buttons that allow users to express their appreciation for the content, follow the authors of the content, or subscribe to our posts. If users are members of the LinkedIn platform, LinkedIn may associate the access to the aforementioned content and features with the users’ profiles on that platform. LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy. LinkedIn is certified under the Privacy Shield Agreement and thereby guarantees compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active). Privacy Policy: https://www.linkedin.com/legal/privacy-policy, Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
Created using Datenschutz-Generator.de by Attorney Dr. Thomas Schwenke
Additional guidelines regarding the use of WIX
We (“we,” “us,” “our”) take the protection of the data of users (“Users” or “you”) of our website and/or our mobile app (the “Website” or the “Mobile App”) very seriously and are committed to protecting the information that Users provide to us in connection with their use of our Website and/or our Mobile App (collectively: “digital assets”). Furthermore, we are committed to protecting and using your data in accordance with applicable law.
This Privacy Policy explains our practices regarding the collection, use, and disclosure of your information when you use our digital assets (the “Services”) by accessing the Services through your devices.
Please read this Privacy Policy carefully and ensure that you fully understand our practices regarding your data before using our services. If you have read and fully understood this Policy and do not agree with our practices, you must stop using our digital assets and services. By using our services, you acknowledge the terms of this Privacy Policy. Your continued use of the services constitutes your consent to this Privacy Policy and any changes to it.
In this Privacy Policy, you will learn:
-
How We Collect Data
-
What Data We Collect
-
Why We Collect This Data
-
Who We Share the Data With
-
Where the Data Is Stored
-
How Long the Data Is Retained
-
How We Protect the Data
-
How We Handle Minors
-
Updates or Changes to the Privacy Policy
What data do we collect?
Below is an overview of the data we may collect:
Unidentified and unidentifiable information that you provide during the registration process or that is collected through your use of our services (“non-personal data”). Non-personal data does not allow us to determine who provided it. The non-personal data we collect consists primarily of technical and aggregated usage information.
Personally identifiable information, i.e., any information that can be used to identify you or that could be used to identify you with reasonable effort (“personal data”). The personal data we collect through our services may include information requested from time to time, such as names, email addresses, mailing addresses, phone numbers, IP addresses, and more. When we combine personal data with non-personal data, we treat the combined data as personal data for as long as it remains combined.
How do we collect data?
The following is a list of the main methods we use to collect data:
We collect data when you use our services. Therefore, when you visit our digital assets and use our services, we may collect, record, and store information regarding your usage, sessions, and related data.
We collect data that you provide to us yourself, for example, when you contact us directly through a communication channel (such as an email containing a comment or feedback).
As described below, we may collect data from third-party sources. We collect data that you provide to us when you sign up for our services through a third-party provider such as Facebook or Google.
Why do we collect this data?
We may use your data for the following purposes:
-
to provide and operate our services;
-
to develop, customize, and improve our services;
-
to respond to your feedback, inquiries, and requests, and to offer assistance;
-
to analyze demand and usage patterns;
-
for other internal, statistical, and research purposes;
-
to improve our data security and fraud prevention capabilities;
-
to investigate violations and enforce our terms and policies, as well as to comply with applicable laws, regulations, and government orders;
-
to send you updates, news, promotional materials, and other information related to our services. For promotional emails, you can decide for yourself whether you would like to continue receiving them. If not, simply click the unsubscribe link in these emails.
Who do we share this data with?
We may share your data with our service providers in order to operate our services (e.g., storing data via third-party hosting services, providing technical support, etc.).
We may also disclose your information under the following circumstances:
(i) to investigate, detect, prevent, or take action against illegal activities or other misconduct;
(ii) to establish or exercise our rights in our defense;
(iii) to protect our rights, property, or personal safety, as well as the safety of our users or the public;
(iv) in the event of a change of control at our company or at one of our affiliates (through a merger, acquisition, or purchase of (substantially) all assets, among other things);
(v) to collect, store, and/or manage your data through authorized third-party providers (e.g., cloud service providers), to the extent that this is reasonable for business purposes;
(vi) to work with third-party providers to improve your user experience. To avoid any misunderstanding, we would like to point out that we may not transfer, disclose, or otherwise use non-personal data to third parties at our sole discretion.
Please note that our services enable social interactions (e.g., publicly posting content, information, and comments, and chatting with other users). We would like to remind you that any content or data you make available in these areas may be read, collected, and used by others. We advise against posting or sharing information with others that you do not wish to make public. If you upload content to our digital assets or otherwise make it available while using a service, you do so at your own risk. We cannot control the actions of other users or members of the public who have access to your data or content. You acknowledge and hereby confirm that copies of your data may remain accessible even after deletion on cached and archived pages or after a copy of your content has been created or stored by third parties.
Cookies and Similar Technologies
When you visit or access our services, we authorize third parties to use web beacons, cookies, pixel tags, scripts, and other technologies and analytics services (“Tracking Technologies”). These tracking technologies may enable third parties to automatically collect your data in order to improve your browsing experience on our digital assets, optimize their performance, and ensure a personalized user experience, as well as for security and fraud prevention purposes.
Through our services and our digital assets (including websites and applications that use our services), we may display advertisements that may be tailored to you, such as ads based on your recent browsing activity on websites, devices, or browsers.
To deliver these ads to you, we may use cookies and/or JavaScript and/or web beacons (including clear GIFs) and/or HTML5 local storage and/or other technologies. We may also use third parties, such as ad networks (i.e., third parties that display ads based on your website visits), to serve targeted ads. Third-party ad networks, advertisers, sponsors, and/or website traffic measurement services may also use cookies and/or JavaScript and/or web beacons (including clear GIFs) and/or Flash cookies and/or other technologies to measure the effectiveness of their ads and to customize advertising content for you. These third-party cookies and other technologies are subject to the specific privacy policy of the respective third-party provider and not to this one.
Where do we store the data?
Non-Personal Data
Please note that our companies, as well as our trusted partners and service providers, are located around the world. For the purposes described in this Privacy Policy, we store and process all non-personal data that we collect in various jurisdictions.
Personal Data
Personal data may be maintained, processed, and stored in the United States, Ireland, South Korea, Taiwan, Israel, and, to the extent necessary for the proper provision of our services and/or as required by law (as further explained below), in other jurisdictions.
How long is the data retained?
Please note that we retain the collected data for as long as necessary to provide our services, comply with our legal and contractual obligations to you, resolve disputes, and enforce our agreements.
We may correct, supplement, or delete inaccurate or incomplete data at any time at our sole discretion.
How do we protect the data?
The hosting service for our digital assets provides us with the online platform through which we can offer our services to you. Your data may be stored using our hosting provider’s data storage systems, databases, and general applications. The provider stores your data on secure servers behind a firewall and offers secure HTTPS access to most areas of its services.
All payment options offered by us and our hosting provider for our digital assets comply with the PCI-DSS (Payment Card Industry Data Security Standard) regulations of the PCI Security Standards Council. This is a collaborative effort involving brands such as Visa, MasterCard, American Express, and Discover. PCI-DSS requirements help ensure the secure handling of credit card data (including physical, electronic, and procedural measures) by our store and our service providers.
Notwithstanding the measures and efforts taken by us and our hosting provider, we cannot and will not guarantee absolute protection or security of the data you upload, publish, or otherwise share with us or others.
For this reason, we ask that you set strong passwords and, whenever possible, refrain from sharing confidential information with us or others that, in your opinion, could cause you significant or lasting harm if disclosed. Since email and instant messaging are not considered secure forms of communication, we also ask that you refrain from sharing confidential information via any of these communication channels.
How do we deal with minors?
Children may use our services. However, if they wish to access certain features, they may be required to provide certain information. Some data (including data collected via cookies, web beacons, and other similar technologies) may be collected automatically. If we knowingly collect, use, or disclose data collected from a child, we will provide notice and obtain parental consent in accordance with applicable law. We do not make a child’s participation in an online activity contingent on the child providing more contact information than is reasonably necessary for participation in that activity. We use the data we collect only in connection with the services the child has requested.
We may also use a parent’s contact information to communicate about the child’s activities on the Services. Parents may view the data we have collected from their child, prohibit us from collecting any further data from their child, and request that all data we have collected be deleted from our records.
Please contact us to view, update, or delete your child’s data. To protect your child, we may ask you to provide proof of your identity. We may deny you access to the data if we believe your identity is in question. Please note that certain data cannot be deleted due to other legal obligations.
We use your personal data only for the purposes set forth in the Privacy Policy and only if we are convinced that:
-
the use of your personal data is necessary to fulfill or enter into a contract (e.g., to provide you with the services themselves or with customer service or technical support);
-
the use of your personal data is necessary to comply with applicable legal or regulatory obligations; or
-
the use of your personal data is necessary to support our legitimate business interests (provided that this is always done in a manner that is proportionate and respects your data protection rights).
As an EU resident, you can:
-
request confirmation as to whether or not personal data concerning you is being processed, and request access to your stored personal data as well as certain additional information;
-
request to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format;
-
request the correction of your personal data stored by us;
-
request the deletion of your personal data;
-
object to our processing of your personal data;
-
request the restriction of the processing of your personal data; or
-
file a complaint with a supervisory authority.
Please note, however, that these rights are not absolute and may be subject to our own legitimate interests and regulatory requirements. If you have general questions about the personal data we collect and how we use it, please contact us as indicated below.
In the course of providing the Services, we may transfer data across borders to affiliated companies or other third parties, and from your country/jurisdiction to other countries/jurisdictions worldwide. By using the Services, you consent to the transfer of your data outside the EEA.
If you are located in the EEA, your personal data will only be transferred to locations outside the EEA if we are satisfied that an adequate or comparable level of protection for personal data exists. We will take appropriate steps to ensure that we have adequate contractual arrangements in place with our third parties to guarantee that appropriate security measures are taken to minimize the risk of unauthorized use, alteration, deletion, loss, or theft of your personal data, and that these third parties act in accordance with applicable laws at all times.
Rights Under the California Consumer Protection Act
If you use the Services as a California resident, you may be entitled under the California Consumer Privacy Act (CCPA) to request access to and deletion of your data.
To exercise your right to access and delete your data, please see below for information on how to contact us.
Category: The website does not sell its users’ data
We do not sell users’ personal information for the purposes defined by the CCPA.
Users of the Services who are California residents and under the age of 18 may request and obtain the removal of their published content by emailing the address provided below in the “Contact” section. All such requests must be labeled “California Removal Request.” All requests must include a description of the content you wish to have removed, as well as sufficient information to help us locate the material. We do not accept notices that are not labeled or submitted properly, and we may not be able to respond if you do not provide sufficient information. Please note that your request does not guarantee that the material will be completely or comprehensively removed. For example, material you have posted may be republished or reposted by other users or third parties.
Updates or Changes to the Privacy Policy
We may revise this Privacy Policy from time to time at our discretion; the version published on the website is always the most current one (see the “Effective Date” section). We ask that you review this Privacy Policy regularly for changes. In the event of material changes, we will post a notice on our website. If you continue to use the services after we have posted a notice of changes on our website, this will be deemed your acknowledgment and acceptance of the changes to the Privacy Policy and your agreement to be bound by the terms of those changes.
Contact
If you have general questions about our services or the data we collect about you and how we use it, please contact us at:
Name: Claudia Wörner
Address: Vor der Lauch 4, 70567 Stuttgart
E-Mail: redaktion@yes-or-no.de