<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:media="http://search.yahoo.com/mrss/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xml:lang="ko">
	<channel>
		<title>주간 OSM</title>
		<link>https://hugo.weeklyosm.eu/ko/</link>
		<description>Recent content on 주간 OSM</description>
		<generator>Hugo</generator>
		<language>ko</language>
		
			<managingEditor>info@weeklyosm.eu (weeklyteam)</managingEditor>
		
		
			<webMaster>info@weeklyosm.eu (weeklyteam)</webMaster>
		
		
		<image>
			<url>https://hugo.weeklyosm.eu/icons/favicon-32x32.png</url>
			<title>주간 OSM</title>
			<link>https://hugo.weeklyosm.eu/ko/</link>
		</image>
		
			<lastBuildDate>Sun, 26 Jul 2026 00:00:00 +0000</lastBuildDate>
		
			<atom:link href="https://hugo.weeklyosm.eu/ko/feed.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>주간 OSM 835</title>
				<link>https://hugo.weeklyosm.eu/ko/archives/0835/</link>
				<pubDate>Sun, 26 Jul 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/archives/0835/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/07/835-scaled.webp" alt="주간 OSM 835" /> 2026.07.16.-2026.07.22.
지도 제작 캠페인 인도 자이푸르에 거주하는 장거리 등산객 Manav Singh Shekhawat이 사하야드리 산맥을 가로질러 약 3,500 km를 걸으면서 2,000 km에 달하는 등산로를 오픈스트리트맵에 그렸다고 Mid-Day지의 Ranjeet Jadhav 기자가 보도했습니다. 커뮤니티 OpenCage에서 Matt Whilden을 인터뷰했습니다. Matt은 오픈스트리트맵 편집자로서의 여정, 오픈스트리트맵 미국 이사회를 통해 커뮤니티를 지원하는 활동, 창의적인 지도 그리기에 갖는 열정을 이야기했습니다.
Jikke Meyer 보츠와나를 시작으로 오픈스트리트맵에 축구 경기장을 상세히 그릴 계획이라고 밝혔습니다. ]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/07/835-scaled.webp" alt="주간 OSM 835" /></p> <p>2026.07.16.-2026.07.22.</p>
<h2 id="지도-제작-캠페인">지도 제작 캠페인</h2>
<ul>
<li><a id="wn835_35022"></a>
 인도 자이푸르에 거주하는 장거리 등산객 Manav Singh Shekhawat이 사하야드리 산맥을 가로질러 약 3,500 km를 걸으면서 2,000 km에 달하는 등산로를 오픈스트리트맵에 그렸다고 Mid-Day지의 Ranjeet Jadhav 기자가 <a href="https://www.mid-day.com/mumbai/mumbai-news/article/jaipur-trekker-maps-over-2000-km-of-sahyadri-trails-for-safer-hiking-23639982">보도했습니다</a>.</li>
</ul>
<h2 id="커뮤니티">커뮤니티</h2>
<ul>
<li>
<p><a id="wn835_35024"></a>
 OpenCage에서 Matt Whilden을 <a href="https://blog.opencagedata.com/post/openstreetmap-interview-watmildon">인터뷰했습니다</a>. Matt은 오픈스트리트맵 편집자로서의 여정, 오픈스트리트맵 미국 이사회를 통해 커뮤니티를 지원하는 활동, 창의적인 지도 그리기에 갖는 열정을 이야기했습니다.</p>
</li>
<li>
<p><a id="wn835_35025"></a>
 Jikke Meyer 보츠와나를 시작으로 오픈스트리트맵에 축구 경기장을 상세히 그릴 계획이라고 <a href="https://mastodon.social/@JikMey/116942743283185972">밝혔습니다</a>. <span class="inline-icon" style="-webkit-mask: url('/wp-content/uploads/2022/01/fr.svg') no-repeat center / contain; mask: url('/wp-content/uploads/2022/01/fr.svg') no-repeat center / contain;"></span></p>
</li>
<li>
<p><a id="wn835_35021"></a>
 Volker Krause가 HTW 베를린에 참석해 오픈스트리트맵에서 실내 공간 지도화와 관련된 주제를 논의하는 워크숍에서 의견을 <a href="https://volkerkrause.eu/2026/07/18/osm-indoor-workshop-july-2026.html">피력했습니다</a>.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-지부">오픈스트리트맵 지부</h2>
<ul>
<li><a id="wn835_35036"></a>
 오픈스트리트맵 말라가에서 스페인 말라가의 자전거 이용자 단체인 Ruedas Redondas 협회가 오픈스트리트맵 데이터를 바탕으로 <a href="https://www.ruedasredondas.org/aparcabicis-malaga">자전거 주차 지도 정보</a>를 공식 홈페이지에 추가했다고 <a href="https://en.osm.town/@osmmalaga/116945565500697038">보도했습니다</a>. Ruedas Redondas 협회에서 설명한 바와 같이, 해당 지도는 지역 오픈스트리트맵 커뮤니티의 협력 덕분에 &ldquo;가장 완벽하고 최신 정보가 반영&quot;되어 있습니다. <span class="inline-icon" style="-webkit-mask: url('/wp-content/uploads/2022/01/es.svg') no-repeat center / contain; mask: url('/wp-content/uploads/2022/01/es.svg') no-repeat center / contain;"></span></li>
</ul>
<h2 id="지도">지도</h2>
<ul>
<li>
<p><a id="wn835_35054"></a>
 Nicolas Seriot가 오픈스트리트맵 데이터를 1990년대 후반을 연상시키는 지도 스타일로 보여주는 <a href="https://seriot.ch/cartopolis/">Cartopolis</a>를 <a href="https://www.reddit.com/r/openstreetmap/comments/1v4a57n/cartopolis_todays_maps_in_1999style_gifs/">개발했습니다</a>.</p>
</li>
<li>
<p><a id="wn835_35030"></a>
 HeiGIT에서 베네수엘라에서 일어나는 재난에 대응하기 위한 맞춤형 openrouteservice 인스턴스를 <a href="https://heigit.org/dynamic-routing-for-disaster-response-in-venezuela/">선보였습니다</a>. 오픈스트리트맵과 HDX의 실시간 도로 차단 데이터를 결합해 손상되거나 통행이 불가능한 구역을 우회해 인도주의 지원 차량의 경로를 동적으로 안내할 수 있습니다.</p>
</li>
<li>
<p><a id="wn835_35038"></a>
 Jaz Michaelking가 누구나 게시글을 쓸 수 있고, 특정 국가/지역/도시를 대상으로 서비스를 제공하면서, 관리가 잘 이루어지는 SNS 제공업체들을 엄선하여 시각화한 웹 지도인 &lsquo;Fediverse Near Me&rsquo;를 <a href="https://umap.openstreetmap.fr/en/map/fediverse-near-me_828094#3/54.316523/16.699219">개발했습니다</a>.</p>
</li>
<li>
<p><a id="wn835_35028"></a>
 <a href="https://livellosegreto.it/@alorenzi">Alessandro Lorenzi</a>가 오픈스트리트맵 데이터베이스의 특정 지형 정보와 연결된 모든 사진을 보여주는 동적 지도, <a href="https://alessandrolorenzi.github.io/openstreetphoto/">OpenStreetPhoto</a>를 개발했습니다. 현재 OpenStreetPhoto는 이탈리아에서만 이용할 수 있습니다.</p>
</li>
<li>
<p><a id="wn835_35033"></a>
 Vladimir Terentyev가 &ldquo;필라프는 어디에서 끝나고 비리아니는 어디서 시작되는가, 그리고 과연 누가 이러한 경계를 정하는가?&ldquo;라는 연구 질문의 답을 찾기 위해 오픈스트리트맵의 전 세계 식당 데이터를 활용해 <a href="https://vova.today/en/works/plofornot/">식당 간판에 적힌 요리 이름을 보여주는 세계 지도</a>를 제작했습니다.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-활용-사례">오픈스트리트맵 활용 사례</h2>
<ul>
<li><a id="wn835_35035"></a>
 Stefan Keller가 오픈스트리트맵과 정부 공공데이터를 기반으로 구축된 지도 제작 웹 앱 2개를 <a href="https://spatialists.ch/posts/2026/07/20-open-geodata-in-action-vivamap-and-urbanistmap/">소개했습니다</a>. <a href="https://vivamap.ch/">VivaMap</a>은 오픈스트리트맵의 관심 지점(POI) 및 건물 정보를 공식 데이터 집합과 결합해 스위스 각 지역의 맞춤형 삶의 질 지표를 구축하는 작업을 돕는 반면, <a href="https://urbanistmap.org">UrbanistMap</a>은 지역 사회에서 전 세계 도시 개발 프로젝트의 위치를 공동으로 파악하고 시각화할 수 있게 해줍니다. UrbanistMap은 현지 지식을 갖춘 사람들이 오픈스트리트맵의 데이터를 업데이트하도록 장려하는 데 매우 적합합니다. <span class="inline-icon" style="-webkit-mask: url('/wp-content/uploads/2022/01/fr.svg') no-repeat center / contain; mask: url('/wp-content/uploads/2022/01/fr.svg') no-repeat center / contain;"></span></li>
</ul>
<h2 id="소프트웨어">소프트웨어</h2>
<ul>
<li>
<p><a id="wn835_35046"></a>
 ^[1]^ Oleksandr Nazarenko가 건물 입구의 정확한 위치와 아파트 호수 범위를 표시하는 데 중점을 둔 내비게이션 앱, <a href="https://pidiizd.web.app/">Pidyizdy</a>를 <a href="https://www.threads.com/@bachennya/post/DbFzlH1jO-s?xmt=AQG09RuEKruLUmG0A2w-TtXeo0MkFjorOdh0qDQ3jR8haWZY0WmiohhJhJY8VZx8HwSSNjq9">개발했습니다</a>. Pidyizdy는 <a href="https://mezha.ua/news/app-that-guides-users-to-the-correct-entrance-313492/">입구를 찾기 위해 공동주택을 이리저리 헤매는 일이 많은</a> 택배 기사, 택시 기사, 공공 서비스 종사자들을 대상으로 만들어졌습니다. <span class="inline-icon" style="-webkit-mask: url('/wp-content/uploads/2021/02/uk.svg') no-repeat center / contain; mask: url('/wp-content/uploads/2021/02/uk.svg') no-repeat center / contain;"></span></p>
</li>
<li>
<p><a id="wn835_35017"></a>
 darkonus가 <a href="https://community.openstreetmap.org/t/fillet-tools-a-small-josm-plugin-for-rounding-corners/143796">최근 개발한</a> JOSM 플러그인 FilletTools를 Pavel Gavrilov가 사용해 본 후기를 <a href="https://www.openstreetmap.org/user/_PG_/diary/409044">남겼습니다</a>. FilletTools 플러그인을  사용하면 선과 다각형의 모서리를 둥글게 다듬을 수 있을 뿐만 아니라 대충 그린 선을 매끄러운 경로로 <a href="https://www.youtube.com/watch?v=agyY25jVeGM">변환할 수도 있습니다</a>. Pavel은 FilletTools를 높이 평가하면서, 새로운 JOSM 플러그인 중에서도 이처럼 많은 사용자의 작업 흐름에서 표준 도구로 자리 잡을 만한 강력한 장점을 갖춘 플러그인은 드물다고 강조했습니다.</p>
</li>
<li>
<p><a id="wn835_35027"></a>
 2019년 아이폰과 아이패드용 프리미엄 앱으로 처음 출시된 <a href="https://anyfinder.app">AnyFinder</a>는 이제 스마트폰, 태블릿, 데스크톱 컴퓨터에서 오픈스트리트맵에 등록된 장소를 검색/추가/편집할 수 있는 무료 웹 애플리케이션의 형태로 제공됩니다. AnyFinder는 백엔드 질의 엔진으로 Overpass와 Postpass를 사용합니다. AnyFinder는 식당과 상점부터 공공 서비스 및 자연 지물에 이르기까지 장소 범주 286종을 그룹 66종으로 묶어 제공합니다.</p>
</li>
</ul>
<p>범주는 검색할 장소의 종류를 정의하며, 128개에 달하는 필터를 통해 휠체어 접근성, 요리 종류, 연료 유형, 이용 가능한 시설과 같은 속성에 따라 결과를 세분화할 수 있습니다. 현재 데이터는 구조화된 지물 47종과 오픈스트리트맵 태그 435개를 기반으로 정리되어 있습니다. 장소 정보를 수정하려면 오픈스트리트맵 계정을 먼저 만들고, AnyFinder를 통해 오픈스트리트맵에 변경 사항을 직접 제출하시면 됩니다.</p>
<ul>
<li>
<p><a id="wn835_35031"></a>
 Tina와 Eugene이 OsmAnd에 내장된 측정 도구(탭으로 거리 측정, 눈금자, 반경 측정자, 목적지까지의 직선)의 사용법을 <a href="https://osmand.net/blog/measuring-tools/">소개했습니다</a>.</p>
</li>
<li>
<p><a id="wn835_35043"></a>
 OsmAnd에서 작은 지역 지도들을 모아 만든 대규모 국가/지역 단위 파일인 &lsquo;통합(merged) 지도&rsquo;의 지원을 종료했다고 Tina와 Eugene이 <a href="https://osmand.net/blog/merged-maps/">공지했습니다</a>. 통합 지도를 설치한 경우 이제 더 이상 해당 지도의 업데이트를 받을 수 없게 됩니다.</p>
</li>
<li>
<p><a id="wn835_35045"></a>
 uMap이 NGI0 Commons Fund를 통해 벡터 지도 타일을 uMap에 통합하는 데 필요한 보조금을 <a href="https://nlnet.nl/project/uMapVectorTiles/">지원받았다고</a>  David Larlet가 <a href="https://www.openstreetmap.org/user/David%20Larlet/diary/409079">밝혔습니다</a>. 현재 벡터 타일 맞춤 설정에 중점을 두고 작업이 진행 중이며, uMap에 벡터 타일이 완전히 도입된다면 지도를 쓰는 목적에 더 잘 부합하도록 건물을 제거하거나 도로의 색상을 바꾸는 등 배경 지도의 스타일을 원하는 대로 수정할 수 있게 됩니다.</p>
</li>
<li>
<p><a id="wn835_35032"></a>
 Stadia Maps에서 지오코딩 프로토타입을 실제 운영 수준의 애플리케이션으로 전환하는 과정에서 업계의 표준 가격 책정 방식이 겉보기만큼 간단하지 않다는 실망스러운 현실이 드러난다고 <a href="https://stadiamaps.com/blog/why-is-your-geocoding-bill-higher-than-it-should-be/">설명했습니다</a>. 구체적으로 대부분의 서비스 제공업체가 질의 결과를 저장하는 데 높은 추가 비용(대개 일반 질의 비용의 6~8배)을 부과하며, 일부 업체는 캐싱을 단일 사용자 세션으로만 제한하는 엄격한 규칙을 적용하기도 합니다.</p>
</li>
<li>
<p><a id="wn835_35042"></a>
 smallCat이 JOSM 내에서 여러 엔드포인트 및 다중 계정를 동시에 쓸 수 있게 해 주는 <a href="https://github.com/daishu0000/josm-account-manager">플러그인</a>을 개발했습니다. JOSM의 <a href="https://josm.openstreetmap.de/wiki/PluginsSource?action=diff&amp;version=882&amp;old_version=880">플러그인 설정</a>에서 바로 설치할 수 있습니다.</p>
</li>
<li>
<p><a id="wn835_35023"></a>
 Koharachan이 iD 편집기를 <a href="https://github.com/koharachan/BetteriD">포크해</a> AI 지원 기능을 비롯해 지도 제작을 편리하게 해주는 기능을 여럿 추가하고 있다고 <a href="https://www.openstreetmap.org/user/%E5%B0%8F%E5%8E%9F%E9%85%B1/diary/409066">발표했습니다</a>. <span class="inline-icon" style="-webkit-mask: url('/wp-content/uploads/2020/08/zh-cn-black.svg') no-repeat center / contain; mask: url('/wp-content/uploads/2020/08/zh-cn-black.svg') no-repeat center / contain;"></span></p>
</li>
<li>
<p><a id="wn835_35041"></a>
 Fedilab에서 동물 복지를 위한 협업 지도, PawFed를 <a href="https://toot.fedilab.app/@apps/116245941766830884">개발했습니다</a>. 마스토돈 계정에서 @PawFed를 태그하고 관련 해시태그와 위치를 함께 기재하면 해당 정보가 지도에 표시됩니다. 지도를 통해 보호소, 동물병원, 분실 및 발견된 동물, 사료 기부 정보 등 동물에게 도움이 될 수 있는 다양한 정보를 볼 수 있습니다.</p>
</li>
<li>
<p><a id="wn835_35016"></a>
 2026년 구글 서머 오브 코드에 참여해 closures.osm.ch 프로젝트를 진행하고 있는 Venetis Charalampidis가 현황을 보고해 본 프로젝트의 목표 중 하나인 &lsquo;폐쇄된 도로를 실제로 우회하는 발할라(Valhalla) 기반 경로 설정 엔드포인트 추가&rsquo;가 막 완료되었다고 <a href="https://www.openstreetmap.org/user/Venetis%20Charalampidis/diary/409056">밝혔습니다</a>.</p>
</li>
</ul>
<h2 id="프로그래밍">프로그래밍</h2>
<ul>
<li>
<p><a id="wn835_35040"></a>
 Marcos Dione가 오픈스트리트맵의 도로망 데이터를 분석해 프랑스 마르세유의 도시 블록 크기를 보여주는 지도를 <a href="https://en.osm.town/@mdione/116241441575150164">제작했습니다</a>.</p>
</li>
<li>
<p><a id="wn835_35044"></a>
 오스트리아/독일계 오픈스트리트맵 타일 호스팅 업체 <a href="https://www.maptoolkit.org/">Maptoolkit</a>에서 상업적 사용이 허용되는 무료 벡터 타일 서버를 출시했습니다. Maptoolkit에서는 관광 및 아웃도어 활동에 중점을 둔 독창적인 지도 기능을 제공하며, 아웃도어 특화 지도 스타일(하이킹, 자전거, 겨울 스포츠), 음영 기복도, 등고선, 수심, 3차원 지형, 최대 15배까지 지원하는 데이터 확대/축소 기능이 갖춰져 있습니다. 해당 서비스는 유럽 연합 내에서 호스팅되며 개인정보 보호에 중점을 둡니다. API 키, 로그인, 쿠키가 필요하지 않으며, GDPR을 완벽하게 준수합니다. 또한 사용자 정의 스타일시트를 지원하며, <a href="https://mapmaker.maptoolkit.org">mapmaker.maptoolkit.org</a>를 통해 초보자도 쉽게 사용할 수 있는 새로운 지도 편집기를 이용할 수 있습니다. AI로 Maptoolkit을 활용하는 방법을 포함해 상세한 <a href="https://docs.maptoolkit.org/">문서화</a>를 제공하며, OpenFreeMap, Protomaps, Versatiles, OpenMapTiles와의 <a href="https://www.maptoolkit.org/compare">비교</a>도 볼 수 있습니다.</p>
</li>
</ul>
<h2 id="출시">출시</h2>
<ul>
<li><a id="wn835_35029"></a>
 uMap 3.8.0a4 업데이트가 7월 18일에 <a href="https://docs.umap-project.org/en/master/changelog/#380a4-2026-07-18">올라왔습니다</a>.</li>
</ul>
<h2 id="알고-계셨나요">알고 계셨나요?</h2>
<ul>
<li><a id="wn835_35020"></a>
 Observing the City에서 자신이 생각하는 &lsquo;시내(downtown)&lsquo;을 직접 그려보고, 그 정의를 다른 사람들의 정의와 비교해 볼 수 있는 웹 앱, Where is Downtown?을 <a href="https://www.observingthecity.ca/downtown-definer">개발했습니다</a>.</li>
</ul>
<h2 id="매체-속-오픈스트리트맵">매체 속 오픈스트리트맵</h2>
<ul>
<li><a id="wn835_35019"></a>
 온라인 잡지 Konvert에서 위키백과, 오픈스트리트맵, iNaturalist, 프로젝트 구텐베르크, 스택 오버플로우와 같은 자원봉사 프로젝트에 참가하는 사람들을 <a href="https://unisender.com/ru/blog/kak-rabotayut-besplatnye-proekty">인터뷰했습니다</a>. <span class="inline-icon" style="-webkit-mask: url('/wp-content/uploads/2022/01/ru.svg') no-repeat center / contain; mask: url('/wp-content/uploads/2022/01/ru.svg') no-repeat center / contain;"></span></li>
</ul>
<h2 id="기타-지리-관련-소식">기타 &lsquo;지리&rsquo; 관련 소식</h2>
<ul>
<li>
<p><a id="wn835_35039"></a>
 <a href="https://github.com/clement-igonet">clement_igonet</a>이 OSM US 슬랙 커뮤니티에서 유럽의 행정 구역 경계에 시간 슬라이더를 표시하는 작은 <a href="https://time-slider.confinia.io">MapLibre 애플리케이션</a>(<a href="https://confinia.github.io/valserhone.gif">사용 예시</a>)을 개발했다고 밝혔습니다. 애플리케이션에서 사용되는 다각형은 유효 기간을 반영해 모델링한 API(INSEE COG, IGN Admin Express, Eurostat GISCO)에서 가져온 것입니다. 이들 API는 모두 공개 데이터이며, 현재로서는 오픈스트리트맵 데이터는 사용되지 않았습니다. 애플리케이션의 기반이 되는 API는 <a href="https://api.confinia.io">api.confinia.io</a>입니다. 소스 코드는 <a href="https://github.com/confinia/confinia-core">깃허브</a>에 올라와 있습니다.</p>
</li>
<li>
<p><a id="wn835_35026"></a>
 미국 NOAA 연안관리국에서는 <a href="https://coast.noaa.gov/digitalcoast/">Digital Coast</a>를 비롯한 주요 프로그램 4개를 운영하고 있는데, 최근 Digital Coast 서비스와 관련해 평균 해수면 변화 시나리오를 추정하고 이에 영향을 받을 것으로 예상되는 (모니터링 대상 지역 내) 해안가를 보여주는 <a href="https://coast.noaa.gov/sealevelcalculator/">해수면 계산기</a>를 출시했습니다. 이용자들의 편의를 돕기 위해 사용 방법을 동영상 형태로 <a href="https://coast.noaa.gov/elearning/video/slc">제공하고 있습니다</a>.</p>
</li>
<li>
<p><a id="wn835_35034"></a>
 HeiGIT에서 Point of Interest 뉴스레터 제1호를 <a href="https://mailings.heigit.org/m/17210084/547227-c3fd08c1dff687c6a597f5ea19a92427ffd0c39cd2c77553e86ae7eb4297827acb16cfc817f2dc93ff395c451bcf9af4">발간했습니다</a>. 이번 호에서는 OpenRouteService의 최신 발전 동향, 인도주의적 활용을 위한 최신 개발 내용, 그리고 HeiGIT의 향후 방향을 중점적으로 다루었습니다.</p>
</li>
</ul>
<h2 id="다가오는-행사">다가오는 행사</h2>
<table>
	<thead>
			<tr>
					<th>국가</th>
					<th>장소</th>
					<th>행사장</th>
					<th>명칭</th>
					<th>일시</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>MapCup Asia Pacific 2026 <a href="https://osmcal.org/event/4911/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-01 - 2026-07-31</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/10/ci.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Abidjan</td>
					<td>cURAT</td>
					<td>MAPATHON TIEBISSOU <a href="https://osmcal.org/event/4970/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-12 - 2026-07-24</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSMF Engineering Working Group meeting <a href="https://osmcal.org/event/4978/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-24</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2024/08/ge.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Online</td>
					<td>Racha Mapping Party <a href="https://osmcal.org/event/4985/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-27 - 2026-08-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum 0</td>
					<td>Braunschweiger Mappertreffen im Stratum 0 Hackerspace <a href="https://osmcal.org/event/4990/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Kiel</td>
					<td>Mango&rsquo;s, Kiel</td>
					<td>Kieler Mapper*innentreffen <a href="https://osmcal.org/event/4992/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>Online</td>
					<td>OSM-Verkehrswende #77 <a href="https://osmcal.org/event/4909/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Mannheim</td>
					<td>RaumZeitLabor, Mannheim</td>
					<td>Rhein-Neckar OSM Treffen <a href="https://osmcal.org/event/4979/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-29</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Düsseldorf</td>
					<td>Online bei <a href="https://meet.jit.si/OSM-DUS-2026">https://meet.jit.si/OSM-DUS-2026</a></td>
					<td>Düsseldorfer OpenStreetMap-Treffen (online) <a href="https://osmcal.org/event/4387/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-29</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>UN Mappers Community Discussion: Community Chapters Initiative <a href="https://osmcal.org/event/4971/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-31</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hannover</td>
					<td>Endhaltestelle Roderbruch der Stadtbahnlinie 4</td>
					<td>Mapping Party <a href="https://osmcal.org/event/4927/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-07-31</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Thiruvananthapuram</td>
					<td>Kazhakoottam Market bus stop</td>
					<td>Mapping Party at Kazhakoottam <a href="https://osmcal.org/event/4994/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-01</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>नई दिल्ली</td>
					<td>Jitsi Meet (online)</td>
					<td>OSM India - Monthly Online Mapathon <a href="https://osmcal.org/event/4887/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-01</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/08/se.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Uppsala</td>
					<td>Datorföreningen Update</td>
					<td>Kartträff i Uppsala. Tema Cykelinfrastruktur <a href="https://osmcal.org/event/4988/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Salzburg</td>
					<td>Bewohnerservice Elisabeth-Vorstadt</td>
					<td>OSM-Treffpunkt <a href="https://osmcal.org/event/4470/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-04</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mapathon (with Training) Beginner Friendly  (Online) [eng] <a href="https://osmcal.org/event/4236/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-04</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>iD Community Chat <a href="https://osmcal.org/event/4973/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-05</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stuttgart</td>
					<td>Biergarten Tschechen &amp; Söhne</td>
					<td>Stuttgarter OpenStreetMap-Treffen <a href="https://osmcal.org/event/4931/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-05</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Angers</td>
					<td>L’Arrière Train, 3 rue de Frémur, Angers</td>
					<td>Angers Rencontre mensuelle OpenStreetMap <a href="https://osmcal.org/event/4932/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Bar Le Schmilblik</td>
					<td>Rencontre mensuelle des contributeurs Paris sud <a href="https://osmcal.org/event/4883/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/07/dk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>København</td>
					<td>Cafe Bevar&rsquo;s</td>
					<td>OSMmapperCPH <a href="https://osmcal.org/event/4880/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>New Delhi</td>
					<td>North Delhi</td>
					<td>OSM Delhi Mapping Party No.31 (North Zone) <a href="https://osmcal.org/event/4899/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/tw.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>臺北市</td>
					<td>MozSpace Taipei</td>
					<td>OpenStreetMap x Wikidata Taipei #91 <a href="https://osmcal.org/event/4327/"><img src="/wp-content/uploads/2024/02/osmcal.png" class="inline-icon-img" alt="" style="height: 1em; width: auto; vertical-align: middle; display: inline-block;" /></a></td>
					<td>2026-08-10</td>
			</tr>
	</tbody>
</table>
<p><em>이 주간OSM은 다음 사람들이 <a href="https://umap.openstreetmap.fr/de/map/weeklyosm-is-currently-produced-in_56718#2/8.4/108.3">제작했습니다</a>. <a href="https://www.openstreetmap.org/user/LuxuryCoop">LuxuryCoop</a>, <a href="https://www.openstreetmap.org/user/MatthiasMatthias">MatthiasMatthias</a>, <a href="https://ivides.org/raquel-deziderio">Raquel Dezidério Souto</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, Andrew Davidson.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>주간 OSM 834</title>
				<link>https://hugo.weeklyosm.eu/ko/archives/0834/</link>
				<pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/archives/0834/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/07/834_1.png" alt="주간 OSM 834" /> 2026.07.09.-2026.07.15.
지도 제작 현재 찬반 투표가 진행 중인 제안은 아래와 같습니다.
실내 지도 제작에서 indoor=wall + area=yes 태그를 통해 벽을 영역으로 그릴 수 있도록 하자는 제안 데이터 센터(telecom=data_center)의 세부 속성(총 전력 용량, IT 부하, 사용 가능 연면적 등)을 오픈스트리트맵에 나타내자는 제안(7월 22일까지) 의견을 받고 있는 제안은 아래와 같습니다.
외국어 이름 및 외래어 명칭을 나타내기 위해 int_name을 쓰지 말자는 제안. 지금까지 int_name 태그는 로마자 표기법 혹은 외래어 명칭을 나타내는 데 일관성 없이 사용되어 왔으며, 표준인 name:&lt;언어&gt; 패턴을 따르지 않기 때문입니다.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/07/834_1.png" alt="주간 OSM 834" /></p> <p>2026.07.09.-2026.07.15.</p>
<h2 id="지도-제작">지도 제작</h2>
<ul>
<li>
<p><a id="wn834_35007"></a>
   현재 찬반 투표가 진행 중인 제안은 아래와 같습니다.</p>
<ul>
<li>실내 지도 제작에서 <code>indoor=wall</code> + <code>area=yes</code> 태그를 통해 벽을 영역으로 그릴 수 있도록 하자는 <a href="https://wiki.openstreetmap.org/wiki/Proposal:Allow_area=yes_for_indoor=wall">제안</a></li>
<li>데이터 센터(<code>telecom=data_center</code>)의 세부 속성(총 전력 용량, IT 부하, 사용 가능 연면적 등)을 오픈스트리트맵에 나타내자는 <a href="https://wiki.openstreetmap.org/wiki/Proposal:Data_center_technical_attributes">제안</a>(7월 22일까지)</li>
</ul>
</li>
<li>
<p><a id="wn834_34963"></a>
   의견을 받고 있는 제안은 아래와 같습니다.</p>
<ul>
<li>
<p>외국어 이름 및 외래어 명칭을 나타내기 위해 <code>int_name</code>을 쓰지 말자는 <a href="https://wiki.openstreetmap.org/wiki/Proposal:Restrict_%22int_name%22_for_exonyms_in_place_names">제안</a>. 지금까지 <code>int_name</code> 태그는 로마자 표기법 혹은 외래어 명칭을 나타내는 데 일관성 없이 사용되어 왔으며, 표준인 <code>name:&lt;언어&gt;</code> 패턴을 따르지 않기 때문입니다.</p>
</li>
<li>
<p><code>addr:*</code> 이름공간을 번호를 매긴 <code>addr:2:*</code> 구문으로 확장해 동일한 개체에 여러 주소를 직접 붙일 수 있도록 하자는 <a href="https://wiki.openstreetmap.org/wiki/Proposal:Alternate_addresses">제안</a>. 이로써 렌더링 및 역지오코딩에 사용되는 필수 주소를 붙일 수 있게 됩니다.</p>
</li>
</ul>
</li>
</ul>
<h2 id="커뮤니티">커뮤니티</h2>
<ul>
<li>
<p><a id="wn834_34971"></a>
   jellyfish_umbrella가 무인 매장에 어떤 태그를 붙이는 것이 좋은지 마스토돈에서 <a href="https://tech.lgbt/@jellyfish_umbrella/116891535801450143">물어보았습니다</a>.</p>
</li>
<li>
<p><a id="wn834_34983"></a>
   Bluestarfish가 2016년 7월 19일 런던에서 열린 맵스와이프(MapSwipe) 출시 파티를 되돌아보면서, 맵스와이프 출범 10주년을 <a href="https://www.openstreetmap.org/user/bluestarfish/diary/409036">기념했습니다</a>.</p>
</li>
<li>
<p><a id="wn834_34982"></a>
   영국에서 공공 통행권(Public Rights of Way)이 인정되는 경로를 보여주는 앱을 개발하고 있는 Chris Debian이 Robert Whittaker의 ‘UK Public Rights of Way’ <a href="https://osm.mathmos.net/prow/">태그 교정 도구</a>를 발견했습니다. Chris는 이를 바탕으로 수정된 항목을 수동으로 일괄 검증하고, 마지막으로 공공데이터를 확인한 시점 이후로부터 어떤 지자체에서 추가로 조용히 데이터를 공개했는지 검토하는 프로그램을 <a href="https://www.openstreetmap.org/user/chris_debian/diary/409034">개발했습니다</a>.</p>
</li>
<li>
<p><a id="wn834_34976"></a>
   Anne-Karoline Distel이 Bing Streetside, 매필러리(Mapillary), 파노라맥스(Panoramax)에 올라온 거리 사진을 활용해 지도 데이터를 개선하는 방법을 설명하는 동영상을 <a href="https://www.youtube.com/watch?v=uP5_sV05-WI">올렸습니다</a>. 상점 간판, 교통 표지판, 도로 표지, 인도, 자전거 도로, 집 번호, 벤치와 같이 항공 사진만으로는 식별하기 어렵거나 불가능한 지형 요소를 오픈스트리트맵에 추가할 때, 거리 사진을 참고 자료로 활용하는 방법 위주로 설명되어 있습니다.</p>
</li>
<li>
<p><a id="wn834_35004"></a>
   <a href="https://social.spejset.org/@ejnro/116896013991757416">Einar</a>가 6월 말 베네수엘라에서 발생한 지진 이후, 오픈스트리트맵을 활용한 인도주의적 지도 제작 활동에 참여한 경험을 담은 글을 <a href="https://faanes.se/blogg/2026/carabelleda/">썼습니다</a>(노르웨이어).</p>
</li>
<li>
<p><a id="wn834_34999"></a>
   Raquel Dezidério Souto가 IVIDES DATA에서 2026년도 제5차 오픈스트리트맵 워크숍을 주최하고, 전자책 <a href="https://zenodo.org/records/21263723/preview/manual_uMap_pt_2026_EN.pdf">『uMap을 활용한 웹 지도 제작을 위한 간단한 안내서』</a>를 발간했다고 <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/409052">발표했습니다</a>.</p>
</li>
<li>
<p><a id="wn834_34966"></a>
   Rphyrin이 약 8년 전, 오픈스트리트맵 편집을 막 시작하던 시절에 자신이 직접 그린 지도 스케치를 우연히 <a href="https://www.openstreetmap.org/user/rphyrin/diary/409025">발견했습니다</a>.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-재단">오픈스트리트맵 재단</h2>
<ul>
<li><a id="wn834_34973"></a>
   오픈스트리트맵 재단에서 오픈스트리트맵과 관련된 유럽 연합 자금 지원 프로젝트 제안서를 작성해 제출하기 전에 재단과 조기에 협의할 것을 <a href="https://blog.openstreetmap.org/2026/07/10/openstreetmap-foundation-and-european-projects-an-invitation-to-collaborate/">요청했습니다</a>. 오픈스트리트맵 재단은 디지털 공공재 및 디지털 주권 분야에서 전략적 파트너로서, 개방형 인프라 거버넌스와 커뮤니티 주도 모델에 대한 경험을 제공할 수 있으나, 서비스 제공자나 실질적인 운영 주체는 아닙니다. 또한 재단에서는 라이선스 호환성(ODbL vs. CC-BY)과 같이 기획 단계에서 해결해야 할 실질적인 사항들과 재단의 지속 가능성을 위한 재정적 기여를 포함해 각 프로젝트가 오픈스트리트맵 생태계에 어떻게 기여할 수 있는지에 대해서도 언급했습니다.</li>
</ul>
<h2 id="행사">행사</h2>
<ul>
<li><a id="wn834_35010"></a>
   Katja Haferkorn이 FOSS4G Europe 2026이 6월 29일부터 7월 5일까지 루마니아 티미쇼아라에서 성공적으로 개최되었다고 <a href="https://www.fossgis.de/news/2026_07_15_foss4geurope-2026_bericht-katja/">보도했습니다</a>. FOSS4G 2026은 &lsquo;지리공간 기술과 인류의 가교&rsquo;라는 주제로 8월 30일부터 9월 5일까지 일본 히로시마에서 열릴 예정입니다. FOSS4G 2027은 영국 브리스톨에서 개최하는 것으로 결정되었습니다. <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



</li>
</ul>
<h2 id="지도">지도</h2>
<ul>
<li>
<p><a id="wn834_34990"></a>
   <a href="https://thecastlemap.com/">성 지도(The Castle Map)</a>는 전 세계의 성과 요새를 보여주는 지도입니다. 해당 지도는 OpenFreeMap에서 제공하는 오픈스트리트맵 벡터 타일과 위키데이터의 랜드마크 데이터를 활용해 전 세계 2,400곳 이상의 성, 요새, 궁전의 위치를 보여줍니다.</p>
</li>
<li>
<p><a id="wn834_34995"></a>
   Chris Whong이 <a href="https://nycneighborhoods.app/map#8.86/40.7012/-73.9979">NYC Neighbourhoods 지도</a>의 웹 버전을 <a href="https://www.linkedin.com/posts/chris-whong-798b587_nyc-neighborhoods-interactive-map-of-every-activity-7472398260599447552-SFVN">공개했습니다</a>. 뉴욕 5개 자치구(borough)에 속한 neighbourhood 300개를 한눈에 볼 수 있으며, 화면을 확대하면 각 지역의 지리적 특징을 알아볼 수 있습니다.</p>
</li>
<li>
<p><a id="wn834_35002"></a>
   geoObserver에서 mapki.com에 게시된 전/후 비교 지도, <a href="https://beforeafter.mapki.com/">&lsquo;OSM-Zeitreise&rsquo;</a>를 <a href="https://mastodon.social/@geoObserver/116911468104246426">언급했습니다</a>. OSM-Zeitreise는 Ian Dees가 Amanda McCann의 osm-mapping-party-before-after를 <a href="https://github.com/iandees/osm-mapping-party-before-after">포크해</a> 만든 것을 기반으로 합니다.</p>
</li>
<li>
<p><a id="wn834_34977"></a>
   Alyosha85가 MapLibre GL을 사용해 싱가포르 전역의 모든 놀이터를 표시하는 웹 지도, ‘PlaySG’를 <a href="https://www.openstreetmap.org/user/Alyosha85/diary/409030">제작했습니다</a>. PlaySG는 Overpass API를 통해 최신 오픈스트리트맵 데이터를 조회하며, 매주 자동으로 갱신됩니다.</p>
</li>
<li>
<p><a id="wn834_34993"></a>
   Peter Brodersen이 남성의 이름을 딴 도로를 특별히 피할 수 있는 경로 탐색기를 <a href="https://mastodon.cloud/@brodersen/116188764643886414">개발했습니다</a>. 도로 데이터는 파리 지역의 오픈스트리트맵 데이터를 가져왔으며, <code>name:etymology:wikidata</code>(어원) 태그가 붙은 모든 도로를 해당 위키데이터 항목과 대조해 성별이 명시되어 있는지 확인합니다. 이후 남성의 이름을 딴 도로를 우회하도록 사용자 정의 OSRM 경로 설정 프로필이 생성됩니다.</p>
</li>
<li>
<p><a id="wn834_35001"></a>
   <a href="https://trainrouter.com/">TrainRouter</a>는 전 세계 767개의 주요 여객 열차 노선을 담은 동적 지도집으로, 오픈스트리트맵 기반의 OpenFreeMap 벡터 타일로 구현되었습니다. TrainRouter의 기반이 되는 철도 데이터 집합은 CC BY 4.0 라이선스로 배포 중입니다.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-활용-사례">오픈스트리트맵 활용 사례</h2>
<ul>
<li>
<p><a id="wn834_34988"></a>
   ^[1]^ UPLB Tools에서 필리핀 대학교 로스 바뇨스(University of the Philippines Los Baños)의 학생들이 강의실을 찾거나 캠퍼스를 돌아다닐 때 쓸 수 있는 웹 지도 RoomTBA를 <a href="https://github.com/uplbtools/room-tba">개발했습니다</a>.</p>
</li>
<li>
<p><a id="wn834_34989"></a>
   <a href="https://radatlas.at/">Radatlas</a>는 명칭이 붙은 오스트리아의 자전거 도로 노선을 수록한 무료 지도집으로, 독일어와 영어를 지원합니다. 오픈스트리트맵의 경로 데이터와 오스트리아 정부에서 배포하는 디지털 고도 모델을 기반으로 제작되었으며, 각 자전거 도로 노선에 대해 상호작용이 가능한 MapLibre 지도, 고도 프로필, GPX/TCX 파일 다운로드 기능을 제공합니다.</p>
</li>
</ul>
<h2 id="열린-데이터">열린 데이터</h2>
<ul>
<li>
<p><a id="wn834_34987"></a>
   Pieter Vander Vennet이 네덜란드 안트베르펜(Antwerpen)주 교통국에서 카고 바이크에 고프로 카메라를 장착해 벨기에의 자전거 도로 사진을 수집하고, 촬영된 사진을 매필러리와 파노라맥스 양쪽에 업로드했다고 <a href="https://www.openstreetmap.org/user/Pieter%20Vander%20Vennet/diary/409031">밝혔습니다</a>.</p>
</li>
<li>
<p><a id="wn834_34985"></a>
   PizzaTreeIsland가 오픈스트리트맵의 도로명 어원 데이터와 EloEverything의 Elo 랭킹을 결합한 지도를 <a href="https://pizzatreeisland.github.io/Streetnames-by-Elo/">공개했습니다</a>. EloEverything은 한 번에 두 가지 개념을 비교해 수천 가지 다양한 대상에 대한 순위를 산출하는 프로젝트입니다. 소스 코드는 <a href="https://github.com/PizzaTreeIsland/Streetnames-by-Elo">깃허브</a>에서 확인할 수 있습니다.</p>
</li>
</ul>
<h2 id="소프트웨어">소프트웨어</h2>
<ul>
<li>
<p><a id="wn834_34992"></a>
   RoomTBA 캠퍼스 지도에서 영감을 받은 rtnF가 오픈스트리트맵의 건물 높이 데이터를 기반으로 사용자 정의가 가능하고 자체 호스팅 가능한 3D 캠퍼스 지도를 구축하는 HTML 스크립트를 <a href="https://rtnf.substack.com/p/missionmap">짰습니다</a>.</p>
</li>
<li>
<p><a id="wn834_34972"></a>
   <a href="https://www.openstreetmap.org/user/seav">Eugene Alvin Villar</a>가 2025년 7월 3일 출시된 CoMaps의 지난 1년을 되돌아보면서, 추적기나 광고가 전혀 없는 오픈스트리트맵 데이터 기반의 &lsquo;개인정보 보호 우선&rsquo; 오프라인 내비게이션 앱으로서 CoMaps의 강점을 <a href="https://technology.inquirer.net/147812/comaps-and-the-right-to-fork">어필했습니다</a>. Eugene은 초기 MapsWithMe에서 시작해 Maps.me와 Organic Maps를 거쳐 CoMaps까지 오게 된 과정을 설명하면서, 각 포크는 상업화와 거버넌스에 대해 커뮤니티에서 우려를 제기함에 따라 발생하게 되었다고 말했습니다. 그러면서 CoMaps의 명확한 비영리 사명과 오픈소스 라이선스가 결합된 점으로부터 알 수 있듯이 포크(fork)의 권리를 통해 프로젝트가 특정 기업에 의해 좌지우지당하는 것을 막을 수 있다고 역설했습니다.</p>
</li>
<li>
<p><a id="wn834_34978"></a>
   오픈스트리트맵 재단의 상표 정책을 준수하기 위해 OpenCourseMaps에서 이름을 바꾼 FairwayMapper가 오픈스트리트맵에 상세한 골프 코스 데이터를 기여할 수 있도록 특별히 설계된 웹 편집기를 <a href="https://www.fairwaymapper.com">선보였습니다</a>. FairwayMapper는 오픈스트리트맵 기여자만 이용할 수 있는 Overpass 인스턴스도 제공하고 있습니다. FairwayMapper는 지난 7월 10일에 출시된 따끈따끈한 서비스입니다.</p>
</li>
<li>
<p><a id="wn834_34996"></a>
   Diego Camargo가 <a href="https://github.com/d-camargo/gisbr">GISBR 0.3.2</a> QGIS 플러그인을 통해 Overpass API에 질의문을 보내고, 선택한 지자체의 도로 데이터를 다운로드하며, 최소한의 위상학적 구조를 가진 두 개의 레이어(연결 고리(도로 조각)와 마디(도로 조각을 연결하는 접점))를 생성할 수 있게 되었다고 <a href="https://www.dcamargo.com.br/2026/07/06/gisbr-0-3-2-osm-fim-experimental.html">발표했습니다</a>. 해당 데이터는 교통 네트워크 모델링에 유용하게 활용할 수 있습니다. <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/09/pt-br.svg"
      
      
    />

  </picture>
</figure>



</p>
</li>
<li>
<p><a id="wn834_34998"></a>
   지도 생태계의 오픈소스 프로젝트를 소개하는 글을 연재하고 있는 Geocode Earth에서 이번에는 지도 데이터를 PMTiles 파일로 패키징해 일반 웹 저장소에 호스팅할 수 있는 ‘Protomaps’를 <a href="https://geocode.earth/blog/2026/protomaps-a-map-you-can-actually-own/">소개했습니다</a>.</p>
</li>
<li>
<p><a id="wn834_34974"></a>
   iD 태그 스키마 v6.19.0이 <a href="https://github.com/openstreetmap/id-tagging-schema/releases/tag/v6.19.0">출시되었습니다</a>. 이번 업데이트에서는 프랑스의 <code>maxweightrating</code>(최대 적재 중량 기준 접근 제한 표지) 지원 추가, 사전 설정 추가(<code>boundary=protected_area</code>, <code>amenity=traffic_park</code> 등 5개), 버그 수정, 기존 필드 조정, 새로운 값(<code>cuisine=austrian</code> 등) 추가, Roentgen 0.16.0에 추가된 아이콘 반영 등이 이루어졌습니다. 또한 이 기사가 올라가는 시점을 기준으로 사소한 변경 사항이 두 가지 <a href="https://github.com/openstreetmap/id-tagging-schema/releases">추가되었습니다</a>. iD 태그 스키마의 최신 버전은 v.7.0.1입니다.</p>
</li>
<li>
<p><a id="wn834_34980"></a>
   Abdullah가 사우디아라비아의 예배 장소 데이터의 지리적 분포, 점 밀도, 시설이 미비한 지역을 시각화할 수 있는 대시보드를 <a href="https://abdullah201x.github.io/sa-places-of-worship">만들었습니다</a>. <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/09/ar.svg"
      
      
    />

  </picture>
</figure>



</p>
</li>
</ul>
<h2 id="프로그래밍">프로그래밍</h2>
<ul>
<li>
<p><a id="wn834_34981"></a>
   구글 서머 오브 코드를 통해 노미나팀(Nominatim)에 범주 기능을 구현하고 있는 Agasta07이 중간 보고서를 <a href="https://www.openstreetmap.org/user/Agasta07/diary/409035">발표했습니다</a>.</p>
</li>
<li>
<p><a id="wn834_35003"></a>
   OSRM의 개발자 Egor Kotov가 OSRM 백엔드 v.0.4가 이제 자체 저장소를 <a href="https://www.ekotov.pro/osrm.backend/index.html">사용하며</a>, 이 저장소에는 독립적으로 실행 가능하고(필요한 모든 라이브러리가 포함되어 있음) 변경 불가능한 형태로 패키징된 OSRM 바이너리가 포함되어 있다고 <a href="https://datasci.social/@EgorKotov/116902638811394344">밝혔습니다</a>. 자세한 내용은 <a href="https://www.ekotov.pro/osrm.backend/articles/binary-providers.html">이 글</a>을 참고하세요.</p>
</li>
</ul>
<h2 id="출시">출시</h2>
<ul>
<li>
<p><a id="wn834_34984"></a>
   Freemap Europe에서 최근 위치 태그가 붙은 위키미디어 공용 사진을 메인 &lsquo;사진&rsquo; 레이어에 통합했다고 <a href="https://en.osm.town/@FreemapSlovakia/116912307723009689">발표했습니다</a>. 이로써 위키미디어 공용과 Freemap 커뮤니티 양쪽에서 위치 태그가 붙은 사진을 더 많이 찾아볼 수 있게 되었습니다.</p>
</li>
<li>
<p><a id="wn834_34994"></a>
   GeoDesk에서 GOL Tool 2.3 업데이트를 <a href="https://www.geodesk.com/2026/07/13/gol-2-3-released">공개했습니다</a>. 이번 업데이트로 질의 결과를 OSM-PBF 형식으로 내보내는 기능이 추가되었습니다.</p>
</li>
</ul>
<h2 id="알고-계셨나요">알고 계셨나요?</h2>
<ul>
<li><a id="wn834_34927"></a>
   장소, 날짜, 시간을 맞추면 실제로 산, 건물, 나무가 드리우는 그림자를 시각화해 주는 시뮬레이터, <a href="https://shademap.app">ShadeMap</a>을 알고 계셨나요? ShadeMap은 오픈스트리트맵의 건물 높이 데이터, Mapterhorn의 전 세계 지형 데이터, 그리고 메타와 세계자원연구소(2026)에서 제공한 수관(樹冠, tree canopy) 데이터를 활용해 실시간으로 그림자의 위치를 계산합니다.</li>
</ul>
<h2 id="매체-속-오픈스트리트맵">매체 속 오픈스트리트맵</h2>
<ul>
<li><a id="wn834_34975"></a>
   Corentin Bechade가 구글 지도의 실용적인 대안을 결국 찾지 못했다고 말했습니다. Corentin은 <a href="https://cartes.app/">cartes.app</a>의 창립자인 Maël Thomas-Quillévéré와 대화를 나누면서, 구글 지도가 어떻게 이처럼 압도적인 시장 지배력을 확보하게 되었는지 <a href="https://www.lesnumeriques.com/societe-numerique/l-impossible-quete-pour-une-alternative-souveraine-et-privee-a-google-maps-a259052.html">설명했습니다</a>. <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



</li>
</ul>
<h2 id="기타-지리-관련-소식">기타 &lsquo;지리&rsquo; 관련 소식</h2>
<ul>
<li>
<p><a id="wn834_34997"></a>
   <a href="https://github.com/Nasef2017/Bathymetrix-AI">Bathymetrix-AI</a>는 Nasef M Aly가 개발하는 고급 QGIS 플러그인으로, 보정된 다중 스펙트럼 위성 영상(Sentinel-2 Level-2A 등)으로부터 고정밀 위성 기반 수심 측정(SDB) 데이터를 도출하기 위한 연구 도구 모음을 <a href="https://plugins.qgis.org/plugins/Bathymetrix_AI">제공합니다</a>. Bathymetrix-AI는 물리학 기반의 영상 처리 기술과 최신 기계 학습 기술을 결합해 수심 측량 정확도를 향상시키는 동시에, 기존 SDB 방법의 여러 한계를 해결합니다.</p>
</li>
<li>
<p><a id="wn834_35000"></a>
   세계자원연구소에서 위성 사진을 바탕으로 남미 지역의 농지 경계를 자동으로 추출하고, 이를 또 다른 지역에 확장 적용할 수 있는 프레임워크인 Trazo를 <a href="https://wri.github.io/trazo/landing/">설명하는</a> 기술 보고서를 <a href="https://www.wri.org/research/field-boundaries-south-america">발간했습니다</a>. 해당 보고서에는 기술적 기초부터 2023~24년 파종기에 수집한 농경지 1,090만 곳의 정보가 담긴 데이터 집합이 포함되어 있으며, CC-BY-4.0 라이선스로 이용할 수 있습니다. 해당 데이터를 사용하려면 기술 노트와 특정 연도의 전 세계 농경지 경계에 대한 예측 정보를 <a href="https://fieldsofthe.world/ftw-inference-app/#map=2.00/0.0000/0.0000/mode:global/threshold:70/year:2025/opacity:90/downloads:0">제공</a>하는 <a href="https://github.com/fieldsoftheworld">‘Fields of the World’</a> 인용해야 합니다. 해당 데이터는 Trazo용 동적 지도에서도 <a href="https://wri.github.io/trazo/landing/map.html">이용할 수 있습니다</a>.</p>
</li>
<li>
<p><a id="wn834_35018"></a>
   어린 시절부터 지도를 접하는 것은 케냐만의 문제가 아니라 전 세계적인 과제입니다. 대부분의 교육과정은 흥미로운 지도 활동을 너무 늦게 도입하기 때문에, 대다수의 학생들이 필수적인 공간적 사고 능력을 갖추지 못한 채 성장하고 있습니다. GeoMind Solutions가 <a href="https://geomindsolutions.co.ke/resources.html">운영하는</a> &lsquo;지도와 함께하는 재미있는 지도 제작(Cartography Fun with Maps)&rsquo; 프로그램은 상호작용형 지도 제작 활동을 조기에 도입함으로써 이러한 격차를 해소합니다. 유튜브에 올라온 <a href="https://youtu.be/daOVYBYGtLc">&lsquo;지도와 관련된 여러분의 이야기는 무엇인가요?(What’s your map story?)&rsquo;</a>라는 영상에서는 케냐의 Catherine Njore가 집필하고 Intercen Books에서 <a href="https://intercenbooks.co.ke/content/b9d29d3b-e136-4e3e-811e-f12a81163767">출간한</a> &lsquo;Mappy Maria&rsquo; 시리즈와 같은 교육 자료를 소개하고 있습니다. 책 구매를 통해 이 프로젝트를 후원하고 싶으신 분께서는 저자에게 <a href="https://geomindsolutions.co.ke/index.html#contact">문의해 주시기 바랍니다</a>.</p>
</li>
<li>
<p><a id="wn834_34979"></a>
   가디언지에서 나이언틱 스페이셜(Niantic Spatial)이 일부 군대에서 사용하는 드론을 포함한 드론용 공간 탐지 소프트웨어 전문 기업인 밴토르(Vantor)와 협력 관계를 맺은 데 이어, 포켓몬 고의 데이터가 전쟁 지역에서 군용 드론을 지원할 수 있는 인공지능을 훈련하는 데 사용되었을 가능성이 있다고 <a href="https://www.theguardian.com/technology/2026/jun/12/pokemon-go-data-trained-ai-that-could-assist-military-drones-in-war-zones">보도했습니다</a>.</p>
</li>
<li>
<p><a id="wn834_34991"></a>
   Caleb Robinson과 Isaac Corley가 센티넬 2호로 촬영한 모든 위성 사진을 지리적 위치 정보가 포함된 실제 지구 표면의 다채로운 패치들로 구성된 모자이크 형태로 재구성해 보여주는 브라우저 앱, Sentinel-2 Paint를 <a href="https://geospatialml.com/posts/sentinel2-paint/">개발했습니다</a>.</p>
</li>
</ul>
<h2 id="다가오는-행사">다가오는 행사</h2>
<table>
	<thead>
			<tr>
					<th>국가</th>
					<th>장소</th>
					<th>행사장</th>
					<th>명칭</th>
					<th>일시</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>MapCup Asia Pacific 2026 <a href="https://osmcal.org/event/4911/">:osmcalpic:</a></td>
					<td>2026-07-01 - 2026-07-31</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/10/ci.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Abidjan</td>
					<td>cURAT</td>
					<td>MAPATHON TIEBISSOU <a href="https://osmcal.org/event/4970/">:osmcalpic:</a></td>
					<td>2026-07-12 - 2026-07-24</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mid-Month (Without Training) Advanced Mappers (Online) [eng] <a href="https://osmcal.org/event/4247/">:osmcalpic:</a></td>
					<td>2026-07-21</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Chemnitz</td>
					<td>Kaffeesatz, Chemnitz</td>
					<td>OSM-Stammtisch Chemnitz <a href="https://osmcal.org/event/4660/">:osmcalpic:</a></td>
					<td>2026-07-21</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bonn</td>
					<td>Dotty&rsquo;s</td>
					<td>202. OSM-Stammtisch Bonn <a href="https://osmcal.org/event/4358/">:osmcalpic:</a></td>
					<td>2026-07-21</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Derby</td>
					<td>The Brunswick, Railway Terrace, Derby</td>
					<td>East Midlands pub meet-up <a href="https://osmcal.org/event/4801/">:osmcalpic:</a></td>
					<td>2026-07-21</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>City of Edinburgh</td>
					<td>Guildford Arms, Edinburgh</td>
					<td>Edinburgh Meetup <a href="https://osmcal.org/event/4933/">:osmcalpic:</a></td>
					<td>2026-07-21</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Online</td>
					<td>Lüneburger Mappertreffen (online) <a href="https://osmcal.org/event/4373/">:osmcalpic:</a></td>
					<td>2026-07-21</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSMF Engineering Working Group meeting <a href="https://osmcal.org/event/4978/">:osmcalpic:</a></td>
					<td>2026-07-24</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2024/08/ge.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Online</td>
					<td>Racha Mapping Party <a href="https://osmcal.org/event/4985/">:osmcalpic:</a></td>
					<td>2026-07-27 - 2026-08-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum 0</td>
					<td>Braunschweiger Mappertreffen im Stratum 0 Hackerspace <a href="https://osmcal.org/event/4990/">:osmcalpic:</a></td>
					<td>2026-07-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>Online</td>
					<td>OSM-Verkehrswende #77 <a href="https://osmcal.org/event/4909/">:osmcalpic:</a></td>
					<td>2026-07-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Mannheim</td>
					<td>RaumZeitLabor, Mannheim</td>
					<td>Rhein-Neckar OSM Treffen <a href="https://osmcal.org/event/4979/">:osmcalpic:</a></td>
					<td>2026-07-29</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Düsseldorf</td>
					<td>Online bei <a href="https://meet.jit.si/OSM-DUS-2026">https://meet.jit.si/OSM-DUS-2026</a></td>
					<td>Düsseldorfer OpenStreetMap-Treffen (online) <a href="https://osmcal.org/event/4387/">:osmcalpic:</a></td>
					<td>2026-07-29</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>UN Mappers Community Discussion: Community Chapters Initiative <a href="https://osmcal.org/event/4971/">:osmcalpic:</a></td>
					<td>2026-07-31</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hannover</td>
					<td>Endhaltestelle Roderbruch der Stadtbahnlinie 4</td>
					<td>Mapping Party <a href="https://osmcal.org/event/4927/">:osmcalpic:</a></td>
					<td>2026-07-31</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>नई दिल्ली</td>
					<td>Jitsi Meet (online)</td>
					<td>OSM India - Monthly Online Mapathon <a href="https://osmcal.org/event/4887/">:osmcalpic:</a></td>
					<td>2026-08-01</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/08/se.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Uppsala</td>
					<td>Datorföreningen Update</td>
					<td>Kartträff i Uppsala. Tema Cykelinfrastruktur <a href="https://osmcal.org/event/4988/">:osmcalpic:</a></td>
					<td>2026-08-02</td>
			</tr>
	</tbody>
</table>
<p><em>이 주간OSM은 다음 사람들이 <a href="https://umap.openstreetmap.fr/de/map/weeklyosm-is-currently-produced-in_56718#2/8.4/108.3">제작했습니다</a>. <a href="https://www.openstreetmap.org/user/LuxuryCoop">LuxuryCoop</a>, <a href="https://www.openstreetmap.org/user/MatthiasMatthias">MatthiasMatthias</a>, <a href="https://ivides.org/raquel-deziderio">Raquel Dezidério Souto</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, Andrew Davidson, <a href="https://www.openstreetmap.org/user/derFred">derFred</a>.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>주간 OSM 831</title>
				<link>https://hugo.weeklyosm.eu/ko/archives/0831/</link>
				<pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/archives/0831/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/06/831.webp" alt="주간 OSM 831" /> 2026.06.18.-2026.06.24.
주간OSM 내부 소식 [1] 주간OSM에 접속하실 때 브라우저 검사가 잠깐 뜨더라도 놀라지 마세요. 주간OSM 웹 사이트는 현재 AI 스크래퍼 때문에 큰 부담을 겪고 있으며, 이러한 스크래퍼를 막기 위해 Anubis를 가동하기 시작했습니다.
커뮤니티 UN Mappers Chapters Initiative의 일환으로 Modo Levo Engelbert Steve가 홍보대사 자격을 맡아 아프리카의 청년들이 지역 문제를 해결하면서 오픈스트리트맵 데이터도 개선하는 CityMapper Externship 프로젝트를 이끌고 있습니다. Modo는 프로젝트의 경과를 보고하면서 IVIDES DATA, GeOsm Family, Geospatial Girls &amp; Kids, 인도주의 오픈스트리트맵 팀(HOT), 톰톰(TomTom)과 같은 파트너들의 귀중한 도움이 없었다면 이 프로젝트는 결코 진행될 수 없었을 것이라고 전했습니다. Séverin Ménard는 이 일이 몇 년 전 시작된 이야기에서 비롯됐다고 마스토돈에서 회고했습니다.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/06/831.webp" alt="주간 OSM 831" /></p> <p>2026.06.18.-2026.06.24.</p>
<h2 id="주간osm-내부-소식">주간OSM 내부 소식</h2>
<ul>
<li><a id="wn831_34877"></a>
   [1] 주간OSM에 접속하실 때 브라우저 검사가 잠깐 뜨더라도 놀라지 마세요.</li>
</ul>
<p>주간OSM 웹 사이트는 현재 AI <a href="https://en.wikipedia.org/wiki/Web_scraping">스크래퍼</a> 때문에 큰 부담을 겪고 있으며, 이러한 스크래퍼를 막기 위해 Anubis를 가동하기 시작했습니다.</p>
<h2 id="커뮤니티">커뮤니티</h2>
<ul>
<li>
<p><a id="wn831_34856"></a>
   UN Mappers Chapters Initiative의 일환으로 Modo Levo Engelbert Steve가 홍보대사 자격을 맡아 아프리카의 청년들이 지역 문제를 해결하면서 오픈스트리트맵 데이터도 개선하는 CityMapper Externship 프로젝트를 <a href="https://www.openstreetmap.org/user/ENGELBERT%20MODO/diary/408919">이끌고 있습니다</a>. Modo는 프로젝트의 경과를 보고하면서 IVIDES DATA, GeOsm Family, Geospatial Girls &amp; Kids, 인도주의 오픈스트리트맵 팀(HOT), 톰톰(TomTom)과 같은 파트너들의 귀중한 도움이 없었다면 이 프로젝트는 결코 진행될 수 없었을 것이라고 전했습니다. Séverin Ménard는 이 일이 몇 년 전 시작된 이야기에서 비롯됐다고 마스토돈에서 <a href="https://mastodon.social/@SeverinGeo/116790299304417902">회고했습니다</a>.</p>
</li>
<li>
<p><a id="wn831_34848"></a>
   Paul Norman이 오픈스트리트맵에 대량으로 잘못 들여온 데이터를 되돌리는 과정에서 복제물 생성 지연이 발생해 수많은 서비스에 영향이 가는 중이라고 <a href="https://www.openstreetmap.org/user/pnorman/diary/408895">공지했습니다</a>.</p>
</li>
<li>
<p><a id="wn831_34855"></a>
   StephanT가 &ldquo;독일연방공화국과 체코 공화국 사이의 공동 국경에 관한 조약&quot;의 <a href="https://www.bundesrat.de/drs.html?id=99-26">독일연방공화국 판본</a>과 <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



 <a href="https://www.psp.cz/sqw/text/tiskt.sqw?o=10&amp;ct=185&amp;ct1=0">체코 공화국 판본</a>을 <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2020/08/cz-black.svg"
      
      
    />

  </picture>
</figure>



 비교해 두 판본 간의 비일관성, 불일치, 오류를 오픈스트리트맵 커뮤니티 포럼에 자세히 <a href="https://community.openstreetmap.org/t/vertrag-zwischen-der-bundesrepublik-deutschland-und-der-tschechischen-republik-uber-die-gemeinsame-staatsgrenze/144595/35">문서화했습니다</a>.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-재단">오픈스트리트맵 재단</h2>
<ul>
<li><a id="wn831_34853"></a>
   오픈스트리트맵 재단 이사회가 앞으로 12개월 동안 다룰 안건의 우선순위 선정과 구체적인 실행 항목을 정하는 워크숍을 6월 6일부터 7일까지 톰톰 마드리드 사무실에서 <a href="https://blog.openstreetmap.org/2026/06/19/2026-board-face-to-face-f2f-in-madrid-spain/">진행했습니다</a>.</li>
</ul>
<h2 id="행사">행사</h2>
<ul>
<li>
<p><a id="wn831_34862"></a>
   State of the Map 2026의 <a href="https://2026.stateofthemap.org/programme/">식순</a>이 공개되었습니다. State of the Map 2026은 8월 28일 금요일 개회식으로 시작해 Adrien Pavie와 Christian Quest의 특별 기조연설 &ldquo;State of Panoramax&quot;가 이어집니다. 자세한 내용은 <a href="https://en.osm.town/@sotm/116799800434591478">마스토돈</a>을 참고하세요.</p>
</li>
<li>
<p><a id="wn831_34861"></a>
   Canadian Open Data Summit이 10월 14~16일에 캐나다 온타리오주 윈저에서 <a href="https://opendatasummit.ca/program/">열립니다</a>. 단체/개인 관계없이 영어나 프랑스어로 워크숍, 패널, 라이트닝 토크, 발표를 <a href="https://docs.google.com/forms/d/e/1FAIpQLSdIJCAkMIVWwwaAFaMu8jdAj2u3FboC3RmZhDt9Zn0BvYxwfQ/viewform">신청할 수 있습니다</a>.</p>
</li>
</ul>
<h2 id="교육">교육</h2>
<ul>
<li><a id="wn831_34854"></a>
   IVIDES DATA에서 진행하는 2026 OSM Workshop Series가 <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408904">3회차를 맞았습니다</a>. 이번 워크숍의 주제는 오픈스트리트맵 데이터용 QGIS 플러그인으로, 여러 가지 사례 연구(접근성, 도시 수목 피복, 산사태 재해 취약 지역 인근 건물 위치 식별)를 보여주는 데 의의가 있었습니다.</li>
</ul>
<h2 id="지도">지도</h2>
<ul>
<li><a id="wn831_34868"></a>
   Żaneta Piasecka가 2026 FIFA 월드컵과 관련된 <a href="https://piaseckazaneta.github.io/world-cup-map/">동적 지도</a>(경기장의 정확한 위치, 경기장까지 얼마나 이동하기 쉬운지, 경기장이 도심에 있는지 교외에 있는지 등)를 만들어 링크드인에 <a href="https://www.linkedin.com/posts/%C5%BCanetapiasecka_gis-python-folium-share-7475519258328952833-TPpX/">올렸습니다</a>.</li>
</ul>
<h2 id="오픈스트리트맵-활용-사례">오픈스트리트맵 활용 사례</h2>
<ul>
<li>
<p><a id="wn831_34865"></a>
   velowire.com에서 오픈스트리트맵에 정밀하게 그려 둔 여러 사이클 경주 코스를 손쉽게 다운로드할 수 있도록 <a href="https://www.velowire.com/blogcat/35/en/openstreetmap-google-earth.html">공개하고 있습니다</a>. .KML 파일로 경로를 다운로드해 구글 어스, iD 편집기, <a href="https://apps.gnome.org/en/Maps/">그놈 지도</a>를 비롯해 KML 포맷을 지원하는 소프트웨어에서 열어볼 수 있습니다.</p>
</li>
<li>
<p><a id="wn831_34847"></a>
   호텔 관리 소프트웨어 플랫폼 <a href="https://www.powerpro.id/">Power Pro</a>에서 호텔 관리자들이 제출한 지원 티켓 위치를 추적하는 데 오픈스트리트맵 데이터를 <a href="https://mastodon.social/@rphyrin/116776264926385444">활용하고 있습니다</a>. 이를 통해 유지보수 및 서비스 요청을 더 효율적으로 모니터링하고 조율할 수 있습니다.</p>
</li>
</ul>
<h2 id="소프트웨어">소프트웨어</h2>
<ul>
<li>
<p><a id="wn831_34859"></a>
   GeoServer 3.0이 <a href="https://mappinggis.com/2026/06/geoserver-3-0-la-mayor-modernizacion-de-la-plataforma-en-anos/">나왔습니다</a>. Mapping GIS 블로그에 글을 쓴 Aurelio Morales에 따르면, 이번 버전은 대대적인 현대화를 앞세우고 있습니다. <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/es.svg"
      
      
    />

  </picture>
</figure>



</p>
</li>
<li>
<p><a id="wn831_34851"></a>
   카오스 컴퓨터 클럽 <a href="https://fahrplan.do-byte.de/do-byte-2026/">DO_BYTE</a> 2026 행사에서 Marc가 파노라맥스(Panoramax) 프로젝트를 소개하면서, 파노라맥스 인스턴스를 일상적으로 운영하면서 느낀 점과 360도 사진을 찍는 실용적인 방법을 <a href="https://media.ccc.de/v/do-byte-2026-17-panoramax-streetview-selber-hosten">공유했습니다</a>. <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/de.svg"
      
      
    />

  </picture>
</figure>



</p>
</li>
<li>
<p><a id="wn831_34860"></a>
   Ian Wagner가 위치 인식 애플리케이션을 만드는 일이 흔히 &ldquo;사용자가 가야 할 곳을 찾도록 돕는다&quot;는 단순한 목표에서 시작된다고 Stadia Maps 블로그에 <a href="https://stadiamaps.com/blog/precision-meets-privacy-consumer-search-experience/">기고했습니다</a>. Ian은 현재 지오코딩 환경에 남아 있는 빈틈을 조명하면서, 보다 신뢰할 수 있는 경로를 Stadia Maps에서 어떻게 탐색하는지 설명했습니다.</p>
</li>
</ul>
<h2 id="알고-계셨나요">알고 계셨나요?</h2>
<ul>
<li>
<p><a id="wn831_34876"></a>
   오픈스트리트맵 재단 이사회에서 이사회 업무 수행 방식을 정하기 위해 자체 규칙을 마련해 놓았다는 <a href="https://osmfoundation.org/wiki/Board_Rules_of_Order">사실</a>을 알고 계셨나요?</p>
</li>
<li>
<p><a id="wn831_34866"></a>
   <a href="https://www.openstreetbrowser.org/#map=10/-22.9201/-43.0811&amp;basemap=osm-mapnik">OpenStreetBrowser</a>의 &lsquo;오픈스트리트맵 품질 관리(OpenStreetMap Quality Control)&rsquo; 아래에서 &lsquo;문화 - 미디어/위키데이터(Culture – Media/Wikidata)&rsquo; 범주를 통해 주제, 작가, 건축가, 어원과 관련한 참고 자료를 확인할 수 있다는 사실을 알고 계셨나요? 자세한 내용은 <a href="https://blog.openstreetbrowser.org/node/106">plepe의 글</a>을 참고하세요.</p>
</li>
</ul>
<h2 id="기타-지리-관련-소식">기타 &lsquo;지리&rsquo; 관련 소식</h2>
<ul>
<li>
<p><a id="wn831_34864"></a>
   지정학과 비판지리학 분야에서 저명한 학자 중 한 명인 이브 라코스트가 6월 20일 토요일 <a href="https://actualitte.com/article/132163/auteurs/yves-lacoste-fondateur-de-la-revue-herodote-est-mort">세상을 떠났습니다</a>. 이브 라코스트는 1976년 저서 La Géographie ça sert d&rsquo;abord à faire la guerre(지리학은 무엇보다 전쟁을 하기 위해 쓰인다)의 제목과 같이 유명하고도 논쟁적인 표현을 여럿 만들어냈습니다. 또한 이브 라코스트는 저널 <a href="https://www.herodote.org/">헤로도토스</a>의 창간자로서, 국가 간 권력 균형에 존재하는 불평등을 부각하며 지정학적 관계에는 중립이 없다는 점을 수십 년 동안 보여주는 데 <a href="https://en.wikipedia.org/wiki/Yves_Lacoste">힘써 왔습니다</a>. <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/fr.svg"
      
      
    />

  </picture>
</figure>



</p>
</li>
<li>
<p><a id="wn831_34850"></a>
   Xona Space Systems에서 유럽과 중동 전역에 걸친 GNSS 전파 방해 범위를 실험 위성을 통해 측정하고 지도화했다고 space.com이 <a href="https://www.space.com/space-exploration/satellites/its-quite-a-bit-more-than-we-expected-satellite-reveals-immense-scale-of-gps-signal-tampering">보도했습니다</a>.</p>
</li>
<li>
<p><a id="wn831_34857"></a>
   Esri España에서 2026 &lsquo;Maps in Action&rsquo; GIS 경진대회 출품 접수를 <a href="https://www.esri.es/es-es/acerca-de/eventos/cesri26/cesri26-mapasenaccion">시작했습니다</a>. 제출 마감일은 9월 21일입니다. 수상작은 9월 30일부터 10월 1일까지 열리는 Esri Spain Conference 2026에서 공개됩니다. <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/01/es.svg"
      
      
    />

  </picture>
</figure>



</p>
</li>
<li>
<p><a id="wn831_34863"></a>
   KoboToolbox <a href="https://github.com/kobotoolbox/kpi/releases/tag/2.026.23">2.026.23 업데이트</a>가 <a href="https://community.kobotoolbox.org/t/new-release-and-final-removal-of-v1-api/76423">나왔습니다</a>. 앞서 예고한 대로 이번 버전부터 버전 1 API가 완전히 제거되었습니다. 따라서 v1 엔드포인트를 사용하는 연동 기능은 더 이상 작동하지 않습니다. 실제 애플리케이션에서 v1에서 v2 엔드포인트로 이전하는 방법은 <a href="https://support.kobotoolbox.org/migrating_api.html">이 글</a>을 참고하세요.</p>
</li>
<li>
<p><a id="wn831_34858"></a>
   로이터에서 전 세계 현재 기온이 과거 평균과 어떻게 다른지 지구본 기반 시각화로 보여주는 동적 웹 대시보드, &lsquo;<a href="https://www.reuters.com/graphics/CLIMATE-AUTOMATED/MONITOR/akpeykqqapr/">로이터 기후 모니터(Reuters Climate Monitor)</a>&lsquo;를 공개했습니다.</p>
</li>
<li>
<p><a id="wn831_34849"></a>
   Rakeda가 공개 데이터 집합 100개 이상을 시각화할 수 있는 실시간 3D 지구본 플랫폼, <a href="https://metiq.space/">Metiq</a>을 <a href="https://news.ycombinator.com/item?id=48556082">개발했습니다</a>.</p>
</li>
<li>
<p><a id="wn831_34869"></a>
   <a href="https://www.reddit.com/user/Evilgrandma03/">u/Evilgrandma03</a>이 사람이 살지 않는 산지를 제외한 <a href="https://en.wikipedia.org/wiki/Languages_of_Switzerland">스위스의 언어</a> 지도를 레딧에 <a href="https://www.reddit.com/r/MapPorn/comments/1uaeagg/language_map_of_switzerland_excluding_uninhabited/">올렸습니다</a>. 이 지도는 스위스 연방통계청(FSO) 공식 지도를 산악 지도 위에 겹쳐 만들어졌습니다.</p>
</li>
<li>
<p><a id="wn831_34875"></a>
   Net Zero Frontiers에서 그린피스 소속 연구자 Nibedita Saha가 열화상 카메라로 여러 도시 지역 온도 차이를 측정했다고 <a href="https://www.linkedin.com/posts/climateaction-urbanheatisland-sustainability-share-7473263979667042304-H_G4/">보도했습니다</a>. 측정 결과, 나무 그늘 아래 표면은 직사광선에 노출된 표면보다 최대 20°C까지 온도가 낮을 수 있다는 사실이 확인되었으며, 도시 열섬 효과를 완화하는 데 도시 녹지가 중요한 역할을 한다는 점이 드러났습니다.</p>
</li>
<li>
<p><a id="wn831_34852"></a>
   secara.teratur가 오픈스트리트맵, Local Guides, 포스퀘어와 같은 인도네시아에서 인기 있는 자원봉사 지리정보 플랫폼 여러 곳을 <a href="https://secarateratur.medium.com/foursquare-appreciation-post-02333c9378b9">비교 분석했습니다</a>. <figure class="figure_figure figure_internal image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_internal image_unprocessed"
        src="https://hugo.weeklyosm.eu/wp-content/uploads/2022/09/id.svg"
      
      
    />

  </picture>
</figure>



</p>
</li>
</ul>
<h2 id="다가오는-행사">다가오는 행사</h2>
<table>
	<thead>
			<tr>
					<th>국가</th>
					<th>장소</th>
					<th>행사장</th>
					<th>명칭</th>
					<th>일시</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2017/11/tz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Dar es-Salaam</td>
					<td></td>
					<td>State of the Map Africa 2026 <a href="https://osmcal.org/event/3663/">:osmcalpic:</a></td>
					<td>2026-06-26 - 2026-06-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/08/se.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Uppsala</td>
					<td>Datorföreningen Update</td>
					<td>Mapping meetup in Uppsala <a href="https://osmcal.org/event/4913/">:osmcalpic:</a></td>
					<td>2026-06-28</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hannover</td>
					<td>Kuriosum</td>
					<td>OSM-Stammtisch Hannover <a href="https://osmcal.org/event/4848/">:osmcalpic:</a></td>
					<td>2026-06-29</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Saint-Étienne</td>
					<td>Zoomacom</td>
					<td>Rencontre Saint-Étienne et sud Loire <a href="https://osmcal.org/event/4897/">:osmcalpic:</a></td>
					<td>2026-06-29</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Heidelberg</td>
					<td>DEZERNAT#16</td>
					<td>Rhein-Neckar OSM Treffen <a href="https://osmcal.org/event/4730/">:osmcalpic:</a></td>
					<td>2026-06-29</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Webinaire en ligne - Hydrants, armoires de rue, poteaux et bâtiments de service <a href="https://osmcal.org/event/4871/">:osmcalpic:</a></td>
					<td>2026-06-30</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum 0</td>
					<td>Braunschweiger Mappertreffen im Stratum 0 Hackerspace <a href="https://osmcal.org/event/4859/">:osmcalpic:</a></td>
					<td>2026-06-30</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>City of Westminster</td>
					<td>The Albert pub</td>
					<td>London pub meet-up <a href="https://osmcal.org/event/4874/">:osmcalpic:</a></td>
					<td>2026-06-30</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Derby</td>
					<td>The Brunswick, Railway Terrace, Derby</td>
					<td>East Midlands pub meet-up <a href="https://osmcal.org/event/4800/">:osmcalpic:</a></td>
					<td>2026-06-30</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>MapCup Asia Pacific 2026 <a href="https://osmcal.org/event/4911/">:osmcalpic:</a></td>
					<td>2026-07-01 - 2026-07-31</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>iD Community Chat <a href="https://osmcal.org/event/4868/">:osmcalpic:</a></td>
					<td>2026-07-01</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stuttgart</td>
					<td>Forum 3 Café,  Gymnasiumstr. 21,  70173 Stuttgart</td>
					<td>Stuttgarter OpenStreetMap-Treffen <a href="https://osmcal.org/event/4854/">:osmcalpic:</a></td>
					<td>2026-07-01</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/06/sk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Žilina</td>
					<td>Fakulta riadenia a informatiky UNIZA</td>
					<td>Missing Maps mapathon Žilina #23 <a href="https://osmcal.org/event/4870/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Gent</td>
					<td>Nerdlab</td>
					<td>IntroLAB ✦ OpenStreetMap <a href="https://osmcal.org/event/4895/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Angers</td>
					<td>L’Arrière Train, 3 rue de Frémur, Angers</td>
					<td>Angers : Rencontre mensuelle OpenStreetMap <a href="https://osmcal.org/event/4855/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Bar Le Schmilblik</td>
					<td>Rencontre mensuelle des contributeurs Paris sud <a href="https://osmcal.org/event/4882/">:osmcalpic:</a></td>
					<td>2026-07-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/co.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bogotá</td>
					<td>Universidad Nacional de Colombia</td>
					<td>State of the Map Colombia (SotMCol) 2026 <a href="https://osmcal.org/event/4794/">:osmcalpic:</a></td>
					<td>2026-07-03 - 2026-07-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/03/br.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>[online]</td>
					<td>🇧🇷 Capacitação OSM 2026 - IVIDES DATA ® - Mapas Web com uMap <a href="https://osmcal.org/event/4764/">:osmcalpic:</a></td>
					<td>2026-07-03</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum0 Hackspace</td>
					<td>Braunschweiger OSM-Treffen Mappingtour: Zusammen Braunschweig mappen <a href="https://osmcal.org/event/4860/">:osmcalpic:</a></td>
					<td>2026-07-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>नई दिल्ली</td>
					<td>Jitsi Meet (online)</td>
					<td>OSM India - Monthly Online Mapathon <a href="https://osmcal.org/event/4886/">:osmcalpic:</a></td>
					<td>2026-07-04</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Greater London</td>
					<td>University College London</td>
					<td>London Data Week: Mapping festival with Missing Maps Mapathon <a href="https://osmcal.org/event/4915/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Salzburg</td>
					<td>Bewohnerservice Elisabeth-Vorstadt</td>
					<td>OSM-Treffpunkt <a href="https://osmcal.org/event/4469/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bern</td>
					<td>TBD</td>
					<td>OSM-Znacht in Bern <a href="https://osmcal.org/event/4820/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mapathon (with Training) Beginner Friendly  (Online) [eng] <a href="https://osmcal.org/event/4235/">:osmcalpic:</a></td>
					<td>2026-07-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2015/07/nl.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Groningen</td>
					<td>Groningen</td>
					<td>FOSS4GNL <a href="https://osmcal.org/event/4863/">:osmcalpic:</a></td>
					<td>2026-07-08 - 2026-07-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Trento</td>
					<td>Università di Trento - Facoltà di Sociologia</td>
					<td>FOSS4G IT &amp; OSMit 2026 <a href="https://osmcal.org/event/4827/">:osmcalpic:</a></td>
					<td>2026-07-09 - 2026-07-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>HTW Berlin</td>
					<td>Indoor OSM Workshop 2026 <a href="https://osmcal.org/event/4892/">:osmcalpic:</a></td>
					<td>2026-07-11 - 2026-07-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Delhi</td>
					<td>Chaayos, Paschim Vihar West, Delhi</td>
					<td>OSM Delhi Mapping Party No.30 (West Zone) <a href="https://osmcal.org/event/4351/">:osmcalpic:</a></td>
					<td>2026-07-12</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSM Chennai Mapping Party – Tambaram Market <a href="https://osmcal.org/event/4916/">:osmcalpic:</a></td>
					<td>2026-07-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/tw.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>臺北市</td>
					<td>MozSpace Taipei</td>
					<td>OpenStreetMap x Wikidata Taipei #90 <a href="https://osmcal.org/event/4326/">:osmcalpic:</a></td>
					<td>2026-07-13</td>
			</tr>
	</tbody>
</table>
<p><em>이 주간OSM은 다음 사람들이 <a href="https://umap.openstreetmap.fr/de/map/weeklyosm-is-currently-produced-in_56718#2/8.4/108.3">제작했습니다</a>. <a href="https://www.openstreetmap.org/user/LuxuryCoop">LuxuryCoop</a>, <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, <a href="https://www.openstreetmap.org/user/derFred">derFred</a>.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>주간 OSM 825</title>
				<link>https://hugo.weeklyosm.eu/ko/archives/0825/</link>
				<pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/archives/0825/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/05/825.png" alt="주간 OSM 825" /> 2026.05.07.-2026.05.13.
지도 제작 의견을 받고 있는 제안은 다음과 같습니다.
telecom=data_center 지물에 다중화 계층(redundancy tier), 총 전력 용량, IT 부하, 가용 IT 면적 등 표준화된 기술 속성을 추가하기 위해 data_center:tier, data_center:total_power, data_center:IT_power, data_center:IT_area 태그를 도입하자는 제안. “비행장 설명 태그(Aerodrome Descriptive Tags)” 제안의 찬반 투표가 진행 중입니다. 이 제안은 현재 여러 의미가 혼재되어 있는 비행장 태그를 개별 속성으로 분리하는 것을 목표로 합니다. 구체적으로 비행장 유형, 용도, 접근성, 스포츠, 국제선 여부를 나타내는 별도 태그를 도입하고, airstrip, heliport, seaplane_base에만 특별히 적용되는 값을 제안합니다.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/05/825.png" alt="주간 OSM 825" /></p> <p>2026.05.07.-2026.05.13.</p>
<h2 id="지도-제작">지도 제작</h2>
<ul>
<li>
<p><a id="wn825_34610"></a>
 의견을 받고 있는 제안은 다음과 같습니다.</p>
<ul>
<li><code>telecom=data_center</code> 지물에 다중화 계층(redundancy tier), 총 전력 용량, IT 부하, 가용 IT 면적 등 표준화된 기술 속성을 추가하기 위해 <code>data_center:tier</code>, <code>data_center:total_power</code>, <code>data_center:IT_power</code>, <code>data_center:IT_area</code> 태그를 도입하자는 <a href="https://wiki.openstreetmap.org/wiki/Proposal:Data_center_technical_attributes">제안</a>.</li>
</ul>
</li>
<li>
<p><a id="wn825_34612"></a>
 “비행장 설명 태그(Aerodrome Descriptive Tags)” 제안의 <a href="https://wiki.openstreetmap.org/wiki/Proposal:Aerodrome_Descriptive_Tags">찬반 투표가 진행 중입니다</a>. 이 제안은 현재 여러 의미가 혼재되어 있는 비행장 태그를 개별 속성으로 분리하는 것을 목표로 합니다. 구체적으로 비행장 유형, 용도, 접근성, 스포츠, 국제선 여부를 나타내는 별도 태그를 도입하고, <code>airstrip</code>, <code>heliport</code>, <code>seaplane_base</code>에만 특별히 적용되는 값을 제안합니다.</p>
</li>
</ul>
<h2 id="커뮤니티">커뮤니티</h2>
<ul>
<li>
<p><a id="wn825_34628"></a>
 Anne-Karoline Distel이 등산이나 하이킹 중에 벤치, 경로 표지판, 전망대, 대피소, 여울, 안전 관련 시설 등을 오픈스트리트맵에 바로 추가할 수 있다고 말하면서, 직접 <a href="https://www.youtube.com/watch?v=94jWBT_6HU0">시연을 보였습니다</a>.</p>
</li>
<li>
<p><a id="wn825_34664"></a>
 Raquel Dezidério Souto가 모잠비크의 마푸토 사범 대학교(Pedagogical University of Maputo)에서 주최한 자국의 환경법 개정 논의 행사에 특별 연사로 참석한 후기를 <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408669">올렸습니다</a>. Raquel은 행사에서 공개 데이터의 중요성과 누구에게나 열린 협업 지도 제작 플랫폼, 특히 오픈스트리트맵을 활용하는 것의 중요성을 강조했습니다. 기조연설 &lsquo;개발과 보존(Development &amp; Conservation)&lsquo;의 발표 자료는 Zenodo.org에 <a href="https://doi.org/10.5281/zenodo.20149423">올라와 있습니다</a>. :PT-s:</p>
</li>
<li>
<p><a id="wn825_34634"></a>
 9tab이 <a href="https://wiki.openstreetmap.org/wiki/Talk:Wiki#addr:place_inconsistencies">addr:place 태그의 불일치</a>를 지적하는 글을 오픈스트리트맵 위키에 올렸습니다. <a href="https://wiki.openstreetmap.org/wiki/Key:addr:place">addr:place</a>의 실제 사용법은 위키의 (모순된) 설명과 다를 수 있으며, 특히 <a href="https://wiki.openstreetmap.org/wiki/Key:addr:street">addr:street</a> 태그와의 관계에서 두드러진다고 9tab은 말합니다.</p>
</li>
<li>
<p><a id="wn825_34651"></a>
 덴마크에서 진행된 2년간의 새로운 <a href="https://community.openstreetmap.org/t/geografisk-crowdsourcing-via-openstreetmap-danmark-er-8-9-gange-mere-effektiv-viser-ny-stor-undersogelse/143708">비교 연구</a>에 따르면, 덴마크 오픈스트리트맵 커뮤니티가 정부 주도의 GeoFA 프로젝트보다 약 9배 더 효율적으로 지리 데이터를 생산하는 것으로 나타냈습니다. 38개의 각기 다른 야외 및 문화 데이터 범주를 2년 동안 추적한 결과, 오픈스트리트맵 덴마크 커뮤니티는 145,000개 이상의 항목을 기록하며 큰 격차로 선두를 유지하고 있습니다. :DK-s:</p>
</li>
<li>
<p><a id="wn825_34639"></a>
 오픈스트리트맵을 주제로 인터뷰를 연재하고 있는 OpenCage가 대중교통 경로 탐색을 위한 개방형 플랫폼, Transitous의 개발자 Volker Krause와 <a href="https://blog.opencagedata.com/post/openstreetmap-interview-transitous">이야기를 나누었습니다</a>.</p>
</li>
<li>
<p><a id="wn825_34638"></a>
 MapComplete 프로젝트에서 운영하는 도구를 통해 2026년 들어 지금까지 20,000개 이상의 바뀜집합이 <a href="https://en.osm.town/@MapComplete/116557376361008108">생성되었습니다</a>. 이와 동시에 오픈스트리트맵에서 <code>panoramax=*</code> 태그 사용 횟수가 100,000회을 돌파했습니다. <code>panoramax=*</code> 태그의 대부분은 MapComplete를 통해 추가되었으며 파노라맥스(Panoramax) 생태계의 콘텐츠와 오픈스트리트맵 개체를 잇는 역할을 합니다.</p>
</li>
<li>
<p><a id="wn825_34493"></a>
 이탈리아 오픈스트리트맵 커뮤니티를 위한 이탈리아어 월간 뉴스레터 <a href="https://community.openstreetmap.org/t/mensileosm-12-aprile-2026/143484">mensileOSM</a> 12호가 5월 1일자로 발행되었습니다. 이번 호는 mensileOSM의 출범 1주년을 기념하는 호이기도 합니다. :IT-s:</p>
</li>
<li>
<p><a id="wn825_34657"></a>
 최근 달 탐사 활동이 다시 활발해짐에 따라 오픈스트리트맵 커뮤니티와 <a href="https://www.openlunar.org/">열린 달 재단(Open Lunar Foundation)</a>이 협력해 오픈소스 달 지도를 구축해 보자고 Thomas D.가 <a href="https://community.openstreetmap.org/t/open-moon-map-collaboration/143808">제안했습니다</a>. 이전에도 협업으로 달 지도를 구축한 사례가 여럿 있었던 만큼, 이번 계획이 마냥 비현실적이거나 뜬금없지는 않아 보입니다.</p>
</li>
<li>
<p><a id="wn825_34653"></a>
 오픈스트리트맵 미국(OpenStreetMap US)이 미국 전역의 습지를 공개적으로 보여주는 OpenWetlandsMap을 구축하기 위해 환경 정책 혁신 센터(EPIC)와 <a href="https://openstreetmap.us/news/2026/05/openwetlandsmap-announcement/">협력하고 있습니다</a>. OpenWetlandsMap은 시대에 뒤떨어지고 파편화된 기존 데이터를 커뮤니티에서 관리하는 최신 오픈스트리트맵 지도 데이터로 보완해 환경 보존 및 정책 결정을 지원하는 것을 목표로 합니다.</p>
</li>
<li>
<p><a id="wn825_34643"></a>
 rphyrin이 <a href="https://en.wikipedia.org/wiki/Hajj">하지(Haji) 순례자</a> 무리의 여정을 Altilunium Locationpad를 활용해 지도 위에 <a href="https://www.openstreetmap.org/user/rphyrin/diary/408657">시각화했습니다</a>.</p>
</li>
<li>
<p><a id="wn825_34629"></a>
 SomeoneElse가 오픈스트리트맵에서 <code>disused=yes</code> 태그가 실제로 무엇을 의미하는지 <a href="https://www.openstreetmap.org/user/SomeoneElse/diary/408645">탐구했습니다</a>.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-지부">오픈스트리트맵 지부</h2>
<ul>
<li><a id="wn825_34669"></a>
 오픈스트리트맵 미국에서 <a href="https://yesterdays.maprva.org/">Yesterdays</a>를 새로운 공인 프로젝트로 <a href="https://openstreetmap.us/news/2026/05/yesterdays-charter-project/">맞이했습니다</a>. Yesterdays는 옛 사진에 좌표 값을 부여하고, 오픈스트리트맵과 과거 사료를 활용해 옛날의 도시 풍경을 지도화하는 협업 플랫폼입니다.</li>
</ul>
<h2 id="행사">행사</h2>
<ul>
<li><a id="wn825_34630"></a>
 오픈스트리트맵 재단에서 State of the Map 2027 개최지 공모를 <a href="https://blog.openstreetmap.org/2026/05/11/state-of-the-map-2027-call-for-venues-is-now-open/">시작했습니다</a>. 신청은 2026년 7월 19일까지 가능하며, 선정된 개최지는 파리에서 열리는 State of the Map 2026 행사에서 발표됩니다.</li>
</ul>
<h2 id="교육">교육</h2>
<ul>
<li><a id="wn825_34665"></a>
 IVIDES DATA(브라질)에서 주최한 2026 OpenStreetMap Workshop Series가 막을 올렸습니다. 행사에는 브라질과 모잠비크, 앙골라 등 포르투갈어권 국가에서 온 사람들이 주를 이뤘습니다. 발표 동영상 링크 및 PDF 사본은 <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408653">여기</a>를 통해 보실 수 있으며, 참가자들의 거주지를 보여주는 <a href="https://umap.openstreetmap.fr/pt-br/map/participantes-ciclo-de-oficinas-osm-2026_1404577#4/-14.944785/-14.414063">uMap</a> 지도도 감상해 보세요. :PT-s:</li>
</ul>
<h2 id="지도">지도</h2>
<ul>
<li>
<p><a id="wn825_34640"></a>
 Andy Allan의 도움을 받아 애플 watchOS용 걷기 추적 앱 <a href="https://itunes.apple.com/us/app/pedometer&#43;&#43;/id712286167">Pedometer++</a>의 오픈스트리트맵 기반 지도를 디자인한 David Smith가 지난 6년 간의 여정을 <a href="https://www.david-smith.org/blog/2026/04/29/maps-on-watchos/">이야기했습니다</a>.</p>
</li>
<li>
<p><a id="wn825_34632"></a>
 Transform Transport에서 유럽 도시 전역의 필수 서비스 접근성을 분석한 &lsquo;15분 도시 점수(15 Minute City Score)&rsquo; 지도를 <a href="https://app.transformtransport.org/15minCS/europe-map.html">발표했습니다</a>. 오픈스트리트맵의 보행자 통행망과 편의시설 데이터를 활용했으며, 도시끼리 서로 비교할 수 있도록 일관된 공간 분석 방법을 적용했습니다.</p>
</li>
<li>
<p><a id="wn825_34649"></a>
 Alex Spritze가 주소 비교 웹 앱, <a href="https://addresses.tillb.de/">OSM-ALKIS</a>를 사용해 독일 작센안할트(Saxony-Anhalt)주 전역의 주소 데이터 분포가 얼마나 완전한지 <a href="https://troet.cafe/@AlexSpritzeOSM/116560131710346931">분석했습니다</a>. 분석 결과, 누락된 주소가 &lsquo;단 9개&rsquo;뿐인 잉거슬레벤(Ingersleben)과 같은 우수 지역부터 오픈스트리트맵에 3.8%의 주소만 들어가 있는 귀스텐(Güsten) 같은 지역에 이르기까지 지자체 간 격차가 크다는 사실이 밝혀졌습니다. :DE-s:</p>
</li>
</ul>
<h2 id="오픈스트리트맵-활용-사례">오픈스트리트맵 활용 사례</h2>
<ul>
<li><a id="wn825_34617"></a>
 시리아 관광부에서 시리아의 관광 명소, 관광 시설, 투자 기회 등을 보여주는 오픈스트리트맵 기반 웹 지도, 시리아 관광 지도(خريطة سورية السياحية)를 <a href="https://alnashra.org/map11/gis_syria2/syria_tourism.php">구축했습니다</a>. :AR-s:</li>
</ul>
<h2 id="소프트웨어">소프트웨어</h2>
<ul>
<li>
<p><a id="wn825_34673"></a>
 HeiGIT에서 오픈스트리트맵 도로 데이터와 기계 학습을 결합해 독일 전역의 도로 교통 관련 CO₂ 배출량과 대기 오염 물질을 지도화하는 새로운 교통 배출량 도구를 <a href="https://climate-action.heigit.org/dashboard/plugin/traffic_emissions">발표했습니다</a>. 해당 도구는 <a href="https://climate-action.heigit.org/dashboard">기후 행동 내비게이터</a>를 통해 이용해볼 수 있으며, 기후 행동이 가장 시급히 필요한 곳이 어디인지 파악하는 데 도움을 줍니다.</p>
</li>
<li>
<p><a id="wn825_34672"></a>
 <a href="https://github.com/open-energy-transition/grid2poster">Grid2Poster</a>는 오픈스트리트맵 데이터를 활용해 송전망을 인쇄용 포스터로 렌더링하는 새로운 오픈소스 도구입니다. Grid2Poster는 GeoPandas, OSMnx, Matplotlib을 토대로 구현되었으며, 지역/국가/대륙 규모로 송전망과 행정 경계(선택 사항)가 시각화된 지도를 뽑을 수 있습니다. Grid2Poster는 <a href="https://github.com/originalankur/maptoposter">maptoposter</a>로부터 크게 영감을 받았으며, maptoposter의 스타일을 가져와 재사용했습니다.</p>
</li>
<li>
<p><a id="wn825_34652"></a>
 Tobias Jordans가 오픈스트리트맵의 행정 경계와 독일 공식 데이터 집합을 비교해 주는 웹 도구인 Grenzabgleich를 <a href="https://grenzabgleich.osm-verkehrswende.org/">공개했습니다</a>. Grenzabgleich는 IoU(교집합 비율) 및 하우스도르프 거리(Hausdorff distance)와 같은 지표를 계산해 불일치하는 부분을 시각적으로 강조함으로써 우선적으로 검토할 곳을 정하고 경계 데이터의 품질을 개선하는 데 도움이 됩니다. :DE-s:</p>
</li>
<li>
<p><a id="wn825_34622"></a>
 오픈스트리트맵 기반 프로젝트인 CoMaps가 Swift와 Material 3로의 이전과 자동 지도 생성을 포함한 주요 기술 업데이트를 <a href="https://www.comaps.app/news/comaps-technical-changes/">발표했습니다</a>. 이번 업데이트는 앱의 유지보수성, 성능, 장기적 지속 가능성을 향상시키는 데 주안점을 두었습니다.</p>
</li>
<li>
<p><a id="wn825_34648"></a>
 CoMaps가 출시 1주년을 맞아 커뮤니티의 성장, 새롭게 추가된 주요 기능, 앞으로 나아갈 방향을 <a href="https://www.comaps.app/news/2026-05-12/celebrating-the-first-comaps-birthday/">돌아보았습니다</a>.</p>
</li>
<li>
<p><a id="wn825_34619"></a>
 HeiGIT에서 <a href="https://ohsome-now.heigit.org/dashboard#hashtag=&amp;start=2025-05-08T00:00:00Z&amp;end=2026-05-08T11:11:15Z&amp;interval=P1M&amp;active_topic=contributor&amp;countries=&amp;topics=contributor,edit,building,road&amp;osm_user=115612">ohsomeNOW</a>에 <a href="https://heigit.org/new-user-statistics-in-ohsomenow/">새로운 사용자 통계 기능</a>을 도입했습니다. 이로써 각 오픈스트리트맵 편집자들의 활동 내역을 더 깊이 이해하고 조직적인 편집 패턴을 분석하기 용이해졌습니다.</p>
</li>
<li>
<p><a id="wn825_34645"></a>
 QGIS를 통한 대량 지도 타일 다운로드가 잦아지면서 다른 사람들의 서비스 이용에 지장이 갈 정도가 되자 오픈스트리트맵 운영팀에서는 QGIS에서 tile.openstreetmap.org에 접근할 수 있는 빈도를 크게 <a href="https://en.osm.town/@osm_tech/116561251606643070">제한했습니다</a>. 현재 오픈스트리트맵과 QGIS 개발팀은 대량 다운로드는 막으면서도 일반적인 사용은 계속해서 지원할 방법을 모색하고 있습니다. 또한 현재 오픈스트리트맵은 타일 렌더링 용량을 늘리기 위해 서버 자원을 기부해 줄 사람 및 단체를 찾고 있습니다.</p>
</li>
<li>
<p><a id="wn825_34635"></a>
 Sean Carapella가 BRouter와 brouter-web을 기반으로 구축된 소형 선박용 경로 탐색 및 지도 도구, <a href="https://paddlemap.net/">PaddleMap</a>을 출시했습니다. 수로 및 육로 운반로(portage) 위에서의 경로 탐색을 지원하며, 선착장, 댐, 급류 등 패들링(paddling) 관련 관심 지점(POI)을 강조해서 보여줍니다.</p>
</li>
<li>
<p><a id="wn825_34671"></a>
 <a href="https://trailmaps.app">Trailmaps.app</a>은 오픈스트리트맵 데이터를 모바일 친화적인 산악 자전거 도로망도로 변환하는 웹 사이트입니다. Trailmaps.app은 일반적으로 쓰이는 난이도 체계 대신 현지 등산로/둘레길 표지판의 난이도 표기와 일치하도록 설계되었으며, 관련 지도 생성기는 오픈 소스로 공개되어 있습니다. 개발자에 따르면 프로젝트의 대부분이 Claude AI의 도움으로 만들어졌다고 합니다.</p>
</li>
<li>
<p><a id="wn825_34624"></a>
 iD 편집기에 여러 사용자 지정 배경 레이어를 추가할 수 있게 해주는 사용자 스크립트가 <a href="https://community.openstreetmap.org/t/userscript-to-add-multiple-custom-maps-to-id-editor/143679">나왔습니다</a>. 이 스크립트를 적용하면 사용자 지정 URL을 매번 바꿀 필요 없이 여러 타일을 한번에 등록해 놓고 손쉽게 전환할 수 있게 됩니다.</p>
</li>
<li>
<p><a id="wn825_34655"></a>
 오픈스트리트맵의 소화전 데이터를 시각화하고 유지 관리하기 위해 Fabian Flodman이 만든 <a href="https://hydrantmap.org/">HydrantMap</a>을 Manny Fred가 <a href="https://community.openstreetmap.org/t/vorstellung-hydrantmap-org-openstreetmap-hydrantenkarte/143804">소개했습니다</a>. HydrantMap은 OsmHydrant의 아이디어에서 영감을 얻었으며, 최신 데이터 유지, 모바일 사용성, 유지보수가 용이한 현대적 기술 기반에 초점을 맞춰 개발되었습니다.</p>
</li>
</ul>
<h2 id="프로그래밍">프로그래밍</h2>
<ul>
<li>
<p><a id="wn825_34644"></a>
 CAD 소프트웨어의 모깎기(fillet) 도구처럼 길(way)의 모서리를 둥글게 만들 수 있는 JOSM 플러그인, Fillet Tools를 개발한 darkonus가 피드백, 버그 제보, 비정상적인 작동 사례, 개선 제안을 받기 위해 Fillet Tools를 시험삼아 써 볼 사람을 <a href="https://www.openstreetmap.org/user/darkonus/diary/408655">모집하고 있습니다</a>. Fillet Tools 플러그인은 GitLab의 <a href="https://gitlab.com/darkonus/josm-fillet-tools/-/releases/v0.1.0/">버전 0.1.0 출시 페이지</a>에서 수동으로 설치하실 수 있습니다.</p>
</li>
<li>
<p><a id="wn825_34618"></a>
 Matija Nalis가 크로아티아 오픈스트리트맵 커뮤니티(OSM-HR)에서 쓸 파노라맥스 인스턴스를 구축한 경험을 하드웨어부터 Docker 설정, 오픈스트리트맵 OAuth2 연동까지 상세하게 <a href="https://www.openstreetmap.org/user/Matija%20Nalis/diary/408636">공유했습니다</a>. Matija의 보고서를 통해 파노라맥스 인스턴스의 배포하고 운영하는 방법뿐만 아니라 여러 가지 난관에 어떻게 대처할 수 있는지 엿볼 수 있습니다.</p>
</li>
<li>
<p><a id="wn825_34616"></a>
 Christian Quest가 OSM-FR 포럼에서 파노라맥스 인스턴스를 구축하는 데 필요한 저장 공간을 구체적으로 <a href="https://forum.geocommuns.fr/t/storage-needs-for-a-panoramax-instance/3205">공유했습니다</a>. 분석 결과, 360° 사진이 필요 용량을 크게 증가시키는 것으로 나타났으며, 이에 Christian은 조만간 저장 용량 최적화를 진행할 계획이라고 밝혔습니다.</p>
</li>
<li>
<p><a id="wn825_34637"></a>
 오픈스트리트맵 운영 작업반에서 노미나팀(Nominatim) 사용 정책을 <a href="https://github.com/openstreetmap/owg-website/pull/170">업데이트했습니다</a>. 이번 변경으로 자동화된 사용 제한이 더욱 강화되었으며, 인공지능 앱 및 &lsquo;바이브 코딩(vibe coding)&lsquo;에 관한 지침이 처음으로 도입되었습니다.</p>
</li>
</ul>
<h2 id="출시">출시</h2>
<ul>
<li>
<p><a id="wn825_34621"></a>
 3월과 4월에 걸쳐 Nico Isenbeck가 <a href="https://onroutemap.de/de/">onroutemap.de</a>를 <a href="https://onroutemap.de/de/about">개선했습니다</a>.</p>
<ul>
<li>3월: 프랑스어와 스페인어 지원이 추가되었으며, 개인 즐겨찾기를 KML 및 GPX로 내보낼 수 있게 되었습니다.</li>
<li>4월: 실시간 돌풍 레이어가 추가되었습니다. 현재 돌풍 데이터(Open-Meteo)를 보퍼트 풍속 등급에 따라 색상으로 구분해 보여줍니다. 또한 OverPass에서 PostGIS로 전환해 지도 생성 성능이 훨씬 향상되었습니다.</li>
</ul>
</li>
<li>
<p><a id="wn825_34625"></a>
 Marcus Jaschen이 bikerouter.de 2026.11 버전에서 어떤 점이 업데이트될지 일부 <a href="https://mastodon.social/@mjaschen/116545565991016798">예고했습니다</a>.</p>
</li>
<li>
<p><a id="wn825_34620"></a>
 Martin Raifer가 <a href="https://github.com/openstreetmap/iD/releases/tag/v2.40.0">iD 편집기 2.40</a> 업데이트를 <a href="https://en.osm.town/@tyr/116539161555937761">공지했습니다</a>. 이번 업데이트로 보행자 및 자전거 겸용 도로에 새로운 스타일이 적용되게 되었으며, 원형 지물의 세부 수준이 동적으로 바뀌게 되었습니다. 또한 사전 설정(preset) 처리 방식도 변경되어 새롭게 선택한 사전 설정에 유효하지 않은 태그가 있다면 자동으로 제거되게 바뀌었습니다.</p>
</li>
<li>
<p><a id="wn825_34667"></a>
 OsmAnd 팀이 OsmAnd Web 버전 1.03 업데이트를 <a href="https://osmand.net/blog/osmand-web-1.03-released">발표했습니다</a>. 이번 업데이트로 가민 커넥트(Garmin Connect) 연동을 통한 활동 동기화 기능과 궤적(track)을 저장하는 스마트 폴더(Smart Folders) 기능이 추가되었으며, 관심 지점(POI) 정보가 개선되었습니다. 또한 GPX 궤적 및 즐겨찾기를 관리하고 표시하는 도구가 새롭게 디자인되었습니다.</p>
</li>
<li>
<p><a id="wn825_34626"></a>
 Project OSRM 팀에서 <code>osrm-backend</code> 26.5.0 업데이트를 <a href="https://github.com/Project-OSRM/osrm-backend/releases/tag/v26.5.0">발표했습니다</a>. 이번 업데이트로 기본 저장소에 파이썬 바운딩이 추가되었고, 빌드 시스템이 vcpkg로 이전되었으며, Boost 의존성이 줄어들었습니다. 아울러 경로 탐색 프로필에서 <code>winter_road</code>와 <code>ice_road</code>를 지원하게 되었습니다.</p>
</li>
<li>
<p><a id="wn825_34627"></a>
 Project OSRM에서 등시선<sup>1</sup>
 엔드포인트를 실험하고 있다고 <a href="https://en.osm.town/@osrm/116540225411349846">알렸습니다</a>. 이 기능은 아직 출시되지 않았지만, 향후 OSRM 경로 탐색을 기반으로 한 도달 가능성 분석을 강화하는 데 도움이 될 전망입니다.</p>
</li>
</ul>
<p>(등시선<sup>1</sup>
(isochrone): 특정 시간 안에 도달할 수 있는 지점들을 연결한 선 - 역주)</p>
<ul>
<li>
<p><a id="wn825_34668"></a>
 Martijn van Exel이 파이썬 overpass 라이브러리의 0.82 업데이트를 <a href="https://community.openstreetmap.org/t/overpass-api-performance-issues/140598/121">발표했습니다</a>. 이번 업데이트부터는 애플리케이션에 User-Agent 헤더를 필수로 설정해야 합니다. 문제가 되는 요청으로부터 Overpass API를 보호하기 위함입니다.</p>
</li>
<li>
<p><a id="wn825_34633"></a>
 CoMaps에서 2026.05.06 버전을 <a href="https://www.comaps.app/news/2026-05-06/Release-2026.05.06-release-notes/">출시했습니다</a>. 이번 버전부터는 지도 버전이 앱 버전에 종속되지 않기 때문에, 앱을 먼저 업데이트하지 않아도 지도 데이터를 업데이트할 수 있습니다. 이로써 지도의 업데이트 빈도가 늘어나 앞으로는 매주 지도가 업데이트될 예정입니다.</p>
</li>
<li>
<p><a id="wn825_34623"></a>
 Organic Maps 개발팀이 2026.05.08-4 버전을 <a href="https://github.com/organicmaps/organicmaps/releases/tag/2026.05.08-4-android">출시했습니다</a>. 이제 지도 상의 정류장에서 대중교통 노선을 확인할 수 있게 되었습니다. 또한 최신 오픈스트리트맵 데이터가 반영되었고, 고도 차트가 개선되었으며, 지도 다운로드 과정이 최적화되었습니다.</p>
</li>
</ul>
<h2 id="알고-계셨나요">알고 계셨나요?</h2>
<ul>
<li><a id="wn825_34654"></a>
 osm.org의 모든 개체에 &lsquo;태그 편집&rsquo; 버튼을 <a href="https://github.com/Zverik/osmtags-editor">추가하는</a> 브라우저 확장 프로그램이 있다는 사실을 알고 계셨나요?</li>
</ul>
<h2 id="매체-속-오픈스트리트맵">매체 속 오픈스트리트맵</h2>
<ul>
<li><a id="wn825_34656"></a>
 CHIP에서 낯선 지역에서 주변 장소를 찾을 때 오픈스트리트맵이 구글 지도보다 훨씬 더 유용하다고 <a href="https://www.chip.de/news/software/warum-tut-man-sich-sowas-an-hier-ist-google-maps-richtig-nutzlos_8fc5f71e-74b0-4490-9e4b-b941a0becd94.html">평했습니다</a>. 기사에서 예시로 든 지역에서 구글 지도는 눈에 띄는 공백을 남긴 반면, 오픈스트리트맵은 상점, 장소, 편의 시설을 더 자세히 보여주었습니다. :DE-s:</li>
</ul>
<h2 id="기타-지리-관련-소식">기타 &lsquo;지리&rsquo; 관련 소식</h2>
<ul>
<li>
<p><a id="wn825_34642"></a>
 Caleb Robinson과 Isaac Corley가 가우시안 스플래팅(Gaussian splatting) 기법을 사용해 센티널 2호(Sentinel-2) 위성 사진을 선명하게 만드는 방법을 <a href="https://geospatialml.com/posts/sentinel2-superresolution">블로그에 올렸습니다</a>. 이 기법은 위성이 여러 번 궤도를 돌며 사진을 촬영할 때 발생하는 미세한 픽셀 위치의 변화를 이용해 사진에서 더 많은 정보를 추출하는 원리로 작동합니다.</p>
</li>
<li>
<p><a id="wn825_34670"></a>
 Ordnance Survey와 GeoPlace가 수백만 건에 달하는 영국의 공개 지방세 주소 기록을 삭제할 것을 <a href="https://www.owenboswarva.com/blog/post-addr86.htm">요구했습니다</a>. 이들은 Ordnance Survey, GeoPlace, Royal Mail의 지적 재산권을 침해했다고 주장하고 있습니다. 삭제 대상이 된 데이터 집합은 이전에 57개 지자체에서 개방형 라이선스로 배포했던 자료입니다.</p>
</li>
<li>
<p><a id="wn825_34636"></a>
 오픈스트리트맵 데이터를 기반으로 하는 최신 가민 지도 업데이트 &lsquo;TopoActive Europe 2026.10&rsquo;이 기기 충돌 및 부한 재부팅을 <a href="https://gpsradler.de/news/vorsicht-kartenupdate-garmin-2026_10/">비롯해</a> 여러 기기에서 심각한 경로 탐색 문제를 <a href="https://forums.garmin.com/sports-fitness/cycling/f/edge-840-series/435572/saving-diagnostics-boot-loop-after-map-update-2026-10">일으키고 있습니다</a>. 여러 Edge 모델이 이 문제의 영향을 받고 있으며, 가민 측은 현재 임시방편으로 이전 지도 버전으로 다운그레이드할 것을 <a href="https://support.garmin.com/de-DE/?faq=Zx9gEvcPOs09nQGpXO64U7">권장하고 있습니다</a>. :DE-s:</p>
</li>
</ul>
<h2 id="다가오는-행사">다가오는 행사</h2>
<table>
	<thead>
			<tr>
					<th>국가</th>
					<th>장소</th>
					<th>행사장</th>
					<th>명칭</th>
					<th>일시</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Acireale</td>
					<td>Mappiamo le Aci <a href="https://osmcal.org/event/4757/">:osmcalpic:</a></td>
					<td>2026-05-16 - 2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/us.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>New York</td>
					<td>East River Park at Corlears Hook</td>
					<td>NYC Mapper Picnic <a href="https://osmcal.org/event/4770/">:osmcalpic:</a></td>
					<td>2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Chennai Corporation</td>
					<td>Hotel Nithya Amirtham, Mylapore Market, Chennai</td>
					<td>Mapping at Mylapore Market, Chennai <a href="https://osmcal.org/event/4743/">:osmcalpic:</a></td>
					<td>2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bologna</td>
					<td>aula 0.6, DICAM, Unibo, Viale del Risorgimento 2</td>
					<td>Unibo Mapathon OpenStreetMap 2026-05 <a href="https://osmcal.org/event/4756/">:osmcalpic:</a></td>
					<td>2026-05-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Mannheim</td>
					<td>RaumZeitLabor, Mannheim</td>
					<td>Rhein-Neckar OpenstreetMap Treffen <a href="https://osmcal.org/event/4742/">:osmcalpic:</a></td>
					<td>2026-05-18</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Webinaire de sensibilisation à OpenStreetMap pour les collectivités <a href="https://osmcal.org/event/4736/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2020/09/uk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Greater London</td>
					<td>Médecins Sans Frontières (MSF UK) Office</td>
					<td>Missing Maps London In-Person Mapathon <a href="https://osmcal.org/event/4787/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mid-Month (Without Training) Advanced Mappers [eng] <a href="https://osmcal.org/event/4245/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Lyon</td>
					<td>Tubà</td>
					<td><del>Réunion du groupe local de Lyon</del> <a href="https://osmcal.org/event/4307/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Chemnitz</td>
					<td>Kaffeesatz, Chemnitz</td>
					<td>OSM-Stammtisch Chemnitz <a href="https://osmcal.org/event/4658/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bonn</td>
					<td>Dotty&rsquo;s</td>
					<td>200. OSM-Stammtisch Bonn <a href="https://osmcal.org/event/4356/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Online</td>
					<td>Lüneburger Mappertreffen (online) <a href="https://osmcal.org/event/4371/">:osmcalpic:</a></td>
					<td>2026-05-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>MJC de Vienne</td>
					<td>Rencontre des contributeurs de Vienne (38) <a href="https://osmcal.org/event/4777/">:osmcalpic:</a></td>
					<td>2026-05-20</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Online Missing Maps Mapathon ÄRZTE OHNE GRENZEN (AT/DE) <a href="https://osmcal.org/event/4772/">:osmcalpic:</a></td>
					<td>2026-05-20</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Karlsruhe</td>
					<td>Chiang Mai</td>
					<td>Stammtisch Karlsruhe <a href="https://osmcal.org/event/4715/">:osmcalpic:</a></td>
					<td>2026-05-20</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/03/br.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>[online]</td>
					<td>🇧🇷 Capacitação OSM 2026 - IVIDES DATA ® - Editor iD - Parte II <a href="https://osmcal.org/event/4760/">:osmcalpic:</a></td>
					<td>2026-05-22</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Metz</td>
					<td>l’Arob@se</td>
					<td>Atelier du groupe local de Metz - Cartographions les services publics ! <a href="https://osmcal.org/event/4783/">:osmcalpic:</a></td>
					<td>2026-05-23</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Ferrara</td>
					<td>Ferrara</td>
					<td>Raccolta dati aree verdi @ Giornata Mondiale della Biodiversità 2026 - Citizen Science Ferrara <a href="https://osmcal.org/event/4716/">:osmcalpic:</a></td>
					<td>2026-05-23</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Navi Mumbai</td>
					<td></td>
					<td>OSM Mumbai Mapping Party No.10 (Trans-Harbour Line - North) <a href="https://osmcal.org/event/4319/">:osmcalpic:</a></td>
					<td>2026-05-23</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bologna</td>
					<td>Velostazione ExDynamo</td>
					<td>Compleanno di Wikipedia a Bologna 2026, con wikigita e mapping party in Bolognina e pranzo alla velostazione <a href="https://osmcal.org/event/4773/">:osmcalpic:</a></td>
					<td>2026-05-24</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4298/">:osmcalpic:</a></td>
					<td>2026-05-25</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Lyon</td>
					<td>Tubà</td>
					<td>Réunion du groupe local de Lyon <a href="https://osmcal.org/event/4791/">:osmcalpic:</a></td>
					<td>2026-05-26</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>Online</td>
					<td>OSM-Verkehrswende #75 <a href="https://osmcal.org/event/4785/">:osmcalpic:</a></td>
					<td>2026-05-26</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Würzburg</td>
					<td>FabLab Würzburg</td>
					<td>Würzburger OSM-Treffen <a href="https://osmcal.org/event/4788/">:osmcalpic:</a></td>
					<td>2026-05-27</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Düsseldorf</td>
					<td>Online bei <a href="https://meet.jit.si/OSM-DUS-2026">https://meet.jit.si/OSM-DUS-2026</a></td>
					<td>Düsseldorfer OpenStreetMap-Treffen (online) <a href="https://osmcal.org/event/4385/">:osmcalpic:</a></td>
					<td>2026-05-27</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Bad Harzburg</td>
					<td>Braunschweiger OSM-Treffen Mappingtour: Zusammen Bad Harzburg mappen <a href="https://osmcal.org/event/4775/">:osmcalpic:</a></td>
					<td>2026-05-30</td>
			</tr>
	</tbody>
</table>
<p><em>이 주간OSM은 다음 사람들이 <a href="https://umap.openstreetmap.fr/de/map/weeklyosm-is-currently-produced-in_56718#2/8.4/108.3">제작했습니다</a>. <a href="https://www.openstreetmap.org/user/LuxuryCoop">LuxuryCoop</a>, <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, Andrew Davidson, <a href="https://www.openstreetmap.org/user/chiho_kang">chiho_kang</a>, <a href="https://www.openstreetmap.org/user/derFred">derFred</a>, <a href="https://www.osm.org/user/mcliquid">mcliquid</a>.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>주간 OSM 823</title>
				<link>https://hugo.weeklyosm.eu/ko/archives/0823/</link>
				<pubDate>Thu, 23 Apr 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/archives/0823/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/05/822.png" alt="주간 OSM 823" /> 2026.04.23.-2026.04.29.
지도 제작 의견을 받고 있는 제안은 다음과 같습니다.
terminal=yes: 화물 터미널을 일관되게 매핑하고 연계 교통수단과 취급 화물을 더 잘 설명하기 위한 태그. 찬반 투표가 진행 중인 제안은 다음과 같습니다.
highway=service + service=safari: 사파리 공원 내 전용 서비스 도로를 지도에 나타내기 위한 태그. 커뮤니티 Chirstian Quest가 OpenCage 블로그와의 인터뷰에서 개방형 연합 거리 사진 플랫폼을 조율할 Panoramax 재단의 향후 계획을 설명했습니다. 오픈스트리트맵 재단에서 영감을 받은 이 프로젝트는 국제적인 협력을 촉진하는 것을 목표로 합니다.
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/05/822.png" alt="주간 OSM 823" /></p> <p>2026.04.23.-2026.04.29.</p>
<h2 id="지도-제작">지도 제작</h2>
<ul>
<li>
<p><a id="wn823_34500"></a>
 의견을 받고 있는 제안은 다음과 같습니다.</p>
<ul>
<li><code>terminal=yes</code>: 화물 터미널을 일관되게 <a href="https://wiki.openstreetmap.org/wiki/Proposal:Freight_Terminal">매핑하고</a> 연계 교통수단과 취급 화물을 더 잘 설명하기 위한 태그.</li>
</ul>
</li>
<li>
<p><a id="wn823_34499"></a>
 찬반 투표가 진행 중인 제안은 다음과 같습니다.</p>
<ul>
<li><code>highway=service</code> + <code>service=safari</code>: 사파리 공원 내 전용 서비스 도로를 <a href="https://wiki.openstreetmap.org/wiki/Proposal:Safari_Route_Relation_Type#Voting">지도에 나타내기 위한</a> 태그.</li>
</ul>
</li>
</ul>
<h2 id="커뮤니티">커뮤니티</h2>
<ul>
<li>
<p><a id="wn823_34506"></a>
 Chirstian Quest가 OpenCage 블로그와의 인터뷰에서 개방형 연합 거리 사진 플랫폼을 조율할 Panoramax 재단의 향후 계획을 <a href="https://blog.opencagedata.com/post/openstreetmap-interview-panoramax">설명했습니다</a>. 오픈스트리트맵 재단에서 영감을 받은 이 프로젝트는 국제적인 협력을 촉진하는 것을 목표로 합니다.</p>
</li>
<li>
<p><a id="wn823_34539"></a>
 Christian Quest가 OSM France에서 운영하는 Paronamax 인스턴스는 테스트 목적으로만 프랑스 외부의 사진을 허용한다는 점을 <a href="https://community.openstreetmap.org/t/osm-fr-panoramax-server-only-for-testing-if-outside-of-france/143428">상기시켰습니다</a>. 그러나 현재 올라온 사진의 거의 절반이 해외에서 촬영된 것입니다. 그는 디스크 용량이 부족해짐에 따라 OSM France 이사회가 조만간 해당 사진들의 삭제 여부를 결정할 것이라고 경고했습니다. 최근 통계에 따르면 Panoramax 연합은 10개의 인스턴스로 <a href="https://en.osm.town/@PanoramaxContribs/116476556609091368">성장했으며</a>, 현재 2,000명 이상의 사용자가 기여한 <a href="https://panoramax.fr/stats">1억 장</a> 이상의 개방형 라이선스 거리 사진을 호스팅하고 있습니다. Bastian Greshake Tzovaras가 마스토돈에서 이 성과를 <a href="https://en.osm.town/@gedankenstuecke@scholar.social/116476561676964776">축하했습니다</a>.</p>
</li>
<li>
<p><a id="wn823_34529"></a>
 9_tab이 자신의 오픈스트리트맵 일기장에  에 대해 썼다 <a href="https://www.openstreetmap.org/user/9_tab/diary/408586"><em>Quartiers de Genève</em></a> :FR-s: 에 관한 글을 올렸습니다. <a href="https://www.openstreetmap.org/#map=14/46.20506/6.14312">제네바</a> 일대에서 진행된 지도 제작 스프린트를 통해 <code>place=*</code> 마디(node)를 정리하였으며, 근린주구와 구역에 대한 현지 데이터를 지도에 그려진 데이터와 비교했습니다.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-재단">오픈스트리트맵 재단</h2>
<ul>
<li>
<p><a id="wn823_34552"></a>
 오픈스트리트맵 재단에서 지난 1월에 승인된 2026년도 예산안을 <a href="https://osmfoundation.org/wiki/Board/Minutes/2026-01/2026_OSMF_budget">발표했습니다</a>. 올해 수입은 약 822,000파운드(약 16억 원), 지출은 약 933,000파운드(약 18억 원)로 예상됩니다. 여기에는 직원 및 계약직 인건비, 소액 보조금, 인프라 자금이 포함되어 있으며, 예산안은 연중 수정될 수 있습니다.</p>
</li>
<li>
<p><a id="wn823_34553"></a>
 오픈스트리트맵 재단에서 공개 이사회 회의 중 진행된 짧은 발표들을 <a href="https://osmfoundation.org/wiki/Monthly_Board_Meetings/Presentations">문서화했으며</a>, 2026년에 이러한 커뮤니티 발표를 부활시키는 방안을 검토하고 있습니다. 10분 동안 진행되는 이 발표를 통해 오픈스트리트맵 커뮤니티의 프로젝트와 활동을 깊이 있게 살펴볼 수 있습니다.</p>
</li>
</ul>
<h2 id="행사">행사</h2>
<ul>
<li>
<p><a id="wn823_34515"></a>
 Silvina Meritano와 Bastian Greshake Tzovaras가 코르도바에서 열린 중남미 자유 소프트웨어 설치 페스티벌에서 오픈스트리트맵에 대한 발표를 <a href="https://scholar.social/@gedankenstuecke/116470842976993935">진행했습니다</a> :ES-s:. 발표 슬라이드 및 자료는 온라인에서 <a href="https://talks.tzovar.as/2026-04-25-flisol/">확인 가능합니다</a> :ES-s:.</p>
</li>
<li>
<p><a id="wn823_34519"></a>
 독일 카를스루에(Karlsruhe)에서 열리는 오픈스트리트맵 해크 위크엔드(Hackweekend) 일정이 2026년 9월 26일부터 27일까지로 <a href="https://community.openstreetmap.org/t/hackweekend-in-karlsruhe-am-26-27-september-2026/143357">공지되었습니다</a> :DE-s:. 개발자와 기여자라면 이 행사에 <a href="https://wiki.openstreetmap.org/wiki/Karlsruhe_Hack_Weekend_September_2026">참여해</a> 오픈스트리트맵 관련 프로젝트를 함께 진행해 보세요.</p>
</li>
<li>
<p><a id="wn823_34521"></a>
 오픈스트리트맵과 관련된 연구 논문을 제출할 수 있는 OSM Science 2026의 논문 모집 기한이 <a href="https://community.openstreetmap.org/t/osm-science-2026/143356">연장되었습니다</a>. 이 컨퍼런스는 파리에서 열리는 State of the Map 2026의 일환으로 진행됩니다.</p>
</li>
<li>
<p><a id="wn823_34555"></a>
 위키데이터와 오픈스트리트맵 대만 커뮤니티가 대만 최대 오픈소스 컨퍼런스인 COSCUP에서 진행하는 &ldquo;State of the Map Taiwan 2026 / Wikidata Community Summit&rdquo; 트랙의 발표 제안을 <a href="https://diff.wikimedia.org/2026/04/29/wikidata-community-summit-2026-coscup-call-for-proposals/">받고 있습니다</a>. 오픈 데이터, 연결형 데이터, 오픈스트리트맵 등의 주제로 2026년 5월 9일까지 신청할 수 있습니다.</p>
</li>
</ul>
<h2 id="교육">교육</h2>
<ul>
<li>
<p><a id="wn823_34524"></a>
 IVIDES.org와 IVIDES DATA에서 오픈스트리트맵 강좌 내용을 영어와 스페인어로 업데이트하고 번역할 유급 작업자 2명을 모집하고 있습니다. 자세한 조건을 <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408582">확인하신 후</a> :EN-s:/:ES-s: 5월 8일 금요일(현지 시각)까지 지원서를 제출해 주세요.</p>
</li>
<li>
<p><a id="wn823_34538"></a>
 IVIDES DATA®에서 2026년도 오픈스트리트맵 워크숍 시리즈(포르투갈어로 진행)의 <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408597">참가 신청을 받고 있습니다</a> :PT-s: &gt; <a href="https://www-openstreetmap-org.translate.goog/user/Raquel%20Dezid%C3%A9rio%20Souto/diary/408597?_x_tr_sl=auto&amp;_x_tr_tl=KO">:KO-t:</a>. 총 5개 세션으로 구성된 이번 위크숍에서는 오픈스트리트맵 지도 제작, QGIS 플러그인, KoboToolbox를 활용한 웹 폼, uMap을 활용한 웹 지도 등 다양한 주제를 다룹니다. 이번 워크숍은 참가자들이 소규모 실습 프로젝트를 개발하는 데 필요한 도구를 제공하는 것에 초점을 맞추고 있습니다. 주최 측은 이러한 실습 위주의 방식을 통해 참가자들이 자유 소프트웨어 도구로 얻은 지식을 보다 잘 흡수할 수 있을 것으로 기대하고 있습니다.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-연구">오픈스트리트맵 연구</h2>
<ul>
<li><a id="wn823_34535"></a>
 HeiGIT에서 공간 기반 분석을 구현하고 기반 시설 모니터링을 개선하기 위해 오픈스트리트맵에서 추출한 도로망 데이터를 활용하여 고속도로 유지 보수를 위한 도로 균열 위치 자동 파악에 관한 연구를 <a href="https://heigit.org/new-paper-automated-road-crack-localization-for-spatially-guided-highway-maintenance/">발표했습니다</a>(<a href="https://www.openstreetmap.org/#map=6/51.33/10.45%29">https://www.openstreetmap.org/#map=6/51.33/10.45)</a>. Knoblauch, Ghamis, Zipf가 저술한 이 연구는 <em>Transactions in GIS30</em> 에 <a href="https://doi.org/10.1111/tgis.70258">게재되었습니다</a>.</li>
</ul>
<h2 id="지도">지도</h2>
<ul>
<li>
<p><a id="wn823_34556"></a>
 Christoph Hormann이 지도에 지물의 이름을 표시할 때 OpenStreetMap Carto에서 이름을 결정하는 방식을 변경하자고 <a href="https://github.com/openstreetmap-carto/openstreetmap-carto/issues/5216">제안했습니다</a>.</p>
</li>
<li>
<p><a id="wn823_34532"></a>
 독일 디지털 도서관(Deutsche Digitale Bibliothek)이  <a href="https://www.archivportal-d.de/content/ueber-uns">Archivportal-D</a>의 도서관 기록물과 연결된, 1945년 이후 독일에서 발생한 극우 극단주의 폭력을 다루는 <a href="https://www.archivportal-d.de/themenportale/rechte-gewalt">주제별</a> :DE-s: 웹 지도를 <a href="https://openbiblio.social/@archivportal/116475825682678225">발표했습니다</a>. 이 지도의 레이어는 시대에 따라 오픈스트리트맵 또는 오픈히스토리컬맵(OpenHistoricalMap)을 기반으로 합니다.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-활용-사례">오픈스트리트맵 활용 사례</h2>
<ul>
<li>
<p><a id="wn823_34534"></a>
 ^[1]^ Zoe Skyforest가 호주의 새로운 국민 스포츠로 떠오른 <a href="https://payphonetag.com">공중전화 태그</a>를 <em>Hackaday</em> 에 <a href="https://hackaday.com/2026/04/28/payphone-tag-is-australias-new-national-sport/">소개했습니다</a>. <a href="https://www.al3x.au/">Alex Allchin</a>이 개발한 이 게임은 플레이어가 공중전화로 특정 번호에 전화를 걸어 주변 지역을 점령하는 일종의 깃발 뺏기 게임입니다. 플레이어가 점령한 영역은 오픈스트리트맵 기반 웹 지도에서 실시간으로 확인할 수 있습니다. 지난 7일 동안 800명의 플레이어가 참여했으며, 지금까지 총 36,640번의 점령이 이루어졌습니다.</p>
</li>
<li>
<p><a id="wn823_34551"></a>
 Leonardo Texidó Quintana가 오픈스트리트맵 데이터를 활용하고 Organic Maps를 포크하여 쿠바의 <a href="https://www.youtube.com/watch?v=CLcUh1Hq_Fs">차량 호출</a> :ES-s: 앱(승객용 및 운전자용)을 <a href="https://dev.to/leonardo_tq_13f83601e8513/20000-taxi-rides-in-cuba-what-i-learned-building-on-organic-maps-3k9b">개발했습니다</a>. 이 앱은 연료 위기 속에서도 2만 건 이상의 실제 택시 운행을 성사시켰으며, 2GB 램이 탑재되고 2G 통신이 간헐적으로 끊기는 저사양 스마트폰에서도 작동합니다.</p>
</li>
</ul>
<h2 id="열린-데이터">열린 데이터</h2>
<ul>
<li>
<p><a id="wn823_34558"></a>
 새로운 개방형 데이터 집합(GOWIRES)은 전 세계 40만 개가 넘는 풍력 발전기 데이터를 <a href="https://www.nature.com/articles/s41597-026-07290-4">통합해</a> 과거와 미래의 풍력 자원 정보를 보강했습니다. 지리 데이터는 주로 오픈스트리트맵을 기반으로 하며, 국가별 등록부와 대조하는 과정을 거쳤습니다.</p>
</li>
<li>
<p><a id="wn823_34533"></a>
 OCHA 인도주의 데이터 센터에서 110개국의 하위 행정 경계를 담은 전 세계 데이터 집합을 <a href="https://data.humdata.org/m/dataset/cod-ab-global">공개했습니다</a>.</p>
</li>
</ul>
<h2 id="소프트웨어">소프트웨어</h2>
<ul>
<li>
<p><a id="wn823_34525"></a>
 최근 공개 Overpass 서버에서 발생한 문제에 대응하기 위해, Kai Johnson이 누구나 자신만의 Overpass 인스턴스를 실행핼 수 있도록 해 주는 새로운 Overpass용 Docker <a href="https://www.openstreetmap.org/user/Kai%20Johnson/diary/408583">컨테이너</a> 이미지를 <a href="https://community.openstreetmap.org/t/announcing-a-new-overpass-container-image/143376">공개했습니다</a>.</p>
</li>
<li>
<p><a id="wn823_34536"></a>
 HeiGIT에서 <code>api.openrouteservice.org</code> URL을 <code>api.heigit.org</code>로 대체한다고 <a href="https://ask.openrouteservice.org/t/deprecating-api-openrouteservice-org-in-favour-of-api-heigit-org/7912">발표했습니다</a>. 서비스는 기존과 동일하게 이용할 수 있지만, 이전 URL의 접속이 차단되는 2026년 8월 전까지 사용자는 자신의 애플리케이션을 새로운 URL에 맞게 수정해야 합니다.</p>
</li>
<li>
<p><a id="wn823_34527"></a>
 geoObserver에서 업로드한 이미지의 윤곽선을 인식해 오픈스트리트맵 도로망으로 채워주는 웹 앱, DrawonMaps를 <a href="https://geoobserver.de/2026/04/28/drawonmaps-osm-picturemap/">소개했습니다</a> :DE-s:.</p>
</li>
<li>
<p><a id="wn823_34548"></a>
 GéoDataMine에서 오픈스트리트맵의 주제별 데이터를 스프레드시트나 지리 파일 형태로 쉽게 <a href="https://geodatamine.fr/">추출할 수 있도록</a> :FR-s:&raquo;&gt;<a href="https://geodatamine-fr.translate.goog/?_x_tr_sl=auto&amp;_x_tr_tl=KO">:KO-t:</a> 지원합니다. 이 데이터는 매일 업데이트되어 CSV, GeoJSON, XLSX, Shapefile 포맷으로 제공됩니다. 국가 데이터 스키마가 존재하는 경우에는 그에 맞춰 호환되도록 구성되며, 그렇지 않은 경우에는 오픈스트리트맵 관례를 따릅니다.</p>
</li>
<li>
<p><a id="wn823_34516"></a>
 Ilya Zverev가 15년 동안 열려 있던 JOSM의 다중 계정 지원 관련 <a href="https://josm.openstreetmap.de/ticket/2710">티켓</a>이 &lsquo;수정하지 않음&rsquo; 상태로 닫혔다고 <a href="https://en.osm.town/@zverik/116473171306638653">언급했습니다</a>. 결과적으로 앞으로도 JOSM에서는 다중 사용자 계정을 기본적으로 지원하지 않을 예정입니다. 일부 사용자는 M!dgard가 *NIX 시스템용으로 <a href="https://www.openstreetmap.org/user/M!dgard/diary/401874">소개한</a> 것처럼 개인 스크립트를 사용해 이러한 한계를 우회하고 있습니다. 윈도우에서도 작동하는 다른 방법도 <a href="https://community.openstreetmap.org/t/mehrere-josm-profile/74386">존재합니다</a> :DE-s:.</p>
</li>
<li>
<p><a id="wn823_34509"></a>
 osm2pgsql 프로젝트 팀이 더 효율적인 저장 포맷을 구현해 <a href="https://github.com/osm2pgsql-dev/osm2pgsql">osm2pgsql</a>의 메모리와 디스크 사용량을 줄이는 것을 목표로 하는 Compact OpenStreetMap Data Archive 프로젝트(가칭)를 <a href="https://osm2pgsql.org/project-coda/">진행하기 위해</a> NGI0 Commons Fund로부터 지원금을 받았다고 <a href="https://osm2pgsql.org/news/2026/04/25/ngi0-grant-for-osm2pgsql.html">발표했습니다</a>.</p>
</li>
<li>
<p><a id="wn823_34514"></a>
 Alejandro Polanco가 <a href="https://open.substack.com/pub/alpoma/p/opengridworks-un-alucinante-mapa">이끄는</a> :ES-s:&raquo;&gt;<a href="https://open-substack-com.translate.goog/pub/alpoma/p/opengridworks-un-alucinante-mapa?_x_tr_sl=auto&amp;_x_tr_tl=KO">:KO-t:</a> <a href="https://opengridworks.com/power-plants?bubbleScale=0.65&amp;layers=tx%2Cdatacenters%2Chpoints%2CrowTx%2CrowSubs&amp;panel=closed">OpenGridWorks</a> 프로젝트는 에너지 기반 시설을 보여주며, 기준 지리공간 레이어로 CARTO와 오픈스트리트맵을 사용합니다. 이용할 수 있는 레이어로는 발전소, 송전선, 변전소, 가스관, 데이터 센터, 송전망 구축 계획, 해저 케이블 경로, 홍수 위험도가 있습니다.</p>
</li>
</ul>
<h2 id="프로그래밍">프로그래밍</h2>
<ul>
<li>
<p><a id="wn823_34541"></a>
 Candid Dauth가 데이터베이스와 렌더링을 분리하고 최신 osm2pgsql 기능을 지원하는 <code>openstreetmap-tile-server</code>의 새로운 <a href="https://github.com/FacilMap/openstreetmap-tile-server">포크</a> 버전을 <a href="https://www.openstreetmap.org/user/Candid%20Dauth/diary/408585">소개했습니다</a>. 이러한 방식은 점진적 업데이트를 바탕으로 더욱 유연하고 효율적인 타일 호스팅을 구현하는 것을 목표로 합니다.</p>
</li>
<li>
<p><a id="wn823_34526"></a>
 Evgeny Arbatov가 오픈스트리트맵 데이터를 활용해 특정 장소의 전반적인 분위기를 분석하는 파이프라인인 &lsquo;vibe mapping&rsquo;을 <a href="https://www.openstreetmap.org/user/Evgeny%20Arbatov/diary/408569">개발했습니다</a>. 이 파이프라인은 오픈스트리트맵 데이터 추출물에서 특정 영역을 H3 육각형으로 분할한 뒤, 각 육각형에 대한 집계 지표를 계산합니다. 이후 산출된 지표를 바탕으로 AI 모델에 해당 장소의 분위기를 묘사하는 짧은 한 문장을 생성하도록 요청합니다. 소스 코드는 Github에 <a href="https://github.com/evgeniyarbatov/vibe-mapping">공개되어 있습니다</a>.</p>
</li>
<li>
<p><a id="wn823_34540"></a>
 NieWnen이 osm2pgsql로 지역 데이터베이스를 최신 상태로 유지할 수 있도록 .poly 경계를 사용해 오픈스트리트맵 복제 파일을 필터링하는 스크립트를 <a href="https://www.openstreetmap.org/user/NieWnen/diary/408589">공개했습니다</a>. 이러한 방식은 Overpass의 대안이 되며, 더욱 유연한 자체 호스팅 데이터 처리를 가능하게 합니다. 소스 코드는 GitHub에 <a href="https://github.com/praszuk/osm-replication-osc-poly-filter">공개되어 있습니다</a>.</p>
</li>
<li>
<p><a id="wn823_34554"></a>
 Mark Litwintschik가 외부 API 없이 국가 코드와 가장 가까운 주소를 찾아주는 Overture Maps 기반의 역 지오코딩 프로토타입을 <a href="https://tech.marksblogg.com/reverse-geocoding-overture-maps.html">소개했습니다</a>. 이 기반 데이터 집합에는 오픈스트리트맵 데이터도 포함되어 있으며, 모든 데이터는 로컬 환경에서 처리됩니다.</p>
</li>
</ul>
<h2 id="출시">출시</h2>
<ul>
<li>
<p><a id="wn823_34557"></a>
 Nils Nolde가 다중 교통수단 경로 탐색, OSM XML 지원, 부가 메타데이터 등의 기능을 도입한 Valhalla 3.7.0을 <a href="https://github.com/valhalla/valhalla/releases/tag/3.7.0">출시했습니다</a>. 이번 버전에는 수많은 버그 수정과 경로 탐색 및 데이터 처리 구성 요소의 변경 사항도 포함되어 있습니다.</p>
</li>
<li>
<p><a id="wn823_34508"></a>
 <a href="https://route.crafter.seen.one/">Route-Crafter</a> 0.2.4 버전에서는 아주 긴 경로를 더 잘 처리하도록 기능을 <a href="https://github.com/seen-one/Route-Crafter/releases/tag/v0.2.4">개선했으며</a>, 모바일 UI 문제를 수정하고, 설정 변경 시 나타나는 경고문을 추가했습니다. 또한 출발지 설정 버튼 기능을 업데이트하고 경로 플레이어의 이동 선 시각화를 개선했습니다.</p>
</li>
<li>
<p><a id="wn823_34517"></a>
 Marcus Jaschen이 웹 브라우저나 서버에 경로를 저장하고 정리할 수 있는 <a href="https://bikerouter.de/">Bikerouter</a>의 새로운 경로 관리자를 <a href="https://www.marcusjaschen.de/en/blog/2026/bikerouter-route-manager/">발표했습니다</a>.</p>
</li>
</ul>
<h2 id="알고-계셨나요">알고 계셨나요?</h2>
<ul>
<li>
<p><a id="wn823_34560"></a>
 … 오픈스트리트맵 데이터를 <a href="https://www.bikemap.net">활용해</a> 지도와 경로 탐색 기능을 제공하는 Bikemap.net에서 전 세계의 자전거 경로를 계획할 수 있다는 사실을 알고 계셨나요?</p>
</li>
<li>
<p><a id="wn823_34550"></a>
 &hellip; Skaringa가 오픈스트리트맵 수로망 데이터를 활용해 중부 유럽의 하천 유역 지도를 <a href="https://www.openstreetmap.org/user/skaringa/diary/408596">개발했다는</a> :DE-s: 사실을 알고 계셨나요?</p>
</li>
</ul>
<h2 id="매체-속-오픈스트리트맵">매체 속 오픈스트리트맵</h2>
<ul>
<li>
<p><a id="wn823_34559"></a>
 온라인 자전거 경로 탐색기를 비교한 <a href="https://gpsradler.de/ratgeber/top-fahrrad-tourenplaner-web/">최근 글</a> :DE-s:에서 광범위한 경로 탐색 옵션과 오픈스트리트맵 기반 지도를 갖춘 강력하고 완전한 무료 도구로 Bikerouter(BRouter 기반)를 조명했습니다. Marcus Jaschen이 개발한 <a href="https://bikerouter.de">Bikerouter.de</a>는 정확한 경로 탐색을 위해 오픈스트리트맵 데이터를 <a href="https://gpsradler.de/praxistest/bikerouter-tourenplaner-test/">사용하며</a> :DE-s:, 고급 맞춤 설정 기능과 GPX 또는 GeoJSON 같은 내보내기 포맷을 제공합니다.</p>
</li>
<li>
<p><a id="wn823_34537"></a>
 Anna Biselli가 <em>netzpolitik.org</em> 에 상용 내비게이션 앱을 대체할 수 있는 개인정보 친화적인 대안을 <a href="https://netzpolitik.org/2026/wandern-radfahren-frei-und-dezentral-ins-gruene/">소개했습니다</a> :DE-s:&raquo;&gt;<a href="https://netzpolitik-org.translate.goog/2026/wandern-radfahren-frei-und-dezentral-ins-gruene?_x_tr_sl=auto&amp;_x_tr_tl=KO">:KO-t:</a>. 이 중에는 오픈스트리트맵을 기반으로 하는 앱도 여러 개 포함되어 있습니다. 해당 글에서는 분산형 접근 방식과 오프라인 사용을 주요 장점으로 꼽았습니다.</p>
</li>
<li>
<p><a id="wn823_34513"></a>
 Substack의 <em>The Rail Agenda</em> 에서 1960년대 Varsity Line의 <a href="https://en.wikipedia.org/wiki/Varsity_Line">폐선</a> 이후 오늘날 옥스퍼드와 케임브리지를 직접 연결하는 철도 노선이 없다는 점에 <a href="https://open.substack.com/pub/therailagenda/p/oxford-and-cambridge-to-get-direct">주목했습니다</a>. 제안된 이스트 웨스트 레일(East West Rail)이 구축되면 전체 구간에서 시간 당 4대의 열차가 운행되며 두 도시 간의 직통 철도가 복원됩니다. 이 게시물은 오픈스트리트맵 지도를 활용해 설명했으며 위키미디어 공용 데이터를 사용했습니다.</p>
</li>
<li>
<p><a id="wn823_34523"></a>
 Joe Fedewa가 오픈스트리트맵 개선에 기여한 사용자에게 포인트로 보상을 제공하는 <a href="https://streetcomplete.app/">StreetComplete</a>를 <a href="https://www.howtogeek.com/android-app-gives-you-points-for-fixing-your-local-open-source-map/">살펴보았습니다</a>. 이 개념은 지역 지도 데이터를 보완하고 수정하기 위한 추가적인 동기를 부여하기 위해 고안되었습니다.</p>
</li>
</ul>
<h2 id="기타-지리-관련-소식">기타 &lsquo;지리&rsquo; 관련 소식</h2>
<ul>
<li>
<p><a id="wn823_34512"></a>
 <em>Crust News</em> 에서 Apple Maps가 레바논 전역의 수많은 마을과 도시 이름을 더 이상 표시하지 않는다는 사실을 <a href="https://open.substack.com/pub/crustiandaily/p/apple-maps-has-removed-place-names">확인했습니다</a>. 이러한 지명 삭제는 이스라엘의 침공과 공격을 받고 있는 지역에만 국한되지 않고 전국적으로 적용되었습니다. 베이루트(Beirut), 티레(Tyre), 시돈(Sidon) 등 소수 대도시만 이름이 남아 있습니다.</p>
</li>
<li>
<p><a id="wn823_34531"></a>
 2026년 11월 11일부터 11월 13일까지 포르투(Porto)에서 제17회 Iberian Conference on Spatial Data Infrastructures (JIIDE)를 <a href="https://www.dgterritorio.gov.pt/jiide2026/Default.aspx">개최합니다</a> :PT-s:. &lsquo;변화하는 세계의 공간 데이터 인프라&rsquo;를 주제로 열리는 본 행사에서는 2026년 6월 10일까지 논문을 공개 <a href="https://www.dgterritorio.gov.pt/apresentacao-de-resumos-prazo-10-de-junho">모집합니다</a> :PT-s:.</p>
</li>
<li>
<p><a id="wn823_34501"></a>
 Bathymetric Data Viewer는 NOAA(미국 국립해양대기청)의 National Centers for Environmental Information에 <a href="https://www.ncei.noaa.gov/news/explore-sea-floor-ncei-modernized-portal">보관된</a> 수심 데이터 및 수치 표고 모델을 <a href="https://www.ncei.noaa.gov/maps/bathymetry/?xmax=4.122&amp;xmin=-8.189&amp;ymax=55.123&amp;ymin=42.326">검색하고</a> 찾을 수 있는 동적 지도 서비스입니다. IHO Data Centre for Digital Bathymetry의 레이어가 포함된 지리 뷰어(geoviewer)도 <a href="https://www.ncei.noaa.gov/maps/iho_dcdb/">이용할 수 있습니다</a>.</p>
</li>
<li>
<p><a id="wn823_34507"></a>
 Jesper Zedlitz가 유럽 연합 지침이 도입된 지 2년이 지난 현재 독일의 고가치 데이터 집합 현황을 <a href="https://open-north.de/blog/2026-04-24_hvd/">분석해</a> :DE-s:&raquo;&gt;<a href="https://open--north-de.translate.goog/blog/2026-04-24_hvd/?_x_tr_sl=de&amp;_x_tr_tl=en&amp;_x_tr_hl=ko">:KO-t:</a> 연방주 간의 큰 격차를 드러냈습니다. 또한 데이터 범주화 과정에서의 공백, 일관성 없는 구현, 미해결 문제를 지적했습니다.</p>
</li>
<li>
<p><a id="wn823_34522"></a>
 Gabrielle Bruney가 <em>Places Journal</em> 에 <a href="https://placesjournal.org/article/the-disappearance-of-the-public-bench/">게재한</a> 최근 기사에서 공공 벤치의 역할과 감소 추세를 탐구하며 벤치의 사회적, 공간적 중요성을 강조했습니다. 이 기사는 <em>Places Journal</em> 과 Columbia Journalism School의 예술 및 문화 프로그램이 협력해 연재하는 『Writing the City』의 최신 글입니다. 오픈스트리트맵의 관점에서 이 기사는 <code>amenity=bench</code>와 같은 지물을 상세하게 <a href="https://wiki.openstreetmap.org/wiki/Tag:amenity%3Dbench">매핑하는</a> 작업의 중요성을 보여줍니다. <a href="https://wiki.openstreetmap.org/wiki/Hostile_architecture#hostile_benches">적대적 건축물</a>의 한 형태인 적대적 벤치를 나타내기 위한 <a href="https://wiki.openstreetmap.org/wiki/Proposal:Hostile_Architecture">제안</a>도 2021년부터 현재까지 지속적으로 논의되고 있습니다.</p>
</li>
</ul>
<h2 id="다가오는-행사">다가오는 행사</h2>
<table>
	<thead>
			<tr>
					<th>국가</th>
					<th>장소</th>
					<th>venue</th>
					<th>명칭</th>
					<th>일시</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Essen</td>
					<td>Linuxhotel Essen</td>
					<td>FOSSGIS-OSM-Communitytreffen im Linuxhotel <a href="https://osmcal.org/event/4121/">:osmcalpic:</a></td>
					<td>2026-04-30 - 2026-05-03</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://www.weeklyosm.eu/wp-content/uploads/2017/11/cn.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>大理市</td>
					<td>三月街集市</td>
					<td>大理三月民族节 <a href="https://osmcal.org/event/4751/">:osmcalpic:</a></td>
					<td>2026-05-01 - 2026-05-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Weil der Stadt</td>
					<td>MA1PPING <a href="https://osmcal.org/event/4500/">:osmcalpic:</a></td>
					<td>2026-05-01</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSMF Engineering Working Group meeting <a href="https://osmcal.org/event/4765/">:osmcalpic:</a></td>
					<td>2026-05-01</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Augsburg</td>
					<td>Augsburger Linux-Infotag 2026</td>
					<td>Workshop: JOSM - Java OpenStreetMap Editor - Eine Einführung <a href="https://osmcal.org/event/4700/">:osmcalpic:</a></td>
					<td>2026-05-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>नई दिल्ली</td>
					<td>Jitsi Meet (online)</td>
					<td>OSM India - Monthly Online Mapathon <a href="https://osmcal.org/event/4116/">:osmcalpic:</a></td>
					<td>2026-05-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Sovigliana-Vinci</td>
					<td>Mappando si Vinci! - 2 Maggio 2026 <a href="https://osmcal.org/event/4678/">:osmcalpic:</a></td>
					<td>2026-05-02 - 2026-06-02</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Braunschweig</td>
					<td>Stratum 0</td>
					<td>Braunschweiger Mappertreffen im Stratum 0 Hackerspace <a href="https://osmcal.org/event/4633/">:osmcalpic:</a></td>
					<td>2026-05-05</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Salzburg</td>
					<td>Bewohnerservice Elisabeth-Vorstadt</td>
					<td>OSM-Treffpunkt <a href="https://osmcal.org/event/4467/">:osmcalpic:</a></td>
					<td>2026-05-05</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London Mapathon (with Training) Beginner Friendly (Online) [eng] <a href="https://osmcal.org/event/4233/">:osmcalpic:</a></td>
					<td>2026-05-05</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>iD Community Chat <a href="https://osmcal.org/event/4733/">:osmcalpic:</a></td>
					<td>2026-05-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stuttgart</td>
					<td>Stuttgart</td>
					<td>Stuttgarter OpenStreetMap-Treffen <a href="https://osmcal.org/event/4679/">:osmcalpic:</a></td>
					<td>2026-05-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/us.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Richmond</td>
					<td>Shockoe Bottom</td>
					<td>Surveillance mapping with MapRVA <a href="https://osmcal.org/event/4682/">:osmcalpic:</a></td>
					<td>2026-05-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/03/br.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>[online]</td>
					<td>🇧🇷 Capacitação OSM 2026 - IVIDES DATA ® - Editor iD - Parte I <a href="https://osmcal.org/event/4740/">:osmcalpic:</a></td>
					<td>2026-05-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>online</td>
					<td>SOSM Association Annual Meeting <a href="https://osmcal.org/event/4556/">:osmcalpic:</a></td>
					<td>2026-05-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/07/dk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>København</td>
					<td>Cafe Bevar&rsquo;s</td>
					<td>OSMmapperCPH <a href="https://osmcal.org/event/4638/">:osmcalpic:</a></td>
					<td>2026-05-10</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Delhi</td>
					<td>Kori&rsquo;s, Humayunpur, Delhi</td>
					<td>OSM Delhi Mapping Party No.29 (South Zone) <a href="https://osmcal.org/event/4350/">:osmcalpic:</a></td>
					<td>2026-05-10</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4297/">:osmcalpic:</a></td>
					<td>2026-05-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Zürich</td>
					<td>Bitwäscherei Zürich</td>
					<td>187. OSM-Stammtisch Zürich <a href="https://osmcal.org/event/4741/">:osmcalpic:</a></td>
					<td>2026-05-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/tw.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>臺北市</td>
					<td>MozSpace Taipei</td>
					<td>OpenStreetMap x Wikidata Taipei #88 <a href="https://osmcal.org/event/4324/">:osmcalpic:</a></td>
					<td>2026-05-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Magdeburg</td>
					<td>Netz39 e.V. , Leibnizstraße 32,  39104 Magdeburg</td>
					<td>1. OSM Stammtisch Magdeburg <a href="https://osmcal.org/event/4734/">:osmcalpic:</a></td>
					<td>2026-05-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hamburg</td>
					<td>Voraussichtlich: &ldquo;Variable&rdquo;, Karolinenstraße 23</td>
					<td>Hamburger Mappertreffen <a href="https://osmcal.org/event/4694/">:osmcalpic:</a></td>
					<td>2026-05-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>temporärhaus</td>
					<td>OSM-Stammtisch Ulm/Neu-Ulm <a href="https://osmcal.org/event/4721/">:osmcalpic:</a></td>
					<td>2026-05-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Maison des associations de Bayonne - salle Valmont</td>
					<td>Rencontre Mapadour <a href="https://osmcal.org/event/4758/">:osmcalpic:</a></td>
					<td>2026-05-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2021/09/cz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Praha</td>
					<td>Seznam.cz</td>
					<td>Pražský mapathon s Lékaři bez hranic v Seznam.cz <a href="https://osmcal.org/event/4720/">:osmcalpic:</a></td>
					<td>2026-05-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2015/07/nl.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Amsterdam</td>
					<td>TomTom HQ</td>
					<td>2026 Spring End Maptime <a href="https://osmcal.org/event/4703/">:osmcalpic:</a></td>
					<td>2026-05-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>München</td>
					<td>Echardinger Einkehr</td>
					<td>Münchner OSM-Treffen <a href="https://osmcal.org/event/4342/">:osmcalpic:</a></td>
					<td>2026-05-13</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Mapaton - Marsh <a href="https://osmcal.org/event/4729/">:osmcalpic:</a></td>
					<td>2026-05-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/06/sk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Žilina</td>
					<td>Fakulta riadenia a informatiky UNIZA</td>
					<td>Missing Maps mapathon Žilina #22 <a href="https://osmcal.org/event/4762/">:osmcalpic:</a></td>
					<td>2026-05-14</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Acireale</td>
					<td>Mappiamo le Aci <a href="https://osmcal.org/event/4757/">:osmcalpic:</a></td>
					<td>2026-05-16 - 2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Chennai Corporation</td>
					<td>Hotel Nithya Amirtham, Mylapore Market, Chennai</td>
					<td>Mapping at Mylapore Market, Chennai <a href="https://osmcal.org/event/4743/">:osmcalpic:</a></td>
					<td>2026-05-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bologna</td>
					<td>aula 0.6, DICAM, Unibo, Viale del Risorgimento 2</td>
					<td>Unibo Mapathon OpenStreetMap 2026-05 <a href="https://osmcal.org/event/4756/">:osmcalpic:</a></td>
					<td>2026-05-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt=""
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Mannheim</td>
					<td>RaumZeitLabor, Mannheim</td>
					<td>Rhein-Neckar OpenstreetMap Treffen <a href="https://osmcal.org/event/4742/">:osmcalpic:</a></td>
					<td>2026-05-18</td>
			</tr>
	</tbody>
</table>
<p><em>이 주간OSM은 다음 사람들이 <a href="https://umap.openstreetmap.fr/de/map/weeklyosm-is-currently-produced-in_56718#2/8.4/108.3">제작했습니다</a>. <a href="https://www.openstreetmap.org/user/Nakaner">Nakaner</a>, <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Raquel%20Dezid%C3%A9rio%20Souto">Raquel IVIDES DATA</a>, <a href="https://www.openstreetmap.org/user/Strubbl">Strubbl</a>, Andrew Davidson, <a href="https://www.openstreetmap.org/user/chiho_kang">chiho_kang</a>, <a href="https://www.osm.org/user/mcliquid">mcliquid</a>.</em></p>
]]></content:encoded>
			</item>
			<item>
				<title>주간 OSM 815</title>
				<link>https://hugo.weeklyosm.eu/ko/archives/0815/</link>
				<pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/archives/0815/</guid>
				<description><![CDATA[<img src="https://weeklyosm.eu/wp-content/uploads/2026/03/815.jpg" alt="주간 OSM 815" /> 2026.02.26.-2026.03.04.
주간OSM 내부 소식 이제 안드로이드 오픈스트리트맵 편집기 StreetComplete에서 주간OSM RSS 피드 알림을 받아볼 수 있게 되었습니다. 특정 유형의 메시지를 비활성화할 수 있는 설정도 같이 추가되었으며, 통계 갱신이 제대로 되지 않는 문제까지 수정되었습니다. 지도 제작 James Wheare가 wetland=tidalflat(갯벌) 태그의 정의를 명확히 할 필요가 있다고 말하면서, 오픈스트리트맵 위키에 토론을 열었습니다. 지도 제작 캠페인 ^[1]^ 오픈스트리트맵 이탈리아 커뮤니티에서 진행하는 이달의 프로젝트를 모니터링하기 위해 Daniele이 위키미디어 클라우드 서비스 플랫폼에 Podoma 인스턴스를 설치했다고 밝혔습니다. :IT-s:
오픈스트리트맵 이탈리아 커뮤니티에서 진행하는 이달의 프로젝트가 2월에도 성공적으로 끝났습니다. 모든 참여자 분들 덕분에 100,000개에 달하는 가로등이 오픈스트리트맵에 추가되었으며, 지지대의 유형, 조명의 종류 및 방향을 비롯한 여러 세부 정보까지 채울 수 있었습니다. :IT-s:
]]></description>
				<content:encoded><![CDATA[<p><img src="https://weeklyosm.eu/wp-content/uploads/2026/03/815.jpg" alt="주간 OSM 815" /></p> <p>2026.02.26.-2026.03.04.</p>
<h2 id="주간osm-내부-소식">주간OSM 내부 소식</h2>
<ul>
<li>이제 안드로이드 오픈스트리트맵 편집기 StreetComplete에서 주간OSM <a href="https://wiki.openstreetmap.org/wiki/WeeklyOSM#RSS_Feed">RSS 피드</a> 알림을 <a href="https://github.com/streetcomplete/StreetComplete/pull/6728">받아볼 수 있게 되었습니다</a>. 특정 유형의 메시지를 비활성화할 수 있는 설정도 같이 추가되었으며, 통계 갱신이 제대로 되지 않는 문제까지 수정되었습니다.</li>
</ul>
<h2 id="지도-제작">지도 제작</h2>
<ul>
<li>James Wheare가 <code>wetland=tidalflat</code>(갯벌) 태그의 정의를 명확히 할 필요가 있다고 말하면서, 오픈스트리트맵 위키에 토론을 <a href="https://www.openstreetmap.org/user/jwheare/diary/408308">열었습니다</a>.</li>
</ul>
<h2 id="지도-제작-캠페인">지도 제작 캠페인</h2>
<ul>
<li>
<p>^[1]^ 오픈스트리트맵 이탈리아 커뮤니티에서 진행하는 <a href="https://wiki.openstreetmap.org/wiki/IT:Italia/Progetto_del_Mese">이달의 프로젝트</a>를 모니터링하기 위해 Daniele이 <a href="https://wikitech.wikimedia.org/wiki/Help:Cloud_Services_introduction">위키미디어 클라우드 서비스</a> 플랫폼에 <a href="https://wiki.openstreetmap.org/wiki/Podoma">Podoma</a> 인스턴스를 설치했다고 <a href="https://community.openstreetmap.org/t/dashboard-podoma-per-il-progetto-del-mese/141779">밝혔습니다</a>. :IT-s:</p>
</li>
<li>
<p>오픈스트리트맵 이탈리아 커뮤니티에서 진행하는 <a href="https://community.openstreetmap.org/t/progetto-del-mese-febbraio-2026-lampioni/141180/61">이달의 프로젝트</a>가 2월에도 성공적으로 끝났습니다. 모든 참여자 분들 덕분에 100,000개에 달하는 가로등이 오픈스트리트맵에 추가되었으며, 지지대의 유형, 조명의 종류 및 방향을 비롯한 여러 세부 정보까지 채울 수 있었습니다. :IT-s:</p>
</li>
</ul>
<h2 id="커뮤니티">커뮤니티</h2>
<ul>
<li>
<p>OpenCage에서 오픈스트리트맵 데이터 내에서 지형 공간 패턴을 검색하는 도구 SPOT을 개발한 DW Innovation을 <a href="https://blog.opencagedata.com/post/openstreetmap-interview-dwinnovation">인터뷰했습니다</a>. 인터뷰를 통해 프로젝트를 시작하게 된 계기, SPOT을 개발하면서 맞닥뜨린 기술적 장애물, SPOT 출시 후 깨닫게 된 사실 등을 엿볼 수 있었습니다.</p>
</li>
<li>
<p>프랑스 범부처 디지털 기술 조정실(Direction interministérielle du numérique)에서 Christian Quest과 인터뷰를 <a href="https://www.numerique.gouv.fr/sinformer/blog/la-fabrique-du-libre-panoramax-de-lutopie-a-linfrastructure-publique/">진행했습니다</a>. Christian은 파노라맥스(Panoramax) 프로젝트의 기원과 초기 개발 과정, 활발한 기여자 공동체를 구축함에 있어서 초기에 해결해야 했던 문제, 향후 몇 년 동안 직면할 수 있는 장애물 등을 인터뷰에서 이야기했습니다. :FR-s:</p>
</li>
<li>
<p>MapRVA에서 미국 버지니아주 리치몬드 지역의 위치 태그가 붙은 과거 사진을 자동으로 공유하는 마스토돈 계정, The Yesterdays Bot을 <a href="https://en.osm.town/@yesterdays_bot">운영하기 시작했습니다</a>. The Yesterdays Bot을 통해 리치몬드의 과거 모습을 생생하게 엿볼 수 있습니다.</p>
</li>
</ul>
<h2 id="오픈스트리트맵-재단">오픈스트리트맵 재단</h2>
<ul>
<li>오버추어 지도 재단(Overture Maps Foundation)에서 개발한 전세계 개체 기준계(Global Entity Reference System, GERS)을 표준화하자는 공개 지리공간 컨소시엄(Open Geospatial Consortium, OGC)의 제안에 오픈스트리트맵 재단 이사회가 <a href="https://en.osm.town/@openstreetmap/116165330892920654">공식적으로 의견을 제출했습니다</a>. 오픈스트리트맵 재단은 전 세계적으로 상호 운용 가능한 지리적 식별 체계라는 개념에는 반대하지 않는다는 점을 분명히 했으나, 지리적 실체를 권위 있는 단일한 출처로 환원할 수는 없다는 사실을 OGC가 인식할 것을 촉구했습니다. 또한 지리적 지식은 주요 기술 기업의 데이터 센터 내에서뿐만 아니라 전 세계의 거리, 이웃, 공동체를 지도화하는 자원봉사자들의 분산된 노력을 통해서도 생성된다고 말하면서, OGC의 승인을 구하는 모든 표준은 중앙 집중식이든 커뮤니티 중심이든 상관없이 지리공간 데이터라면 전부 수용할 수 있을 만큼 포괄적이어야 한다고 역설했습니다.</li>
</ul>
<h2 id="지도">지도</h2>
<ul>
<li>OpenStreetMap Americana의 다국어 지원이 <a href="https://community.openstreetmap.org/t/osm-americana-your-local-language-companion/141757">개선되었습니다</a>. 이제 각 언어의 방언을 지원하며, 더 많은 장소에 이중 언어 이름표를 붙일 수 있게 되었습니다. 또한 <a href="https://github.com/osm-americana/diplomat/">Diplomat</a>을 통해 OpenStreetMap Americana와 같이 현지화된 이름표를 임의의 MapLibre 지도에 적용할 수 있게 되었습니다.</li>
</ul>
<h2 id="소프트웨어">소프트웨어</h2>
<ul>
<li>
<p>GanderPL가 <a href="https://github.com/openstreetmap/id-tagging-schema">iD 태그 스키마</a>를 활용해 OSM 태그 체계를 불러오는 <a href="https://en.wikipedia.org/wiki/Model_Context_Protocol">MCP</a> 서버를 <a href="https://www.openstreetmap.org/user/GanderPL/diary/408286">개발했습니다</a>.</p>
</li>
<li>
<p>Conveyal이 웹 브라우저에서 오픈스트리트맵 PBF 데이터를 읽고, 질의하고, 병합하고, 변환하는 조립형(composable) 라이브러리 모음, <a href="https://github.com/conveyal/osmix">Osmix</a>를 <a href="https://medium.com/conveyal-blog/introducing-osmix-365c4b4332ef">개발했습니다</a>.</p>
</li>
<li>
<p>Sarath Sabarish가 보행 적합도를 평가하는 도구, SafeStreets가 오픈스트리트맵 데이터, 노미나팀(지오코딩용), Overpass API(보행자 이용시설 조회용)를 결합해서 어떻게 15분 도시 점수를 산출하는지 <a href="https://www.openstreetmap.org/user/sarath%20sabarish/diary/408305">설명했습니다</a>. Sarath는 태국 치앙마이의 사례를 통해 <code>highway=crossing</code>(횡단보도) 태그가 누락되면 횡단보도 점수가 거의 0에 가까워지는 것을 보여주면서, 동남아시아 매퍼들에게 보도 및 횡단보도 태그를 개선할 것을 촉구했습니다.</p>
</li>
</ul>
<h2 id="프로그래밍">프로그래밍</h2>
<ul>
<li>
<p>Pascal Neis가 MS 코파일럿, OpenAI 코덱스, 앤트로픽 클로드의 성능을 비교한 결과 및 후기를 블로그에 <a href="https://neis-one.org/2026/03/flappy-birds-coding-assistants">올렸습니다</a>. Pascal은 AI 코딩 어시스턴트의 성능을 테스트해 보기 위해 플래피 버드 개발을 간단하게 시켜 본 뒤, 각종 WebGIS 코딩 작업을 수행하게 해 보았습니다. 그러면서 다음 학기에는 학생들과 같이 바이브 코딩을 시도해 볼 것이라면서, 어떻게 하면 인공지능에 과도하게 의존하지 않고 교육에 바이브 코딩을 접목할 수 있을지 고민하고 있다고 밝혔습니다.</p>
</li>
<li>
<p>HeiGIT에서 거리 사진과 심층 학습 기법을 결합해 기존 데이터 집합에서 누락되곤 하는 주요 기반시설을 찾고 지도화하는 방법을 <a href="https://heigit.org/how-street-level-imagery-and-deep-learning-are-helping-map-global-infrastructure">설명했습니다</a>. 이 방법론은 노면 분류 및 폐기물 감지부터 보도 폭 측정, 날씨에 따른 경로 설정에 이르기까지 다양한 분야에서 활용될 수 있습니다.</p>
</li>
</ul>
<h2 id="매체-속-오픈스트리트맵">매체 속 오픈스트리트맵</h2>
<ul>
<li>FOSDEM 2026에서 HOT의 수석 기술 파트너십 매니저 Petya Kangalova가 HOT에서 어떻게 오픈스트리트맵 환경을 기반으로 종합적인 기술 스택을 구축해 현지 공동체에서 주변 환경을 지도화하고, 재난 대응 노력을 강화하며, 전 세계의 인도주의 활동을 지원할 수 있었는지에 대해 <a href="https://lwn.net/Articles/1057691/">발표했습니다</a>.</li>
</ul>
<h2 id="기타-지리-관련-소식">기타 &lsquo;지리&rsquo; 관련 소식</h2>
<ul>
<li>
<p>NASA와 <a href="https://dev.global/">DevGlobal</a>에서 산불, 홍수, 산사태 등 재난 상황에 공동으로 대응할 때 정보를 효율적으로 전달할 수 있는 <a href="https://nasalifelines.org/data-studios/">Lifelines Data Studios</a>를 소개하는 온라인 강연을 <a href="https://www.timeanddate.com/worldclock/fixedtime.html?iso=20260311T1500&amp;msg=Event">3월 12일 자정(한국 시각)</a>부터 1시간 동안 진행합니다. 참가 신청은 <a href="https://nasalifelines.org/community-connect-sign-up/">여기</a>에서 하실 수 있습니다.</p>
</li>
<li>
<p>Chromy가 선박의 위치를 실시간으로 모니터링하는 웹 지도 사이트, <a href="https://atlas.flexport.com/">Flexport Atlas</a>를 <a href="https://news.ycombinator.com/item?id=47205637">소개했습니다</a>. Flexport Atlas는 오픈스트리트맵 데이터를 부분적으로 활용해 화물선, 항구, 항공기를 추적하며, 정확한 선박의 상태(계류 중, 정박 중, 이동 중) 및 항구 체류 시간을 2시간마다 갱신해 보여줍니다.</p>
</li>
</ul>
<h2 id="다가오는-행사">다가오는 행사</h2>
<ul>
<li>
<table>
	<thead>
			<tr>
					<th>국가</th>
					<th>장소</th>
					<th>venue</th>
					<th>명칭</th>
					<th>일시</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/2024/08/bg.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>София</td>
					<td>Rectorate of Sofia University St. Kliment of Ohrid</td>
					<td>FOSS4G:BG Open GIS Conference 2026 <a href="https://osmcal.org/event/4550/">:osmcalpic:</a></td>
					<td>2026-03-06 - 2026-03-07</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>OSMF Engineering Working Group meeting <a href="https://osmcal.org/event/4541/">:osmcalpic:</a></td>
					<td>2026-03-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2017/05/al.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Tiranë</td>
					<td>Destil Creative Hub Tirana</td>
					<td>OpenStreetMap Community Meetup - Tirana <a href="https://osmcal.org/event/4596/">:osmcalpic:</a></td>
					<td>2026-03-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Gent</td>
					<td>Wijgaard</td>
					<td>OpenStreetMap meetup in Gent - Pre-VLA-congres editie <a href="https://osmcal.org/event/4520/">:osmcalpic:</a></td>
					<td>2026-03-06</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Hogeschool Odissee Hospitaalstraat 23 Sint-Niklaas</td>
					<td>Vereniging Leraars Aardrijkskunde (VLA) conference 2026 <a href="https://osmcal.org/event/4522/">:osmcalpic:</a></td>
					<td>2026-03-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2017/06/au.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Perth</td>
					<td>Espresso Perk U Later</td>
					<td>Social Mapping Sunday: Moort-ak Waadiny / Wellington Square Perth <a href="https://osmcal.org/event/4539/">:osmcalpic:</a></td>
					<td>2026-03-07</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2017/06/au.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Perth</td>
					<td>Espresso Perk U Later</td>
					<td>Social Mapping Sunday: Moort-ak Waadiny / Wellington Square Perth <a href="https://osmcal.org/event/4540/">:osmcalpic:</a></td>
					<td>2026-03-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/07/dk.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>København</td>
					<td>Cafe Bevar&rsquo;s</td>
					<td><del>OSMmapperCPH</del> <a href="https://osmcal.org/event/4479/">:osmcalpic:</a></td>
					<td>2026-03-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/in.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Delhi</td>
					<td>Books and Beans Café, Mayur Vihar Phase 1</td>
					<td>OSM Delhi Mapping Party No.27 (East Zone) <a href="https://osmcal.org/event/4348/">:osmcalpic:</a></td>
					<td>2026-03-08</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/ca.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>London</td>
					<td>Social Sciences Centre - Western University</td>
					<td>Friends of MSF UWO Mapathon <a href="https://osmcal.org/event/4517/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4293/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2021/09/cz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Brno</td>
					<td>Geografický ústav, PřF MUNI, Brno</td>
					<td>Březnový brněnský Missing Maps Mapathon na Geografickém ústavu <a href="https://osmcal.org/event/4512/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Grenoble</td>
					<td>La Turbine Coop</td>
					<td>Découverte d&rsquo;OpenStreetMap <a href="https://osmcal.org/event/4563/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/tw.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>臺北市</td>
					<td>MozSpace Taipei</td>
					<td>OpenStreetMap x Wikidata Taipei #86 <a href="https://osmcal.org/event/4322/">:osmcalpic:</a></td>
					<td>2026-03-09</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Hamburg</td>
					<td>Voraussichtlich: &ldquo;Variable&rdquo;, Karolinenstraße 23</td>
					<td>Hamburger Mappertreffen <a href="https://osmcal.org/event/4399/">:osmcalpic:</a></td>
					<td>2026-03-10</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://www.weeklyosm.eu/wp-content/uploads/2018/11/ie.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Cork</td>
					<td>Logitech, Cork, Ireland</td>
					<td><del>Logitech Missing Maps - Office Mapathon</del> <a href="https://osmcal.org/event/4510/">:osmcalpic:</a></td>
					<td>2026-03-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/us.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Reston</td>
					<td>George Mason University, HUB VIP 3</td>
					<td>The GAIN Mapathon <a href="https://osmcal.org/event/4531/">:osmcalpic:</a></td>
					<td>2026-03-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Zürich</td>
					<td>Bitwäscherei Zürich</td>
					<td>185. OSM-Stammtisch Zürich <a href="https://osmcal.org/event/4450/">:osmcalpic:</a></td>
					<td>2026-03-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/ch.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Zürich</td>
					<td>Schweizerisches Rotes Kreuz</td>
					<td>Missing Maps Zürich Mapathon <a href="https://osmcal.org/event/4558/">:osmcalpic:</a></td>
					<td>2026-03-11</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/it.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Milano</td>
					<td>Building 3A Ground Floor - Politecnico di Milano</td>
					<td>PoliMappers Maptedì <a href="https://osmcal.org/event/4599/">:osmcalpic:</a></td>
					<td>2026-03-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Berlin</td>
					<td>Dieselhaus, Forum a. d. Museumsinsel 10</td>
					<td>213. OSM-Stammtisch Berlin-Brandenburg <a href="https://osmcal.org/event/4600/">:osmcalpic:</a></td>
					<td>2026-03-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>München</td>
					<td>WikiMUC</td>
					<td>Münchner OSM-Treffen <a href="https://osmcal.org/event/4343/">:osmcalpic:</a></td>
					<td>2026-03-12</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Magrathea Laboratories Chaos Computer Club Fulda</td>
					<td>OSM-Tools: Wenn die Welt zur Spielwiese wird <a href="https://osmcal.org/event/4598/">:osmcalpic:</a></td>
					<td>2026-03-13</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/05/be.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Leuven</td>
					<td>Romaanse Poort</td>
					<td>Camera&rsquo;s in kaart brengen <a href="https://osmcal.org/event/4549/">:osmcalpic:</a></td>
					<td>2026-03-14</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps London: (Online) Mid-Month Mapathon [eng] <a href="https://osmcal.org/event/4243/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Lyon</td>
					<td>Tubà</td>
					<td>Réunion du groupe local de Lyon <a href="https://osmcal.org/event/4305/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Bonn</td>
					<td>Dotty&rsquo;s</td>
					<td>198. OSM-Stammtisch Bonn <a href="https://osmcal.org/event/4354/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>Online</td>
					<td>Lüneburger Mappertreffen (online) <a href="https://osmcal.org/event/4369/">:osmcalpic:</a></td>
					<td>2026-03-17</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/fr.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td>MJC de Vienne</td>
					<td>Réunion des contributeurs de Vienne (38) <a href="https://osmcal.org/event/4562/">:osmcalpic:</a></td>
					<td>2026-03-18</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Online Mapathon - Ärzte ohne Grenzen <a href="https://osmcal.org/event/4513/">:osmcalpic:</a></td>
					<td>2026-03-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/02/at.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Stainach-Pürgg</td>
					<td>Online</td>
					<td>20. Österreichischer OSM-Stammtisch (online) <a href="https://osmcal.org/event/4438/">:osmcalpic:</a></td>
					<td>2026-03-18</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Heidelberg</td>
					<td>DEZERNAT#16</td>
					<td>Rhein-Neckar OSM Treffen // Intro iD-Editor <a href="https://osmcal.org/event/4509/">:osmcalpic:</a></td>
					<td>2026-03-19</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://weeklyosm.eu/wp-content/uploads/sites/4/2021/09/cz.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td>Olomouc</td>
					<td>Přírodovědecká fakulta Univerzity Palackého</td>
					<td>Missing Maps Day Olomouc 2026 <a href="https://osmcal.org/event/4545/">:osmcalpic:</a></td>
					<td>2026-03-21</td>
			</tr>
			<tr>
					<td><figure class="figure_figure figure_external figure_svg image-scalable">
  <picture>

    
      
        
        
        
        
        
        
    <img
      loading="lazy"
      decoding="async"
      alt="flag"
      
        class="image_figure image_external image_svg image_unprocessed"
        src="https://blog.openstreetmap.de/wp-uploads/2016/01/de.svg"
      
      
    />

  </picture>
</figure>



</td>
					<td></td>
					<td></td>
					<td>Frühlingsmapping 2026 <a href="https://osmcal.org/event/4542/">:osmcalpic:</a></td>
					<td>2026-03-22</td>
			</tr>
			<tr>
					<td></td>
					<td></td>
					<td></td>
					<td>Missing Maps : Mapathon en ligne - CartONG [fr] <a href="https://osmcal.org/event/4294/">:osmcalpic:</a></td>
					<td>2026-03-23</td>
			</tr>
	</tbody>
</table>
</li>
</ul>
]]></content:encoded>
			</item>
			<item>
				<title>개인정보 보호정책</title>
				<link>https://hugo.weeklyosm.eu/ko/privacy-policy/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/privacy-policy/</guid>
				<description><![CDATA[ We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).
]]></description>
				<content:encoded><![CDATA[<p></p> <p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<h2 id="1-definitions"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM<br>
c/o FOSSGIS e.V.<br>
Bundesallee 23<br>
10717 Berlin</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a><br>
Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.## Angaben gemäß § 5 DDG</p>
<h1 id="privacy-policy"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-1"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-1"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-1"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-1"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-1"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-1"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-1"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-1"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-1"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-1"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-1"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-1"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-1"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-1"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-1"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-1"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-1"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-1"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-1"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-1"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-1"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-1"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-1"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-2"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-2"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-2"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-2"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-2"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-2"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-2"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-2"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-2"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-2"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-2"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-2"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-2"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-2"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-2"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-2"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-2"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-2"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-2"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-2"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-2"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-2"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.weeklyOSM</p>
<h1 id="privacy-policy-2"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-3"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-3"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-3"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-3"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-3"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-3"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-3"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-3"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-3"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-3"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-3"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-3"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-3"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-3"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-3"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-3"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-3"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-3"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-3"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-3"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-3"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-3"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.z. H. FOSSGIS e.V.</p>
<h1 id="privacy-policy-3"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-4"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-4"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-4"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-4"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-4"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-4"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-4"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-4"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-4"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-4"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-4"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-4"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-4"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-4"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-4"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-4"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-4"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-4"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-4"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-4"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-4"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-4"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Bundesallee 23</p>
<h1 id="privacy-policy-4"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-5"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-5"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-5"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-5"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-5"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-5"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-5"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-5"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-5"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-5"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-5"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-5"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-5"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-5"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-5"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-5"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-5"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-5"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-5"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-5"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-5"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-5"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.10717 Berlin</p>
<h1 id="privacy-policy-5"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-6"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-6"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-6"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-6"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-6"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-6"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-6"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-6"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-6"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-6"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-6"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-6"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-6"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-6"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-6"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-6"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-6"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-6"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-6"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-6"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-6"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-6"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-6"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-7"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-7"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-7"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-7"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-7"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-7"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-7"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-7"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-7"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-7"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-7"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-7"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-7"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-7"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-7"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-7"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-7"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-7"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-7"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-7"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-7"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-7"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Vertreten durch</p>
<h1 id="privacy-policy-7"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-8"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-8"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-8"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-8"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-8"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-8"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-8"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-8"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-8"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-8"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-8"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-8"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-8"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-8"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-8"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-8"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-8"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-8"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-8"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-8"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-8"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-8"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-8"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-9"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-9"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-9"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-9"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-9"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-9"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-9"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-9"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-9"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-9"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-9"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-9"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-9"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-9"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-9"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-9"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-9"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-9"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-9"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-9"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-9"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-9"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Marc Gehling</p>
<h1 id="privacy-policy-9"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-10"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-10"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-10"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-10"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-10"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-10"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-10"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-10"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-10"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-10"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-10"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-10"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-10"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-10"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-10"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-10"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-10"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-10"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-10"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-10"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-10"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-10"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-10"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-11"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-11"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-11"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-11"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-11"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-11"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-11"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-11"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-11"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-11"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-11"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-11"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-11"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-11"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-11"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-11"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-11"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-11"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-11"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-11"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-11"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-11"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Kontakt</p>
<h1 id="privacy-policy-11"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-12"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-12"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-12"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-12"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-12"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-12"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-12"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-12"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-12"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-12"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-12"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-12"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-12"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-12"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-12"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-12"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-12"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-12"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-12"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-12"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-12"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-12"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-12"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-13"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-13"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-13"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-13"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-13"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-13"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-13"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-13"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-13"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-13"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-13"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-13"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-13"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-13"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-13"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-13"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-13"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-13"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-13"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-13"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-13"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-13"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure <a href="mailto:wording.info@weeklyosm.eu">wording.info@weeklyosm.eu</a></p>
<h1 id="privacy-policy-13"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-14"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-14"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-14"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-14"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-14"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-14"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-14"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-14"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-14"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-14"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-14"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-14"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-14"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-14"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-14"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-14"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-14"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-14"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-14"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-14"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-14"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-14"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-14"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-15"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-15"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-15"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-15"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-15"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-15"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-15"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-15"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-15"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-15"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-15"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-15"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-15"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-15"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-15"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-15"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-15"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-15"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-15"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-15"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-15"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-15"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.## Redaktionell verantwortlich</p>
<h1 id="privacy-policy-15"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-16"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-16"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-16"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-16"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-16"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-16"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-16"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-16"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-16"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-16"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-16"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-16"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-16"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-16"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-16"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-16"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-16"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-16"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-16"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-16"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-16"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-16"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-16"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-17"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-17"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-17"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-17"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-17"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-17"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-17"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-17"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-17"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-17"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-17"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-17"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-17"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-17"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-17"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-17"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-17"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-17"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-17"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-17"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-17"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-17"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Marc Gehling</p>
<h1 id="privacy-policy-17"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-18"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-18"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-18"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-18"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-18"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-18"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-18"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-18"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-18"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-18"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-18"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-18"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-18"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-18"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-18"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-18"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-18"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-18"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-18"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-18"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-18"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-18"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-18"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-19"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-19"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-19"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-19"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-19"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-19"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-19"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-19"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-19"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-19"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-19"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-19"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-19"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-19"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-19"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-19"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-19"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-19"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-19"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-19"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-19"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-19"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Haftung für Inhalte</p>
<h1 id="privacy-policy-19"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-20"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-20"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-20"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-20"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-20"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-20"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-20"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-20"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-20"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-20"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-20"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-20"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-20"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-20"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-20"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-20"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-20"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-20"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-20"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-20"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-20"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-20"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-20"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-21"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-21"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-21"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-21"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-21"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-21"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-21"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-21"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-21"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-21"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-21"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-21"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-21"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-21"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-21"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-21"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-21"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-21"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-21"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-21"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-21"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-21"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Als Diensteanbieter sind wir gemäß § 7 Abs.1 Digitale-Dienste-Gesetz (DDG) für eigene Inhalte auf diesen Seiten nach den allgemeinen Gesetzen verantwortlich. Nach den Art. 4 bis 8 des Digital Services Act, sind wir als Diensteanbieter jedoch nicht verpflichtet, übermittelte oder gespeicherte fremde Informationen zu überwachen oder nach Umständen zu forschen, die auf eine rechtswidrige Tätigkeit hinweisen.</p>
<h1 id="privacy-policy-21"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-22"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-22"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-22"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-22"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-22"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-22"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-22"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-22"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-22"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-22"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-22"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-22"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-22"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-22"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-22"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-22"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-22"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-22"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-22"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-22"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-22"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-22"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-22"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-23"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-23"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-23"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-23"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-23"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-23"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-23"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-23"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-23"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-23"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-23"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-23"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-23"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-23"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-23"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-23"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-23"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-23"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-23"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-23"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-23"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-23"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Verpflichtungen zur Entfernung oder Sperrung der Nutzung von Informationen nach den allgemeinen Gesetzen bleiben hiervon unberührt. Eine diesbezügliche Haftung ist jedoch erst ab dem Zeitpunkt der Kenntnis einer konkreten Rechtsverletzung möglich. Bei Bekanntwerden von entsprechenden Rechtsverletzungen werden wir diese Inhalte umgehend entfernen.</p>
<h1 id="privacy-policy-23"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-24"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-24"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-24"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-24"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-24"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-24"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-24"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-24"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-24"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-24"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-24"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-24"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-24"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-24"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-24"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-24"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-24"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-24"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-24"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-24"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-24"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-24"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-24"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-25"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-25"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-25"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-25"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-25"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-25"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-25"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-25"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-25"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-25"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-25"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-25"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-25"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-25"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-25"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-25"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-25"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-25"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-25"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-25"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-25"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-25"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Haftung für Links</p>
<h1 id="privacy-policy-25"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-26"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-26"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-26"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-26"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-26"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-26"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-26"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-26"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-26"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-26"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-26"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-26"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-26"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-26"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-26"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-26"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-26"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-26"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-26"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-26"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-26"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-26"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-26"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-27"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-27"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-27"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-27"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-27"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-27"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-27"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-27"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-27"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-27"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-27"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-27"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-27"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-27"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-27"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-27"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-27"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-27"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-27"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-27"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-27"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-27"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Unser Angebot enthält Links zu externen Websites Dritter, auf deren Inhalte wir keinen Einfluss haben. Deshalb können wir für diese fremden Inhalte auch keine Gewähr übernehmen. Für die Inhalte der verlinkten Seiten ist stets der jeweilige Anbieter oder Betreiber der Seiten verantwortlich. Die verlinkten Seiten wurden zum Zeitpunkt der Verlinkung auf mögliche Rechtsverstöße überprüft. Rechtswidrige Inhalte waren zum Zeitpunkt der Verlinkung nicht erkennbar.</p>
<h1 id="privacy-policy-27"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-28"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-28"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-28"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-28"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-28"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-28"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-28"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-28"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-28"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-28"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-28"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-28"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-28"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-28"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-28"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-28"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-28"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-28"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-28"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-28"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-28"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-28"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-28"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-29"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-29"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-29"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-29"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-29"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-29"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-29"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-29"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-29"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-29"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-29"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-29"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-29"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-29"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-29"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-29"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-29"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-29"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-29"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-29"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-29"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-29"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Eine permanente inhaltliche Kontrolle der verlinkten Seiten ist jedoch ohne konkrete Anhaltspunkte einer Rechtsverletzung nicht zumutbar. Bei Bekanntwerden von Rechtsverletzungen werden wir derartige Links umgehend entfernen.</p>
<h1 id="privacy-policy-29"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-30"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-30"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-30"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-30"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-30"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-30"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-30"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-30"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-30"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-30"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-30"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-30"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-30"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-30"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-30"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-30"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-30"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-30"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-30"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-30"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-30"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-30"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-30"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-31"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-31"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-31"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-31"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-31"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-31"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-31"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-31"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-31"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-31"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-31"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-31"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-31"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-31"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-31"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-31"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-31"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-31"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-31"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-31"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-31"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-31"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.### Urheberrecht</p>
<h1 id="privacy-policy-31"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-32"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-32"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-32"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-32"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-32"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-32"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-32"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-32"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-32"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-32"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-32"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-32"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-32"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-32"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-32"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-32"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-32"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-32"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-32"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-32"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-32"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-32"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-32"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-33"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-33"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-33"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-33"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-33"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-33"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-33"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-33"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-33"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-33"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-33"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-33"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-33"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-33"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-33"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-33"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-33"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-33"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-33"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-33"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-33"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-33"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Die durch die Seitenbetreiber erstellten Inhalte und Werke auf diesen Seiten unterliegen dem deutschen Urheberrecht. Die Vervielfältigung, Bearbeitung, Verbreitung und jede Art der Verwertung außerhalb der Grenzen des Urheberrechtes bedürfen der schriftlichen Zustimmung des jeweiligen Autors bzw. Erstellers. Downloads und Kopien dieser Seite sind nur für den privaten, nicht kommerziellen Gebrauch gestattet.</p>
<h1 id="privacy-policy-33"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-34"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-34"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-34"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-34"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-34"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-34"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-34"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-34"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-34"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-34"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-34"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-34"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-34"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-34"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-34"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-34"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-34"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-34"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-34"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-34"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-34"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-34"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-34"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-35"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-35"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-35"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-35"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-35"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-35"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-35"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-35"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-35"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-35"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-35"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-35"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-35"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-35"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-35"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-35"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-35"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-35"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-35"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-35"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-35"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-35"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Soweit die Inhalte auf dieser Seite nicht vom Betreiber erstellt wurden, werden die Urheberrechte Dritter beachtet. Insbesondere werden Inhalte Dritter als solche gekennzeichnet. Sollten Sie trotzdem auf eine Urheberrechtsverletzung aufmerksam werden, bitten wir um einen entsprechenden Hinweis. Bei Bekanntwerden von Rechtsverletzungen werden wir derartige Inhalte umgehend entfernen.</p>
<h1 id="privacy-policy-35"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-36"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-36"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-36"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-36"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-36"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-36"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-36"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-36"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-36"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-36"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-36"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-36"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-36"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-36"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-36"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-36"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-36"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-36"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-36"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-36"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-36"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-36"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-36"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-37"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-37"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-37"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-37"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-37"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-37"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-37"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-37"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-37"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-37"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-37"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-37"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-37"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-37"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-37"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-37"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-37"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-37"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-37"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-37"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-37"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-37"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.## Verbraucher­streit­beilegung/Universal­schlichtungs­stelle</p>
<h1 id="privacy-policy-37"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-38"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-38"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-38"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-38"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-38"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-38"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-38"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-38"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-38"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-38"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-38"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-38"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-38"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-38"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-38"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-38"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-38"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-38"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-38"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-38"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-38"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-38"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-38"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-39"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-39"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-39"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-39"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-39"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-39"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-39"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-39"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-39"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-39"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-39"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-39"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-39"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-39"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-39"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-39"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-39"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-39"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-39"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-39"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-39"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-39"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.Wir sind nicht bereit oder verpflichtet, an Streitbeilegungsverfahren vor einer Verbraucherschlichtungsstelle teilzunehmen.</p>
<h1 id="privacy-policy-39"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-40"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-40"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-40"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-40"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-40"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-40"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-40"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-40"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-40"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-40"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-40"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-40"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-40"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-40"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-40"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-40"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-40"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-40"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-40"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-40"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-40"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-40"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-40"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-41"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-41"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-41"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-41"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-41"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-41"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-41"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-41"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-41"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-41"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-41"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-41"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-41"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-41"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-41"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-41"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-41"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-41"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-41"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-41"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-41"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-41"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.## Quelle</p>
<h1 id="privacy-policy-41"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-42"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-42"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-42"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-42"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-42"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-42"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-42"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-42"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-42"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-42"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-42"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-42"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-42"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-42"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-42"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-42"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-42"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-42"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-42"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-42"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-42"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-42"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
<h1 id="privacy-policy-42"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-43"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-43"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-43"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-43"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-43"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-43"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-43"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-43"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-43"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-43"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-43"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-43"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-43"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-43"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-43"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-43"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-43"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-43"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-43"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-43"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-43"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-43"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.<a href="https://www.e-recht24.de">eRecht24</a></p>
<h1 id="privacy-policy-43"><strong>Privacy Policy</strong></h1>
<p>We are pleased that you are interested in our organization. The protection of your Personal Data is particularly important to our management. As a rule, you can use our websites without disclosing any Personal Data to us. However, if you wish to use more specific services via our websites, including our other websites, applications and social media pages, we may have to process your Personal Data. If we wish to process data about you and we cannot rely on any other legal basis, we will always ask you for your Consent first (e.g., via a cookie banner).</p>
<p>We always comply with applicable data protection laws when handling your Personal Data (such as name, address, email or telephone number). With this Privacy Policy, we inform you about which data we process. This Privacy Policy also explains to you what rights you have as a Data Subject.</p>
<p>We have taken various technical and organizational measures to protect your data on our websites in the best possible way. Nevertheless, there are always risks on the internet and complete protection is not possible. For this reason, you can also transmit your Personal Data to us by other means, for example by telephone, if you prefer.</p>
<p>This Privacy Policy is not only intended to fulfill the obligations under GDPR and to comply with the law of the Member States of the European Union (EU) and the European Economic Area (EEA). This Privacy Policy is also intended to comply with legislation such as UK data protection laws (UK-GDPR), Swiss Federal Data Protection Act and Swiss Data Protection Ordinance (DSG, DSV), California Consumer Privacy Act (CCPA/CPRA), China&rsquo;s Personal Information Protection Law (PIPL), Delaware Personal Data Privacy Act (DPDPA), Tennessee Information Protection Act (TIPA), Minnesota Consumer Data Privacy Act (MCDPA), Iowa Act Relating to Consumer Data Protection (ICDPA), Maryland Online Data Privacy Act (MODPA), Nebraska Data Privacy Act (NDPA), New Hampshire Consumer Data Privacy Law (SB255), New Jersey Data Privacy Law (SB332), South Carolina Consumer Privacy Bill (House Bill 4696) and other global data protection regulations and shall be interpreted accordingly. The following Privacy Policy shall be interpreted for each country, state or federal state in such a way that the terms and legal bases used correspond to the terms and legal bases used in the respective state or federal state.</p>
<p>For reasons of better readability, the simultaneous use of the language forms male, female, diverse and other gender identities (m/f/d/other) is avoided on our websites, in publications, in communication and in our Privacy Policy. All formulations used apply equally to all genders.</p>
<p>If you have any suggestions for improving the texts in this Privacy Policy or if you want to hire an External Data Protection Officer, please contact the author of the text: <a href="https://www.linkedin.com/in/heikomaniero/">Prof. Dr. h.c. Heiko Jonny Maniero, LL.B., LL.M. mult., M.L.E.</a>.</p>
<h2 id="1-definitions-44"><strong>1. Definitions</strong></h2>
<p>In our Privacy Policy, we use special terms from various data protection laws. We want our statement to be easy to understand and therefore explain these terms in advance.</p>
<p>The following definitions shall be interpreted or expanded, as appropriate, based on the case law of the General Court of the European Union (EGC), the European Court of Justice (ECJ), the Swiss Federal Supreme Court (SFSC), the Supreme Court of the United Kingdom (UKSC) or on national data protection laws or national case law of a state or federal state, including but not limited to California, including case law, also under common law, if this is necessary for the application of the law in individual cases.</p>
<p>We use the following terms, among others, in this Privacy Policy:</p>
<p>a) Personal Data</p>
<p>Personal Data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, or who must be regarded as such under national data protection legislation or national jurisdiction of a state or federal state, including under common law.</p>
<p>b) Data Subject</p>
<p>Data Subject is any identified or identifiable natural person whose Personal Data is processed by the Controller, a Processor, an international organization or another data recipient, and persons who must be regarded as such under national data protection laws or national jurisdiction of a state or federal state, including case law, also under common law.</p>
<p>c) Processing</p>
<p>Processing is any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.</p>
<p>d) Restriction of Processing</p>
<p>Restriction of Processing is the marking of stored Personal Data with the aim of limiting their Processing in the future.</p>
<p>e) Profiling</p>
<p>Profiling is any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person&rsquo;s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.</p>
<p>f) Pseudonymization</p>
<p>Pseudonymization is the Processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.</p>
<p>g) Controller</p>
<p>The Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law.</p>
<p>h) Processor</p>
<p>A Processor is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller.</p>
<p>i) Recipient</p>
<p>A Recipient is a natural or legal person, public authority, agency or another body, to which the Personal Data are disclosed, whether a Third Party or not. However, public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.</p>
<p>j) Third Party</p>
<p>A Third Party is a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process Personal Data.</p>
<p>k) Consent</p>
<p>Consent is any freely given, specific, informed and unambiguous indication of the Data Subject&rsquo;s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.</p>
<h2 id="2-name-and-address-of-the-controller-44"><strong>2. Name and address of the Controller</strong></h2>
<p>The Controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and the European Economic Area, British data protection laws, Swiss data protection laws (DSG, DSV), Californian data protection law (CCPA/CPRA), Chinese data protection law (PIPL), as well as international laws and provisions with a data protection nature is:</p>
<p>weeklyOSM</p>
<p>c/o FOSSGIS e.V. Bundesallee 23</p>
<p>10717 Berlin</p>
<p>Phone.: +491789318008</p>
<p>eMail: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<p>Website: <a href="https://weeklyosm.eu">https://weeklyosm.eu</a></p>
<h2 id="3-collection-of-general-data-and-information-44"><strong>3. Collection of general data and information</strong></h2>
<p>Our websites collect a range of general data and information each time the websites are accessed by a Data Subject or an automated system. This general data and information are stored in the log files of the respective server. Among other things, the (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system accesses our websites (so-called referrer), (4) the sub-websites which are accessed via an accessing system on our websites, (5) the date and time of access to the website, (6) an internet protocol address (IP address), (7) the internet service provider of the accessing system and (8) other similar data and information used for security purposes in the event of attacks on our information technology systems can be recorded.</p>
<p>When using this general data and information, we generally do not draw any conclusions about the Data Subject. Rather, this information is required to (1) correctly deliver the content of our websites, (2) optimize the content of our websites and the advertising for them, (3) ensure the long-term functionality of our information technology systems and the technology of our websites and (4) provide law enforcement authorities with the information necessary for criminal prosecution in the event of a cyber-attack. This anonymously collected data and information is therefore evaluated by us both statistically and with the aim of increasing data protection and data security in our organisation to ultimately ensure an optimal level of protection for the Personal Data processed by us. The data of the server log files are stored separately from all Personal Data provided by a Data Subject.</p>
<p>The purpose of processing is to avert danger and ensure IT security, as well as the aforementioned purposes. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is the protection of our information technology systems. The log files are deleted after the stated purposes have been achieved.</p>
<h2 id="4-contact-possibility-via-the-website-and-other-data-transfers-and-your-consent-44"><strong>4. Contact possibility via the website and other data transfers and your Consent</strong></h2>
<p>Our website contains information that enables quick electronic contact with our organisation as well as direct communication with us, which also includes a general address of the so-called electronic mail (email address) and possibly a telephone number. If a Data Subject contacts us by email, via a contact form, via an input form or in any other way, the Personal Data transmitted by the Data Subject will be stored automatically. This Personal Data transmitted to us on a voluntary basis by a Data Subject is processed for the purposes of usage or contacting the Data Subject.</p>
<p>We obtain your Consent for the transmission, storage and Processing of your contact data and inquiries and for contacting you in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered or transmitted for the purposes of processing the inquiry and contacting you. By transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes stated, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<h2 id="5-routine-deletion-and-restriction-of-personal-data-44"><strong>5. Routine deletion and restriction of Personal Data</strong></h2>
<p>We process and store Personal Data for the period required to achieve the purpose of processing or if this has been provided for by the European legislator or another legislator in laws or regulations to which we are subject, or if a legal basis for the Processing exists.</p>
<p>If the purpose of processing no longer applies or if a storage period prescribed by the European legislator or another competent legislator expires, or if the legal basis for the Processing no longer applies, the Personal Data will be routinely restricted or deleted in accordance with the statutory provisions.</p>
<h2 id="6-rights-of-the-data-subject-according-to-gdpr-44"><strong>6. Rights of the Data Subject according to GDPR</strong></h2>
<p>a) Right to confirmation</p>
<p>Each Data Subject has the right to obtain from the Controller confirmation as to whether or not Personal Data concerning him or her is being processed.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>b) Right to information</p>
<p>Each Data Subject has the right to obtain from the Controller free information about the Personal Data stored about him/her and a copy of this data at any time. Furthermore, the European legislator has granted the Data Subject access to the following information:</p>
<p>• the purposes of processing,</p>
<p>• the categories of Personal Data that are processed,</p>
<p>• the recipients or categories of recipients to whom the Personal Data have been or will be disclosed, in particular recipients in third countries or international organizations,</p>
<p>• where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period,</p>
<p>• the existence of the right to request from the Controller rectification or erasure of Personal Data or Restriction of Processing of Personal Data concerning the Data Subject or to object to such Processing,</p>
<p>• the existence of a right to lodge a complaint with a supervisory authority,</p>
<p>• if the Personal Data is not collected from the Data Subject: All available information about the origin of the data,</p>
<p>• the existence of automated decision-making, including Profiling, referred to in Art. 22 (1) and (4) GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such Processing for the Data Subject.</p>
<p>Furthermore, the Data Subject has a right to information as to whether Personal Data has been transferred to a third country or to an international organization. If this is the case, the Data Subject also has the right to obtain information about the appropriate safeguards in connection with the transfer.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>c) Right to rectification</p>
<p>Each Data Subject has the right to demand the immediate correction of incorrect Personal Data concerning them. Furthermore, the Data Subject has the right to request the completion of incomplete Personal Data, including by means of a supplementary declaration, taking into account the purposes of the Processing.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>d) Right to erasure (right to be forgotten)</p>
<p>Each Data Subject has the right, to obtain from the Controller the erasure of Personal Data concerning him or her without undue delay, and the Controller shall have the obligation to erase Personal Data without undue delay where one of the following grounds applies, as long as the Processing is not necessary:</p>
<p>• Personal Data was collected or otherwise processed for purposes for which it is no longer necessary.</p>
<p>• The Data Subject withdraws Consent on which the Processing is based according to Art. 6 (1) (a) GDPR, or Art. 9 (2) (a) GDPR, and where there is no other legal ground for the Processing.</p>
<p>• The Data Subject objects to the Processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to the Processing pursuant to Art. 21 (2) GDPR.</p>
<p>• Personal Data was processed unlawfully.</p>
<p>• The deletion of Personal Data is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the Controller is subject.</p>
<p>• The Personal Data was collected in relation to information society services offered in accordance with Art. 8 (1) GDPR.</p>
<p>If one of the aforementioned reasons applies, and a Data Subject wishes to request the erasure of Personal Data stored by us, he or she may contact us at any time.</p>
<p>If we have made the Personal Data public and if our organisation is obliged to delete the Personal Data in accordance with Art. 17 (1) GDPR, we shall take appropriate measures, including technical measures, taking into account the available technology and the implementation costs, to inform other data Controllers who process the published Personal Data that the Data Subject has requested the deletion of all links to this Personal Data or of copies or replications of this Personal Data from these other data Controllers, insofar as the Processing is not necessary.</p>
<p>e) Right to Restriction of Processing</p>
<p>Each Data Subject has the right to obtain from the Controller Restriction of Processing where one of the following applies:</p>
<p>• The accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data.</p>
<p>• The Processing is unlawful, and the Data Subject opposes the erasure of the Personal Data and requests the restriction of their use instead.</p>
<p>• The Controller no longer needs the Personal Data for the purposes of the Processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims.</p>
<p>• The Data Subject has objected to Processing pursuant to Art. 21 (1) GDPR pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.</p>
<p>If one of the aforementioned conditions is met, and a Data Subject wishes to request the restriction of the Processing of Personal Data stored by us, he or she may contact us at any time.</p>
<p>f) Right to data portability</p>
<p>Each Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Controller, in a structured, commonly used and machine-readable format. He or she also has the right to transmit those data to another Controller without hindrance from the Controller to which the Personal Data have been provided, where Processing is based on Consent pursuant to Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR or on a contract pursuant to Art. 6 (1) (b) GDPR and the Processing is carried out by automated means, unless the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.</p>
<p>Furthermore, in exercising their right to data portability pursuant to Art. 20 (1) GDPR, the Data Subject has the right to have the Personal Data transmitted directly from one Controller to another, where technically feasible and provided that this does not adversely affect the rights and freedoms of others.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>g) Right to object</p>
<p>Each Data Subject has the right to object, on grounds relating to his or her particular situation, at any time, to Processing of Personal Data concerning him or her, which is based on point (e) or (f) of Article 6(1) of the GDPR. This also applies to Profiling based on these provisions.</p>
<p>In the event of an objection, we will no longer process the Personal Data unless we can demonstrate compelling legitimate grounds for the Processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.</p>
<p>If we process Personal Data for direct marketing purposes, the Data Subject shall have the right to object at any time to Processing of Personal Data concerning him or her for such marketing. This also applies to Profiling insofar as it is associated with such direct advertising. If the Data Subject objects to us to the Processing for direct marketing purposes, we will no longer process the Personal Data for these purposes.</p>
<p>In addition, the Data Subject has the right, on grounds relating to his or her particular situation, to object to Processing of Personal Data concerning him or her by us for scientific or historical research purposes, or for statistical purposes pursuant to Article 89(1) of the GDPR, unless the Processing is necessary for the performance of a task carried out for reasons of public interest.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time. The Data Subject is also free, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise his or her right to object by automated means using technical specifications.</p>
<p>h) Automated decisions in individual cases including Profiling</p>
<p>Each Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her, or similarly significantly affects him or her, provided that the decision (1) is not necessary for the conclusion or performance of a contract between the Data Subject and the Controller, or (2) is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, or (3) is based on the Data Subject&rsquo;s explicit Consent.</p>
<p>If the decision (1) is necessary for entering into, or the performance of, a contract between the Data Subject and a data Controller, or (2) it is based on the Data Subject&rsquo;s explicit Consent, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Controller, to express his or her point of view and contest the decision.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<p>i) Right to withdraw Consent under data protection law</p>
<p>Each Data Subject has the right to withdraw Consent to the Processing of Personal Data at any time.</p>
<p>If a Data Subject wishes to exercise this right, he or she may contact us at any time.</p>
<h2 id="7-general-purpose-of-processing-categories-of-processed-data-and-categories-of-recipients-44"><strong>7. General purpose of Processing, categories of processed data and categories of recipients</strong></h2>
<p>The general purpose of processing Personal Data is the handling of all activities relating to the Controller, customers, interested parties, business partners or other contractual or pre-contractual relationships between the aforementioned groups (in the broadest sense) or legal obligations of the Controller. This general purpose applies if no more specific purposes for specific Processing are specified.</p>
<p>The categories of Personal Data that we process are customer data, prospective customer data, employee data (including applicant data) and supplier data. The categories of recipients of Personal Data are public bodies, external bodies, internal processing, intragroup processing and other bodies.</p>
<p>A list of our Processors and data recipients in third countries and, if applicable, international organizations is either published on our website or can be requested from us free of charge.</p>
<h2 id="8-legal-basis-for-the-processing-44"><strong>8. Legal basis for the Processing</strong></h2>
<p>Art. 6 (1) (a) GDPR serves as the legal basis for Processing operations for which we obtain Consent for a specific Processing purpose. If the Processing of Personal Data is necessary for the performance of a contract to which the Data Subject is party, as is the case, for example, when Processing operations are necessary for the supply of goods or to provide any other service or consideration, Processing is based on Art. 6 (1) (b) GDPR. The same applies to such Processing operations that are necessary to carry out pre-contractual measures, for example in cases of inquiries about our products or services. If we are subject to a legal obligation which requires the Processing of Personal Data, such as for the fulfillment of tax obligations, Processing is based on Art. 6 (1) (c) GDPR.</p>
<p>In rare cases, it may be necessary to process Personal Data to protect the vital interests of the Data Subject or another natural person. This would be the case, for example, if a visitor were injured in our organisation and their name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other Third Party. The Processing would then be based on Art. 6 (1) (d) GDPR.</p>
<p>If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, the legal basis is Art. 6 (1) (e) GDPR.</p>
<p>Ultimately, Processing operations could be based on Art. 6 (1) (f) GDPR. This legal basis is used for Processing operations which are not covered by any of the abovementioned legal grounds, if Processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a Third Party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data. We are permitted to carry out such Processing operations in particular because they have been specifically mentioned by the European legislator. In this respect, it took the view that a legitimate interest could be assumed, for example, if the Data Subject is a customer of the Controller (Recital 47 Sentence 2 GDPR).</p>
<h2 id="9-legitimate-interests-in-processing-pursued-by-the-controller-or-a-third-party-and-direct-marketing-44"><strong>9. Legitimate interests in Processing pursued by the Controller or a Third Party and direct marketing</strong></h2>
<p>If the Processing of Personal Data is based on Art. 6 (1) (f) GDPR and no more specific legitimate interests are stated, our legitimate interest is the performance of our business activities for the benefit of the well-being of our staff and our shareholders.</p>
<p>We may send you direct advertising about our own goods or services that are similar to the goods or services you have requested, commissioned or purchased. You may object to direct advertising at any time (e.g. by email). You will not incur any costs other than the transmission costs according to the basic rates. The Processing of Personal Data for direct marketing purposes is based on Art. 6 (1) (f) GDPR. The legitimate interest is direct marketing.</p>
<p>Our messages and newsletters may also constitute direct marketing communications within the meaning of Article 13(2) of EU Directive 2002/58 (Directive on privacy and electronic communications) and the national law resulting from the Directive, provided that we have obtained your electronic and other contact information in connection with the sale of a service or product, which includes the creation of a free user account that allows you, among other things, to access free content on our websites and publications (newsletters, etc.), provided that we advertise similar products or services through direct marketing, so that direct marketing is also permissible without consent (see ECJ, judgment of November 13, 2025, Case C 654/23). In such cases, you can refuse the use of your contact information at any time free of charge.</p>
<h2 id="10-duration-for-which-the-personal-data-is-stored-44"><strong>10. Duration for which the Personal Data is stored</strong></h2>
<p>The criterion for the duration of the storage of Personal Data is the respective statutory retention period. If there is no statutory retention period, the criterion is the contractual or internal retention period. After this period has expired, the corresponding data is routinely deleted if it is no longer required to fulfill or initiate a contract. This applies in particular to all Processing operations for which no more specific criteria have been defined.</p>
<h2 id="11-legal-or-contractual-provisions-for-the-provision-of-personal-data-necessity-for-the-conclusion-of-the-contract-obligation-of-the-data-subject-to-provide-the-personal-data-possible-consequences-of-non-provision-44"><strong>11. Legal or contractual provisions for the provision of Personal Data; necessity for the conclusion of the contract; obligation of the Data Subject to provide the Personal Data; possible consequences of non-provision</strong></h2>
<p>We would like to inform you that the provision of Personal Data is partly required by law (e.g., tax regulations) or may also result from contractual obligations (e.g., information on the contractual partner). Sometimes it may be necessary for a contract to be concluded for a Data Subject to provide us with Personal Data that must subsequently be processed by us. For example, Data Subjects are obliged to provide us with Personal Data if our organisation concludes a contract with them. Failure to provide Personal Data would mean that the contract with the Data Subject could not be concluded. The Data Subject must contact us before providing Personal Data. We will inform the Data Subject on a case-by-case basis whether the provision of the Personal Data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the Personal Data and what the consequences would be if the Personal Data were not provided.</p>
<h2 id="12-existence-of-automated-decision-making-44"><strong>12. Existence of automated decision-making</strong></h2>
<p>As a responsible company, we do not normally use automated decision-making or Profiling. If, in exceptional cases, we carry out automated decision-making or Profiling, we will inform the Data Subject either separately or via a sub-item in our Privacy Policy (here on our website). In this case, the following applies:</p>
<p>Automated decision-making, including Profiling, may take place if (1) this is necessary for the conclusion or performance of a contract between the Data Subject and us, or (2) this is permissible on the basis of Union or Member State legislation to which we are subject and this legislation contains appropriate measures to safeguard the rights and freedoms and legitimate interests of the Data Subject, or (3) this takes place with the explicit Consent of the Data Subject.</p>
<p>In the cases referred to in Art. 22 (2) (a) and (c) GDPR, we shall implement suitable measures to safeguard the Data Subject&rsquo;s rights and freedoms and legitimate interests. In these cases, you have the right to obtain human intervention on the part of the Controller, to express your point of view and to contest the decision.</p>
<p>Meaningful information on the logic involved and the scope and intended effects of such Processing for the Data Subject will be provided in this Privacy Policy where applicable.</p>
<h2 id="13-recipients-in-a-third-country-and-appropriate-or-adequate-safeguards-and-how-to-obtain-a-copy-of-them-or-where-they-are-available-44"><strong>13. Recipients in a third country and appropriate or adequate safeguards and how to obtain a copy of them or where they are available.</strong></h2>
<p>According to Art. 46 (1) GDPR, the Controller or Processor may only transfer Personal Data to a third country if the Controller or Processor has provided appropriate safeguards and if enforceable rights and effective legal remedies are available to the Data Subjects. Appropriate safeguards can be provided by standard contractual clauses without the need for special approval from a supervisory authority, Art. 46 (2) (c) GDPR.</p>
<p>The EU standard contractual clauses or other appropriate safeguards are agreed with all recipients from third countries prior to the first transfer of Personal Data, or the transfers are based on adequacy decisions. Consequently, it is ensured that appropriate safeguards, enforceable rights and effective legal remedies are guaranteed for all Processing of Personal Data. Any Data Subject can obtain a copy of the standard contractual clauses or adequacy decisions from us. In addition, the standard contractual clauses and adequacy decisions are available in the Official Journal of the European Union.</p>
<p>Art. 45 (3) GDPR authorizes the European Commission to decide by means of an implementing decision that a non-EU country ensures an adequate level of protection. This means a level of protection for Personal Data that essentially corresponds to the level of protection within the EU. Adequacy decisions mean that Personal Data can flow from the EU (as well as from Norway, Liechtenstein and Iceland) to a third country without further obstacles. Similar regulations apply to the United Kingdom, Switzerland and some other countries.</p>
<p>In all cases where the European Commission, or a government or competent authority of another country, has decided that a third country ensures an adequate level of protection and/or a valid framework exists (e.g., EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework), all transfers by us to the members of such frameworks (e.g., self-certified entities) are based solely on the membership of that entity in the respective framework or on the respective adequacy decisions. If we or one of our group companies is a member of such a framework, all transfers to us or our group company are based exclusively on the membership of the respective company in this framework. If we or one of our group companies is located in a third country with an adequate level of protection, all transfers to us or our group company are based solely on the respective adequacy decisions.</p>
<p>Any Data Subject can obtain a copy of the frameworks from us. In addition, the frameworks are also available in the Official Journal of the European Union or in the published legal materials or on the websites of data protection supervisory authorities or other authorities or institutions.</p>
<h2 id="14-right-to-lodge-a-complaint-with-a-data-protection-supervisory-authority-44"><strong>14. Right to lodge a complaint with a data protection supervisory authority</strong></h2>
<p>As the Controller, we are obliged to inform the Data Subject of the existence of the right to lodge a complaint with a supervisory authority. The right to lodge a complaint is regulated in Art. 77 (1) GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the General Data Protection Regulation. The right to lodge a complaint has been restricted by the EU legislator to the effect that it can only be exercised with a single supervisory authority (Recital 141 Sentence 1 GDPR). This provision is intended to avoid duplicate complaints in the same matter by the same Data Subject. If a Data Subject wishes to complain about us, it is therefore requested that only one supervisory authority is contacted.</p>
<h2 id="15-blog-and-comment-function-44"><strong>15. Blog and comment function</strong></h2>
<p>A blog is a portal, usually open to the public, in which one or more people, called bloggers or web bloggers, post articles or publish thoughts in so-called blog posts. You can leave individual comments on blog posts in our blog.</p>
<p>If you leave your own comments on our blog, information about the time you entered the comments and your username (possibly a pseudonym) will be stored, published and distributed in addition to the comments. By submitting comments, you conclude a publication contract with us, which grants us free of charge and irrevocably all worldwide copyright usage rights that you are entitled to. This includes, in particular, the rights to reproduce, distribute and make publicly available all comments submitted by you. The legal basis for the Processing is therefore Art. 6 (1) (b) GDPR.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and granting the opportunity to submit comments.</p>
<p>Furthermore, the IP address assigned to your internet connection by your internet service provider (ISP) is logged when you post a comment. The IP address is stored for security reasons and for the case you violate the rights of Third Parties or post illegal content by posting a comment. The storage of this Personal Data is therefore in our own interest so that we can exculpate ourselves in the event of an infringement. The above purposes are the legitimate interests pursued by the Controller (Art. 6 (1) (f) GDPR). This data will not be passed on to Third Parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution or exculpation.</p>
<h2 id="16-subscription-to-comments-44"><strong>16. Subscription to comments</strong></h2>
<p>The comments posted on our blog can be subscribed to by anyone. In particular, it is possible for a commentator to subscribe to the comments following their comment on a particular blog post.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time to subscribe to comments using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the subscription to comments. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a subscription to comments only to reconfirmed recipients. The option to subscribe to comments can be canceled at any time.</p>
<p>The purposes of Processing are the provision of a blog with a comment function and the granting of the option to subscribe to comments. The legal basis for sending these comments is Art. 6 (1) (b) GDPR, due to the contract concluded with us for sending comments.</p>
<h2 id="17-data-protection-provisions-about-the-application-and-use-of-hetzner-44"><strong>17. Data protection provisions about the application and use of Hetzner</strong></h2>
<p>Hetzner Online GmbH is a provider of hosting services and data center infrastructure, offering a wide range of products from web hosting and managed hosting to dedicated servers and cloud solutions. With powerful and reliable technology, Hetzner helps companies and individuals build and scale their online presence. Customers benefit from state-of-the-art data centers, comprehensive security and data protection, and dedicated customer service.</p>
<p>When using Hetzner services, Personal Data such as names, addresses, contact details, payment information and usage data of the services provided are processed. This information is necessary to manage user accounts, provide services, provide support and ensure the security of the systems.</p>
<p>The company that operates the service and thus the recipient of personal data is: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The representative under national law in the United Kingdom is: Hetzner Ltd., 7 Coronation Road, Dephna House, Launchese 105, London, NW10 7PQ, United Kingdom.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use and optimization of hosting services and data center infrastructure. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of secure, reliable and efficient hosting solutions.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Hetzner may be retrieved under <a href="https://www.hetzner.com.">https://www.hetzner.com.</a></p>
<h2 id="18-data-protection-provisions-about-the-application-and-use-of-font-awesome-44"><strong>18. Data protection provisions about the application and use of Font Awesome</strong></h2>
<p>Font Awesome offers an extensive collection of scalable vector icons and social media logos that web developers and designers can use in their projects to make user interfaces more intuitive and visually appealing. As one of the most popular icon toolkits, Font Awesome makes it easy to integrate icons through CSS, JavaScript or by using web fonts. The platform offers both free and pro versions that provide access to a wider variety of icons and additional features.</p>
<p>When using Font Awesome, Personal Data such as IP addresses and usage data may be processed, especially when users visit the website or sign up for a Pro account. This information is necessary to provide services, analyze website usage, make support requests and ensure the security of the platform.</p>
<p>The company that operates the service and thus the recipient of personal data is: Fonticons, Inc., 307 S Main St Ste 202, Bentonville, AR 72712-9214, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is the use of the Icon Toolkit and the associated services. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the optimization of the user experience and the efficient provision of an appealing website.</p>
<p>The company that operates the service is located in a third country, namely in the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Font Awesome can be found at <a href="https://fontawesome.com.">https://fontawesome.com.</a></p>
<h2 id="19-data-protection-provisions-about-the-application-and-use-of-google-fonts-44"><strong>19. Data protection provisions about the application and use of Google Fonts</strong></h2>
<p>Google Fonts is a free service from Google LLC that provides web developers with a wide range of fonts to improve the design and aesthetics of websites. By integrating Google Fonts, web developers can ensure that texts on their websites are displayed consistently and as intended on different devices and browsers. Google Fonts is provided via Google servers, ensuring high availability and fast loading times.</p>
<p>When using Google Fonts, Personal Data such as IP addresses and browser information may be processed, as a request is sent to the Google servers when the fonts are loaded. This data is used to provide the service, optimize performance and prevent misuse.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and optimize the font service for web developers and end users. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in improving the user experience on websites by providing a variety of fonts and ensuring fast loading times.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Google Fonts can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="20-data-protection-provisions-about-the-application-and-use-of-jquery-44"><strong>20. Data protection provisions about the application and use of jQuery</strong></h2>
<p>jQuery is a widely used JavaScript library used by web developers to simplify and speed up HTML document management, event handling, animation and Ajax interactions. The use of jQuery on our website serves to create a smoother and more interactive user experience. When visiting our website, jQuery can be used to collect certain data, such as information about user behavior and interactions on the site. The Processing takes place indirectly and is primarily aimed at improving website performance and user-friendliness.</p>
<p>jQuery itself, as a client-side library, stores or processes Personal Data on its own servers. jQuery is executed in the user&rsquo;s browser and can be used for dynamic content updates by also transmitting data to external servers.</p>
<p>The company that operates the service and thus the recipient of personal data is: The jQuery Foundation, c/o OpenJS Foundation, 1 Letterman Drive, Suite D4700, San Francisco, CA 94129, USA.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of using jQuery is to improve the user experience on our website through an efficient interaction experience. Processing is based on Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of a functional, user-friendly and visually appealing website.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>jQuery&rsquo;s Privacy Policy is available at <a href="https://jquery.com/.">https://jquery.com/.</a></p>
<h2 id="21-data-protection-provisions-about-the-application-and-use-of-google-gmail-44"><strong>21. Data protection provisions about the application and use of Google Gmail</strong></h2>
<p>Gmail is a widely used email service. It allows users to send and receive emails, organize messages in folders and use various productivity tools directly within the platform. Gmail is known for its powerful search capabilities, extensive storage capacity and integration with other Google services such as Google Drive and Google Calendar.</p>
<p>When using Gmail, Personal Data such as names, email addresses, email content, contacts and calendar events are processed. This information is necessary to enable email communication, filter spam, identify security risks and offer users a personalized experience.</p>
<p>The company that operates the service and thus the recipient of personal data is: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For data subjects in the EU and EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acts as contact and representative within the meaning of Art. 27 GDPR. The representative under national law in the United Kingdom is: Google UK Limited, Belgrave House, 76 Buckingham Palace Road, London SW1W 9TQ, United Kingdom. The representative under Art. 14 of the Federal Act on Data Protection (FADP) in Switzerland is: Google Switzerland GmbH, Brandschenkestrasse 110, 8002 Zurich, Switzerland.</p>
<p>Purposes for which the Personal Data is to be processed and the legal basis for the Processing: The purpose of processing is to use and improve the email service and the integration with other Google services. Processing is based on Art. 6 (1) (b) GDPR for the performance of a contract to which the Data Subject is party and Art. 6 (1) (f) GDPR, whereby our legitimate interest lies in the provision and use of an efficient, secure and user-friendly email service.</p>
<p>The company that operates the service is based in a third country, namely the USA. Transfers to third countries may be based on the conclusion of Standard Contractual Clauses or other suitable or appropriate safeguards referred to in Art. 46 (2) GDPR. The company that operates the service may be a certified member of one or more of the data privacy frameworks. You can find more information at <a href="https://www.dataprivacyframework.gov/list.">https://www.dataprivacyframework.gov/list.</a> You can request a copy of the suitable or appropriate safeguards from us.</p>
<p>The criteria for determining the duration for which the Personal Data is processed are the contractual relationship between us and the company that operates the service or statutory or contractual retention periods. The provision of Personal Data is not required by law or contract, nor is it necessary for the conclusion of a contract. You are not obliged to provide us or the company that operates the service with Personal Data. However, if you do not provide it, you may not be able to use our services or those of the company operating the service.</p>
<p>Further information and the applicable data protection provisions of Gmail can be found at <a href="https://policies.google.com/privacy.">https://policies.google.com/privacy.</a></p>
<h2 id="22-subscription-to-our-newsletter-and-your-consent-44"><strong>22. Subscription to our newsletter and your Consent</strong></h2>
<p>We inform our customers and business partners about offers and news at regular intervals by means of a newsletter. You are therefore given the opportunity to subscribe to our newsletter on our website. The Personal Data transmitted to us when you subscribe to the newsletter can be understood from the input mask used. You can only receive our newsletter if (1) you have a valid email address and (2) you have registered to receive the newsletter.</p>
<p>For legal reasons, a confirmation email is sent to the email address entered by a Data Subject for the first time for the newsletter using the double opt-in procedure. This confirmation email is used to check whether the owner of the email address as the Data Subject has authorized the receipt of the newsletter. The legal basis for sending this double opt-in confirmation email is Art. 6 (1) (c) GDPR, as there is a legal obligation to send a newsletter only to confirmed recipients.</p>
<p>When registering for the newsletter, we also store the IP address assigned by the internet service provider (ISP) of the internet connection used by the Data Subject at the time of registration, as well as the date and time of registration. The storage of this data is necessary to be able to trace the (possible) misuse of a Data Subject&rsquo;s email address at a later point in time and therefore serves as legal protection for the Controller. The legal basis for Processing is also Art. 6 (1) (c) GDPR.</p>
<p>We obtain your Consent for the transmission and storage of your email address for the subscription to our newsletter in accordance with Art. 6 (1) (a) GDPR and Art. 49 (1) (1) (a) GDPR as follows:</p>
<p><strong>By entering and transmitting your Personal Data, you voluntarily consent to the Processing of the Personal Data you have entered for the purpose of sending our newsletter. By entering and transmitting your data to us, you also voluntarily give your explicit Consent in accordance with Art. 49 (1) (1) (a) GDPR to data transfers to third countries to and by the companies named in this Privacy Policy and for the purposes mentioned, in particular for such transfers to third countries for which there is or is not an adequacy decision by the EU/EEA and to companies or other bodies that are not subject to an existing adequacy decision on the basis of self-certification or other accession criteria and in which or for which there are significant risks and no suitable guarantees for the protection of your Personal Data (e.g., due to Section 702 FISA, Executive Order EO12333 and the CloudAct in the USA). When you gave your voluntary and explicit Consent, you were aware that there may not be an adequate level of data protection in third countries and that your data subject rights may not be enforceable. You can withdraw your Consent under data protection law at any time with effect for the future. The withdrawal of Consent does not affect the lawfulness of Processing based on Consent before its withdrawal. With a single action (entry and transmission), you give several Consents. These are Consents under EU/EEA data protection law as well as those under the CCPA/CPRA, ePrivacy and telemedia law, and other international legislation, which are required, among other things, as a legal basis for any planned further Processing of your Personal Data. With your action, you also confirm that you have read and taken note of this Privacy Policy.</strong></p>
<p>Your Consent to the Processing of Personal Data that you have given us for the storage of the email address for sending the newsletter can be revoked at any time. There is a corresponding link in every newsletter for the purpose of revoking Consent. It is also possible to inform us of your wish to unsubscribe by other means (e.g., by telephone).</p>
<p>The Personal Data collected when registering for the newsletter will be used exclusively to send our newsletter. Furthermore, subscribers to the newsletter may be informed by email if this is necessary for the operation of the newsletter service or a registration in this regard, as could be the case in the event of changes to the newsletter offer or changes to the technical circumstances. The Personal Data collected as part of the newsletter service will not be passed on to Third Parties.</p>
<p>By subscribing to our newsletter, you conclude a contract with us for the delivery of the newsletter, which is why the Processing in connection with the dispatch is based on Art. 6 (1) (b) GDPR as the legal basis. The contract can be terminated at any time.</p>
<p>This privacy policy was created using a specialized generator developed by <a href="https://www.wbs.legal/">legal experts in IT law</a>, <a href="https://dg-datenschutz.de/">data protection auditors</a>, and the <a href="https://cert-authority.com/">ISO 50001 certification body</a> to ensure legally secure wording.</p>
]]></content:encoded>
			</item>
			<item>
				<title>기여하다</title>
				<link>https://hugo.weeklyosm.eu/ko/this-news-should-be-in-weeklyosm/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/this-news-should-be-in-weeklyosm/</guid>
				<description><![CDATA[ Thank you for considering contributing to weeklyOSM! We welcome all link proposals from across the OpenStreetMap universe.
Propose a Link We collect your contributions with our OSM Blog Collector. Thank you for proposing your link via this form.
Step-by-Step Guide Log In: Before you can submit a link proposal, you need to log in with your OpenStreetMap account.
Search: Once authenticated, enter your link proposal into the search form provided.
Check for Duplicates: Upon submission, the Blog Collector will display a table of similar links that have already been submitted. Please review the latest entries to avoid duplicates. If your link isn&rsquo;t listed, or if you see the message No Articles found for search, you are the first to propose it!
]]></description>
				<content:encoded><![CDATA[<p></p> <p>Thank you for considering contributing to weeklyOSM! We welcome all link proposals from across the OpenStreetMap universe.</p>
<h2 id="propose-a-link">Propose a Link</h2>
<p>We collect your contributions with our <em>OSM Blog Collector</em>. Thank you for proposing your link <a href="https://osmbc.openstreetmap.de/article/create">via this form</a>.</p>
<hr>
<h2 id="step-by-step-guide">Step-by-Step Guide</h2>
<ol>
<li>
<p><strong>Log In:</strong> Before you can submit a link proposal, you need to log in with your OpenStreetMap account.</p>
</li>
<li>
<p><strong>Search:</strong> Once authenticated, enter your link proposal into the search form provided.</p>
</li>
<li>
<p><strong>Check for Duplicates:</strong> Upon submission, the Blog Collector will display a table of similar links that have already been submitted. Please review the latest entries to avoid duplicates. If your link isn&rsquo;t listed, or if you see the message <code>No Articles found for search</code>, you are the first to propose it!</p>
</li>
<li>
<p><strong>Add Details:</strong> Enter a short title and a brief description in the <em>Collection</em> field. You can also include additional relevant links here. Choosing a matching category is optional but helpful.</p>
</li>
<li>
<p><strong>Submit:</strong> Once you have filled in all the relevant details, click <em>OK</em> to submit your link. It will then be forwarded to the Blog Collector for our editors and translators to review.</p>
</li>
</ol>
]]></content:encoded>
			</item>
			<item>
				<title>법적 고지</title>
				<link>https://hugo.weeklyosm.eu/ko/imprint/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/imprint/</guid>
				<description><![CDATA[ This page has been translated from German.
Information pursuant to Section 5 DDG (German Digital Services Act) weeklyOSM
c/o FOSSGIS e.V.
Bundesallee 23
10717 Berlin
Germany
Represented by Marc Gehling
Contact info@weeklyosm.eu
Editorial Responsibility Marc Gehling
Liability for Content As a service provider, we are responsible for our own content on these pages in accordance with general laws pursuant to Section 7 Paragraph 1 of the German Digital Services Act (DDG). However, pursuant to Articles 4 to 8 of the EU Digital Services Act (DSA), we as a service provider are not obligated to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity.
]]></description>
				<content:encoded><![CDATA[<p></p> <p>This page has been translated from German.</p>
<h2 id="information-pursuant-to-section-5-ddg-german-digital-services-act">Information pursuant to Section 5 DDG (German Digital Services Act)</h2>
<p>weeklyOSM<br>
c/o FOSSGIS e.V.<br>
Bundesallee 23<br>
10717 Berlin<br>
Germany</p>
<h3 id="represented-by">Represented by</h3>
<p>Marc Gehling</p>
<h3 id="contact">Contact</h3>
<p><a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
<h2 id="editorial-responsibility">Editorial Responsibility</h2>
<p>Marc Gehling</p>
<h3 id="liability-for-content">Liability for Content</h3>
<p>As a service provider, we are responsible for our own content on these pages in accordance with general laws pursuant to Section 7 Paragraph 1 of the German Digital Services Act (DDG). However, pursuant to Articles 4 to 8 of the EU Digital Services Act (DSA), we as a service provider are not obligated to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity.</p>
<p>Obligations to remove or block the use of information under general laws remain unaffected by this. However, liability in this regard is only possible from the time of knowledge of a specific infringement. Upon becoming aware of corresponding legal violations, we will remove this content immediately.</p>
<h3 id="liability-for-links">Liability for Links</h3>
<p>Our offer contains links to external websites of third parties, whose content we have no influence over. Therefore, we cannot assume any liability for this external content. The respective provider or operator of the pages is always responsible for the content of the linked pages. The linked pages were checked for possible legal violations at the time of linking. Illegal content was not recognizable at the time of linking.</p>
<p>However, a permanent control of the content of the linked pages is not reasonable without concrete evidence of an infringement. Upon becoming aware of legal violations, we will remove such links immediately.</p>
<h3 id="copyright">Copyright</h3>
<p>The content and works created by the site operators on these pages are subject to German copyright law. The duplication, processing, distribution, and any kind of exploitation outside the limits of copyright law require the written consent of the respective author or creator. Downloads and copies of this site are only permitted for private, non-commercial use.</p>
<p>Insofar as the content on this page was not created by the operator, the copyrights of third parties are respected. In particular, third-party content is marked as such. Should you nevertheless become aware of a copyright infringement, please inform us accordingly. Upon becoming aware of legal violations, we will remove such content immediately.
Consumer Dispute Resolution/Universal Arbitration Board</p>
<p>We are neither willing nor obliged to participate in dispute resolution proceedings before a consumer arbitration board.</p>
<h2 id="source">Source</h2>
<p><a href="https://www.e-recht24.de">eRecht24</a></p>
]]></content:encoded>
			</item>
			<item>
				<title>회사 소개</title>
				<link>https://hugo.weeklyosm.eu/ko/about-us/</link>
				<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>info@weeklyosm.eu (weeklyteam)</author>
				<guid isPermaLink="false">https://hugo.weeklyosm.eu/ko/about-us/</guid>
				<description><![CDATA[ 주간OSM이란 무엇인가요? 주간OSM은 매주 오픈스트리트맵 세계에서 일어나는 일을 커뮤니티에 알립니다. 주간OSM은 숙련된 편집자부터 오픈스트리트맵 신규 가입자까지 모두가 읽을 수 있습니다. 주간OSM은 지도 편집자와 오픈스트리트맵 애호가들이 제작합니다. 주간OSM 편집 및 번역 신청은 언어를 막론하고 언제나 환영합니다. 엄청난 작업량(연간 52개호, 휴가 및 휴일 없음)으로 인해 3명의 편집자가 협력하기로 동의해야만 새로운 언어를 추가할 수 있습니다.
주간OSM의 아이디어는 전 세계의 오픈스트리트맵 관련 소식을 수집하고, 이를 가공하여 가능한 한 많은 언어로 번역하는 것입니다. 이를 통해 커뮤니티에 최대한 포괄적인 정보를 제공하고 언어 장벽을 극복하는 데 주간OSM이 도움이 될 것입니다.
]]></description>
				<content:encoded><![CDATA[<p></p> <h2 id="주간osm이란-무엇인가요">주간OSM이란 무엇인가요?</h2>
<p>주간OSM은 매주 오픈스트리트맵 세계에서 일어나는 일을 커뮤니티에 알립니다. 주간OSM은 숙련된 편집자부터 오픈스트리트맵 신규 가입자까지 모두가 읽을 수 있습니다. 주간OSM은 지도 편집자와 오픈스트리트맵 애호가들이 제작합니다. 주간OSM 편집 및 번역 신청은 언어를 막론하고 언제나 환영합니다. 엄청난 작업량(연간 52개호, 휴가 및 휴일 없음)으로 인해 3명의 편집자가 협력하기로 동의해야만 새로운 언어를 추가할 수 있습니다.</p>
<p>주간OSM의 아이디어는 전 세계의 오픈스트리트맵 관련 소식을 수집하고, 이를 가공하여 가능한 한 많은 언어로 번역하는 것입니다. 이를 통해 커뮤니티에 최대한 포괄적인 정보를 제공하고 언어 장벽을 극복하는 데 주간OSM이 도움이 될 것입니다.</p>
<p>주간OSM은 모든 조직 및 회사로부터 독립적입니다. 이는 오픈스트리트맵 재단, HOT, FOSSGIS… 그리고 여기에 나열되지 않은 다른 모든 회사에도 적용됩니다. 그럼에도 불구하고 저희의 현재 기사가 (어떤 언어로든) 오픈스트리트맵 위키의 첫 페이지에 “오픈스트리트맵 이용하기”, “자유 지도 데이터에 기여하기”, “소프트웨어 개발”과 동등하게 표시된다면 기쁠 것 같습니다. 또한 주간OSM 편집진은 오픈스트리트맵 재단에서 관리 감독을 받지 않는다는 점을 알려드리고 싶습니다.</p>
<h2 id="주간osm은-누가-어디에서-편집하나요">주간OSM은 누가, 어디에서 편집하나요?</h2>
<ul>
<li>
<p>이메일: <a href="mailto:info@weeklyosm.eu">info@weeklyosm.eu</a></p>
</li>
<li>
<p><a href="https://wiki.openstreetmap.org/wiki/WeeklyOSM">주간OSM 위키 문서</a></p>
</li>
<li>
<p><a href="https://umap.openstreetmap.fr/en/map/weeklyosm-is-currently-produced-in_56718#2/8.8/108.3">현재 주간OSM을 편집하는 사람들은 어디에 살고 있나요?</a></p>
</li>
<li>
<p><a href="https://wiki.openstreetmap.org/wiki/Former_weeklyOSM_authors">편집 횟수가 100번이 넘는 과거 (혹은 현재 게스트) 편집자</a></p>
</li>
</ul>
]]></content:encoded>
			</item>
	</channel>
</rss>
